From 4328d92091638cbe70188fb2c831a61d1547ea09 Mon Sep 17 00:00:00 2001 From: Prowler Bot Date: Wed, 7 Oct 2026 12:35:35 +0200 Subject: [PATCH] chore(grype): suppress zlib CVE-2026-85091 until base images ship the fix (#12971) Co-authored-by: StylusFrost <43682773+StylusFrost@users.noreply.github.com> Co-authored-by: StylusFrost --- .grype.yaml | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/.grype.yaml b/.grype.yaml index 5028944529..81e6be2eb9 100644 --- a/.grype.yaml +++ b/.grype.yaml @@ -126,3 +126,18 @@ ignore: - vulnerability: CVE-2026-82049 package: name: python + + # zlib in the Alpine base images of the UI (node:24.18.1-alpine) and MCP + # (python:3.13.14-alpine3.23) containers. CVE-2026-85091 is a heap overflow in + # gz_vacate() reached only through non-blocking gzwrite() followed by gzprintf() after + # a write stall. Node links its own bundled zlib and the MCP server never writes gzip + # files, so neither image calls that path. TEMPORARY: the 1.3.2-r1 fix is in the + # Alpine index and could be taken with `apk add --upgrade`, but we wait for the base + # images to ship it instead (the newest node:24-alpine and python:3.13-alpine3.23 still + # carry 1.3.2-r0). Pinned to that version so the rule stops matching on its own once a + # base image moves forward. Remove when the base digests are bumped, by 2026-11-07. + # https://security.alpinelinux.org/vuln/CVE-2026-85091 + - vulnerability: CVE-2026-85091 + package: + name: zlib + version: 1.3.2-r0