diff --git a/.grype.yaml b/.grype.yaml index 5028944529..81e6be2eb9 100644 --- a/.grype.yaml +++ b/.grype.yaml @@ -126,3 +126,18 @@ ignore: - vulnerability: CVE-2026-82049 package: name: python + + # zlib in the Alpine base images of the UI (node:24.18.1-alpine) and MCP + # (python:3.13.14-alpine3.23) containers. CVE-2026-85091 is a heap overflow in + # gz_vacate() reached only through non-blocking gzwrite() followed by gzprintf() after + # a write stall. Node links its own bundled zlib and the MCP server never writes gzip + # files, so neither image calls that path. TEMPORARY: the 1.3.2-r1 fix is in the + # Alpine index and could be taken with `apk add --upgrade`, but we wait for the base + # images to ship it instead (the newest node:24-alpine and python:3.13-alpine3.23 still + # carry 1.3.2-r0). Pinned to that version so the rule stops matching on its own once a + # base image moves forward. Remove when the base digests are bumped, by 2026-11-07. + # https://security.alpinelinux.org/vuln/CVE-2026-85091 + - vulnerability: CVE-2026-85091 + package: + name: zlib + version: 1.3.2-r0