diff --git a/mcp_server/Dockerfile b/mcp_server/Dockerfile index db8d9bbb8f..a2ba13ff6c 100644 --- a/mcp_server/Dockerfile +++ b/mcp_server/Dockerfile @@ -29,15 +29,21 @@ FROM python:3.13.14-alpine3.23@sha256:9fdbf2e3e82628351513560b121e2ee6ce31cac212 LABEL maintainer="https://github.com/prowler-cloud" -# CVE-2026-11822 and CVE-2026-11824, both high, are fixed in Alpine 3.23's -# sqlite 3.53.4-r0. The base image pins python 3.13.14, which has not been -# rebuilt since that package was published and still ships 3.51.2-r0, so the -# upgrade is taken here rather than by moving the pin -- the newest published -# python:3.13-alpine3.23 carries the same vulnerable version. +# High CVEs fixed in Alpine 3.23 but not yet in the pinned base image: +# sqlite-libs 3.53.4-r0 CVE-2026-11822, CVE-2026-11824 (image ships 3.51.2-r0) +# libcrypto3/libssl3 3.5.8-r0 CVE-2026-14456 (image ships 3.5.7-r0) +# The base image pins python 3.13.14, which has not been rebuilt since those +# packages were published, so the upgrade is taken here rather than by moving +# the pin -- the newest published python:3.13-alpine3.23 carries the same +# vulnerable versions. libcrypto3 and libssl3 are both built from openssl and +# are flagged separately, so both are named. # `>=` rather than `=`: Alpine keeps only the newest build of a package in a -# branch's index, so an exact pin breaks this build the day 3.53.4-r0 is -# superseded. Drop this once the base image ships 3.53.4-r0 or later. -RUN apk add --no-cache --upgrade "sqlite-libs>=3.53.4-r0" +# branch's index, so an exact pin breaks this build the day one of these is +# superseded. Drop an entry once the base image ships that version or later. +RUN apk add --no-cache --upgrade \ + "sqlite-libs>=3.53.4-r0" \ + "libcrypto3>=3.5.8-r0" \ + "libssl3>=3.5.8-r0" # Create non-root user for security # Using specific UID/GID for consistency across environments diff --git a/mcp_server/changelog.d/mcp-image-openssl-cve.security.md b/mcp_server/changelog.d/mcp-image-openssl-cve.security.md new file mode 100644 index 0000000000..9eb80f75a9 --- /dev/null +++ b/mcp_server/changelog.d/mcp-image-openssl-cve.security.md @@ -0,0 +1 @@ +`libcrypto3` and `libssl3` upgraded to 3.5.8-r0 in the container image, patching CVE-2026-14456