Releases: HomeLabHD/frappe-suite
Releases · HomeLabHD/frappe-suite
Release list
latest-dev
📦 frappe-suite — v16.33.0-dev+f823a00
Release type: prerelease • Commit:
f823a00
Security: 🛡️ ❌ Critical — 45 critical and 419 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/frappe-suite |
dev-f823a00 latest-dev latest-v16-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/frappe-suite |
dev-f823a00 latest-dev latest-v16-dev |
| GitHub Container Registry | ghcr.io/homelabhd/frappe-suite |
dev-f823a00 latest-dev latest-v16-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/frappe-suite
docker pull docker.io/hlhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c
cr.pcfae.com/hlhd/frappe-suite
docker pull cr.pcfae.com/hlhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c
ghcr.io/homelabhd/frappe-suite
docker pull ghcr.io/homelabhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c
Notable Changes
Documentation
- refresh generated badges (stagefreight)
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
Security
🛡️ ❌ Critical — 45 critical and 419 high vulnerabilities detected
Vulnerability details (45 critical, 419 high, 558 medium, 387 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2026-58016 | libglib2.0-0 | 2.74.6-2+deb12u9 | — | A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with... |
| Critical | CVE-2026-33845 | libgnutls30 | 3.7.9-2+deb12u5 | 3.7.9-2+deb12u7 | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read... |
| Critical | CVE-2026-42010 | libgnutls30 | 3.7.9-2+deb12u5 | 3.7.9-2+deb12u7 | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames... |
| Critical | CVE-2026-13221 | libperl5.36 | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When... |
| Critical | CVE-2026-42496 | libperl5.36 | 5.36.0-7+deb12u3 | — | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | libperl5.36 | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of... |
| Critical | CVE-2025-7458 | libsqlite3-0 | 3.40.1-2+deb12u2 | — | An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of... |
| Critical | CVE-2026-6653 | libxml2 | 2.9.14+dfsg-1.3~deb12u6 | — | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper... |
| Critical | CVE-2026-13221 | perl | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When... |
| Critical | CVE-2026-42496 | perl | 5.36.0-7+deb12u3 | — | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | perl | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of... |
| Critical | CVE-2026-13221 | perl-base | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When... |
| Critical | CVE-2026-42496 | perl-base | 5.36.0-7+deb12u3 | — | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | perl-base | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of... |
| Critical | CVE-2026-13221 | perl-modules-5.36 | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When... |
| Critical | CVE-2026-42496 | perl-modules-5.36 | 5.36.0-7+deb12u3 | — | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | perl-modules-5.36 | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of... |
| Critical | CVE-2023-45853 | zlib1g | 1:1.2.13.dfsg-1 | — | zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6 |
| Critical | CVE-2023-45133 | @babel/traverse | 7.21.5 | 7.23.2, 8.0.0-alpha.4 | babel: arbitrary code execution |
| Critical | CVE-2022-37601 | loader-utils | 0.2.17 | 2.0.3, 1.4.1 | loader-utils: prototype pollution in function parseQuery in parseQuery.js |
| Critical | CVE-2026-41242 | protobufjs | 7.2.6 | 8.0.1, 7.5.5 | protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields |
| Critical | CVE-2026-9277 | shell-quote | 1.8.1 | 1.8.4 | shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators |
| Critical | CVE-2026-59873 | tar | 7.5.1 | 7.5.19 | tar: node-tar: Denial of Service via crafted gzip bomb |
| Critical | CVE-2026-54466 | websocket-driver | 0.7.4 | 0.7.5 | websocket-driver is a WebSocket protocol handler with pluggable I/O. P ... |
| Critical | CVE-2023-24538 | stdlib | v1.19 | 1.19.8, 1.20.3 | Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals... |
| Critical | CVE-2023-24540 | stdlib | v1.19 | 1.19.9, 1.20.4 | Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript... |
| Critical | CVE-2024-24790 | stdlib | v1.19 | 1.21.11, 1.22.4 | The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms. |
| Critical | CVE-2025-68121 | stdlib | v1.19 | 1.24.13, 1.25.7, 1.26.0-rc.3 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may... |
| Critical | GHSA-76p3-8jx3-jpfq | loader-utils | 0.2.17 | 1.4.1 | Prototype pollution in webpack loader-utils |
| Critical | GO-2023-1703 | stdlib | go1.19 | 1.19.8 | Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals... |
| Critical | GO-2024-2887 | stdlib | go1.19 | 1.21.11 | The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms. |
| Critical | CVE-2023-29404 | stdlib | go1.19 | 1.19.10 | The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code... |
| Critical | CVE-2023-29405 | stdlib | go1.19 | 1.19.10 | The go command may e... |
