chore(grype): suppress zlib CVE-2026-85091 until base images ship the fix (#12971)

Co-authored-by: StylusFrost <43682773+StylusFrost@users.noreply.github.com>
Co-authored-by: StylusFrost <pm.diaz.pena@gmail.com>
This commit is contained in:
authored and GitHub committed 2026-10-07 12:35:35 +02:00
1 parent b476e45c60
commit 4328d92091
1 file changed
+15
+15
View File
@@ -126,3 +126,18 @@ ignore:
- vulnerability: CVE-2026-82049
package:
name: python
# zlib in the Alpine base images of the UI (node:24.18.1-alpine) and MCP
# (python:3.13.14-alpine3.23) containers. CVE-2026-85091 is a heap overflow in
# gz_vacate() reached only through non-blocking gzwrite() followed by gzprintf() after
# a write stall. Node links its own bundled zlib and the MCP server never writes gzip
# files, so neither image calls that path. TEMPORARY: the 1.3.2-r1 fix is in the
# Alpine index and could be taken with `apk add --upgrade`, but we wait for the base
# images to ship it instead (the newest node:24-alpine and python:3.13-alpine3.23 still
# carry 1.3.2-r0). Pinned to that version so the rule stops matching on its own once a
# base image moves forward. Remove when the base digests are bumped, by 2026-11-07.
# https://security.alpinelinux.org/vuln/CVE-2026-85091
- vulnerability: CVE-2026-85091
package:
name: zlib
version: 1.3.2-r0