mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-09 21:14:22 +00:00
chore(grype): suppress zlib CVE-2026-85091 until base images ship the fix (#12971)
Co-authored-by: StylusFrost <43682773+StylusFrost@users.noreply.github.com> Co-authored-by: StylusFrost <pm.diaz.pena@gmail.com>
This commit is contained in:
1 file changed
+15
+15
@@ -126,3 +126,18 @@ ignore:
|
||||
- vulnerability: CVE-2026-82049
|
||||
package:
|
||||
name: python
|
||||
|
||||
# zlib in the Alpine base images of the UI (node:24.18.1-alpine) and MCP
|
||||
# (python:3.13.14-alpine3.23) containers. CVE-2026-85091 is a heap overflow in
|
||||
# gz_vacate() reached only through non-blocking gzwrite() followed by gzprintf() after
|
||||
# a write stall. Node links its own bundled zlib and the MCP server never writes gzip
|
||||
# files, so neither image calls that path. TEMPORARY: the 1.3.2-r1 fix is in the
|
||||
# Alpine index and could be taken with `apk add --upgrade`, but we wait for the base
|
||||
# images to ship it instead (the newest node:24-alpine and python:3.13-alpine3.23 still
|
||||
# carry 1.3.2-r0). Pinned to that version so the rule stops matching on its own once a
|
||||
# base image moves forward. Remove when the base digests are bumped, by 2026-11-07.
|
||||
# https://security.alpinelinux.org/vuln/CVE-2026-85091
|
||||
- vulnerability: CVE-2026-85091
|
||||
package:
|
||||
name: zlib
|
||||
version: 1.3.2-r0
|
||||
Reference in new issue
Block a user