dev-f823a00
📦 frappe-suite — v16.33.0-dev+f823a00
Release type: prerelease • Commit:
f823a00
Security: 🛡️ ❌ Critical — 45 critical and 419 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/frappe-suite |
dev-f823a00 latest-dev latest-v16-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/frappe-suite |
dev-f823a00 latest-dev latest-v16-dev |
| GitHub Container Registry | ghcr.io/homelabhd/frappe-suite |
dev-f823a00 latest-dev latest-v16-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/frappe-suite
docker pull docker.io/hlhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c
cr.pcfae.com/hlhd/frappe-suite
docker pull cr.pcfae.com/hlhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c
ghcr.io/homelabhd/frappe-suite
docker pull ghcr.io/homelabhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c
Notable Changes
Documentation
- refresh generated badges (stagefreight)
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
Security
🛡️ ❌ Critical — 45 critical and 419 high vulnerabilities detected
Vulnerability details (45 critical, 419 high, 558 medium, 387 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2026-58016 | libglib2.0-0 | 2.74.6-2+deb12u9 | — | A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with... |
| Critical | CVE-2026-33845 | libgnutls30 | 3.7.9-2+deb12u5 | 3.7.9-2+deb12u7 | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read... |
| Critical | CVE-2026-42010 | libgnutls30 | 3.7.9-2+deb12u5 | 3.7.9-2+deb12u7 | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames... |
| Critical | CVE-2026-13221 | libperl5.36 | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When... |
| Critical | CVE-2026-42496 | libperl5.36 | 5.36.0-7+deb12u3 | — | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | libperl5.36 | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of... |
| Critical | CVE-2025-7458 | libsqlite3-0 | 3.40.1-2+deb12u2 | — | An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of... |
| Critical | CVE-2026-6653 | libxml2 | 2.9.14+dfsg-1.3~deb12u6 | — | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper... |
| Critical | CVE-2026-13221 | perl | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When... |
| Critical | CVE-2026-42496 | perl | 5.36.0-7+deb12u3 | — | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | perl | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of... |
| Critical | CVE-2026-13221 | perl-base | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When... |
| Critical | CVE-2026-42496 | perl-base | 5.36.0-7+deb12u3 | — | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | perl-base | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of... |
| Critical | CVE-2026-13221 | perl-modules-5.36 | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When... |
| Critical | CVE-2026-42496 | perl-modules-5.36 | 5.36.0-7+deb12u3 | — | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | perl-modules-5.36 | 5.36.0-7+deb12u3 | — | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of... |
| Critical | CVE-2023-45853 | zlib1g | 1:1.2.13.dfsg-1 | — | zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6 |
| Critical | CVE-2023-45133 | @babel/traverse | 7.21.5 | 7.23.2, 8.0.0-alpha.4 | babel: arbitrary code execution |
| Critical | CVE-2022-37601 | loader-utils | 0.2.17 | 2.0.3, 1.4.1 | loader-utils: prototype pollution in function parseQuery in parseQuery.js |
| Critical | CVE-2026-41242 | protobufjs | 7.2.6 | 8.0.1, 7.5.5 | protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields |
| Critical | CVE-2026-9277 | shell-quote | 1.8.1 | 1.8.4 | shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators |
| Critical | CVE-2026-59873 | tar | 7.5.1 | 7.5.19 | tar: node-tar: Denial of Service via crafted gzip bomb |
| Critical | CVE-2026-54466 | websocket-driver | 0.7.4 | 0.7.5 | websocket-driver is a WebSocket protocol handler with pluggable I/O. P ... |
| Critical | CVE-2023-24538 | stdlib | v1.19 | 1.19.8, 1.20.3 | Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals... |
| Critical | CVE-2023-24540 | stdlib | v1.19 | 1.19.9, 1.20.4 | Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript... |
| Critical | CVE-2024-24790 | stdlib | v1.19 | 1.21.11, 1.22.4 | The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms. |
| Critical | CVE-2025-68121 | stdlib | v1.19 | 1.24.13, 1.25.7, 1.26.0-rc.3 | During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may... |
| Critical | GHSA-76p3-8jx3-jpfq | loader-utils | 0.2.17 | 1.4.1 | Prototype pollution in webpack loader-utils |
| Critical | GO-2023-1703 | stdlib | go1.19 | 1.19.8 | Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals... |
| Critical | GO-2024-2887 | stdlib | go1.19 | 1.21.11 | The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms. |
| Critical | CVE-2023-29404 | stdlib | go1.19 | 1.19.10 | The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code... |
| Critical | CVE-2023-29405 | stdlib | go1.19 | 1.19.10 | The go command may e... |