From f299e1d9acd14471f9c1b6491a48fa0ef8128097 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Rub=C3=A9n=20De=20la=20Torre=20Vico?= Date: Tue, 25 Aug 2026 17:41:44 +0200 Subject: [PATCH] fix(mcp): patch the two high sqlite CVEs in the container image (#12537) --- .github/workflows/mcp-container-build-push.yml | 2 ++ .github/workflows/mcp-container-checks.yml | 2 ++ mcp_server/Dockerfile | 10 ++++++++++ .../changelog.d/mcp-image-sqlite-cves.security.md | 1 + 4 files changed, 15 insertions(+) create mode 100644 mcp_server/changelog.d/mcp-image-sqlite-cves.security.md diff --git a/.github/workflows/mcp-container-build-push.yml b/.github/workflows/mcp-container-build-push.yml index a5116d63be..0e652c703c 100644 --- a/.github/workflows/mcp-container-build-push.yml +++ b/.github/workflows/mcp-container-build-push.yml @@ -114,6 +114,8 @@ jobs: egress-policy: block allowed-endpoints: > auth.docker.io:443 + dl-cdn.alpinelinux.org:443 + dualstack.j.sni.global.fastly.net:443 files.pythonhosted.org:443 ghcr.io:443 github.com:443 diff --git a/.github/workflows/mcp-container-checks.yml b/.github/workflows/mcp-container-checks.yml index a5b8104b88..ce6d02f17d 100644 --- a/.github/workflows/mcp-container-checks.yml +++ b/.github/workflows/mcp-container-checks.yml @@ -81,6 +81,8 @@ jobs: pkg-containers.githubusercontent.com:443 files.pythonhosted.org:443 pypi.org:443 + dl-cdn.alpinelinux.org:443 + dualstack.j.sni.global.fastly.net:443 api.github.com:443 mirror.gcr.io:443 check.trivy.dev:443 diff --git a/mcp_server/Dockerfile b/mcp_server/Dockerfile index 195bfe1eae..db8d9bbb8f 100644 --- a/mcp_server/Dockerfile +++ b/mcp_server/Dockerfile @@ -29,6 +29,16 @@ FROM python:3.13.14-alpine3.23@sha256:9fdbf2e3e82628351513560b121e2ee6ce31cac212 LABEL maintainer="https://github.com/prowler-cloud" +# CVE-2026-11822 and CVE-2026-11824, both high, are fixed in Alpine 3.23's +# sqlite 3.53.4-r0. The base image pins python 3.13.14, which has not been +# rebuilt since that package was published and still ships 3.51.2-r0, so the +# upgrade is taken here rather than by moving the pin -- the newest published +# python:3.13-alpine3.23 carries the same vulnerable version. +# `>=` rather than `=`: Alpine keeps only the newest build of a package in a +# branch's index, so an exact pin breaks this build the day 3.53.4-r0 is +# superseded. Drop this once the base image ships 3.53.4-r0 or later. +RUN apk add --no-cache --upgrade "sqlite-libs>=3.53.4-r0" + # Create non-root user for security # Using specific UID/GID for consistency across environments RUN addgroup -g 1001 prowler && \ diff --git a/mcp_server/changelog.d/mcp-image-sqlite-cves.security.md b/mcp_server/changelog.d/mcp-image-sqlite-cves.security.md new file mode 100644 index 0000000000..e69ac2a161 --- /dev/null +++ b/mcp_server/changelog.d/mcp-image-sqlite-cves.security.md @@ -0,0 +1 @@ +`sqlite-libs` upgraded to 3.53.4-r0 in the container image, patching CVE-2026-11822 and CVE-2026-11824