Skip to content

Releases: HomeLabHD/frappe-suite

latest-dev

latest-dev Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 02 Sep 23:21

📦 frappe-suite — v16.33.0-dev+f823a00

Release type: prerelease • Commit: f823a00

Security: 🛡️ ❌ Critical — 45 critical and 419 high vulnerabilities detected

Image Availability

Registry Image Tags
Docker Hub docker.io/hlhd/frappe-suite dev-f823a00 latest-dev latest-v16-dev
cr.pcfae.com cr.pcfae.com/hlhd/frappe-suite dev-f823a00 latest-dev latest-v16-dev
GitHub Container Registry ghcr.io/homelabhd/frappe-suite dev-f823a00 latest-dev latest-v16-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/frappe-suite

docker pull docker.io/hlhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c

cr.pcfae.com/hlhd/frappe-suite

docker pull cr.pcfae.com/hlhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c

ghcr.io/homelabhd/frappe-suite

docker pull ghcr.io/homelabhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c

Notable Changes

Documentation

  • refresh generated badges (stagefreight)

Maintenance

  • governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)

Security

🛡️ ❌ Critical — 45 critical and 419 high vulnerabilities detected

Vulnerability details (45 critical, 419 high, 558 medium, 387 low)
Severity CVE Package Installed Fixed Description
Critical CVE-2026-58016 libglib2.0-0 2.74.6-2+deb12u9 A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with...
Critical CVE-2026-33845 libgnutls30 3.7.9-2+deb12u5 3.7.9-2+deb12u7 A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read...
Critical CVE-2026-42010 libgnutls30 3.7.9-2+deb12u5 3.7.9-2+deb12u7 A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames...
Critical CVE-2026-13221 libperl5.36 5.36.0-7+deb12u3 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When...
Critical CVE-2026-42496 libperl5.36 5.36.0-7+deb12u3 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()...
Critical CVE-2026-8376 libperl5.36 5.36.0-7+deb12u3 Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of...
Critical CVE-2025-7458 libsqlite3-0 3.40.1-2+deb12u2 An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of...
Critical CVE-2026-6653 libxml2 2.9.14+dfsg-1.3~deb12u6 Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper...
Critical CVE-2026-13221 perl 5.36.0-7+deb12u3 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When...
Critical CVE-2026-42496 perl 5.36.0-7+deb12u3 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()...
Critical CVE-2026-8376 perl 5.36.0-7+deb12u3 Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of...
Critical CVE-2026-13221 perl-base 5.36.0-7+deb12u3 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When...
Critical CVE-2026-42496 perl-base 5.36.0-7+deb12u3 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()...
Critical CVE-2026-8376 perl-base 5.36.0-7+deb12u3 Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of...
Critical CVE-2026-13221 perl-modules-5.36 5.36.0-7+deb12u3 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When...
Critical CVE-2026-42496 perl-modules-5.36 5.36.0-7+deb12u3 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()...
Critical CVE-2026-8376 perl-modules-5.36 5.36.0-7+deb12u3 Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of...
Critical CVE-2023-45853 zlib1g 1:1.2.13.dfsg-1 zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6
Critical CVE-2023-45133 @babel/traverse 7.21.5 7.23.2, 8.0.0-alpha.4 babel: arbitrary code execution
Critical CVE-2022-37601 loader-utils 0.2.17 2.0.3, 1.4.1 loader-utils: prototype pollution in function parseQuery in parseQuery.js
Critical CVE-2026-41242 protobufjs 7.2.6 8.0.1, 7.5.5 protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields
Critical CVE-2026-9277 shell-quote 1.8.1 1.8.4 shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators
Critical CVE-2026-59873 tar 7.5.1 7.5.19 tar: node-tar: Denial of Service via crafted gzip bomb
Critical CVE-2026-54466 websocket-driver 0.7.4 0.7.5 websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...
Critical CVE-2023-24538 stdlib v1.19 1.19.8, 1.20.3 Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals...
Critical CVE-2023-24540 stdlib v1.19 1.19.9, 1.20.4 Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript...
Critical CVE-2024-24790 stdlib v1.19 1.21.11, 1.22.4 The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
Critical CVE-2025-68121 stdlib v1.19 1.24.13, 1.25.7, 1.26.0-rc.3 During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may...
Critical GHSA-76p3-8jx3-jpfq loader-utils 0.2.17 1.4.1 Prototype pollution in webpack loader-utils
Critical GO-2023-1703 stdlib go1.19 1.19.8 Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals...
Critical GO-2024-2887 stdlib go1.19 1.21.11 The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
Critical CVE-2023-29404 stdlib go1.19 1.19.10 The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code...
Critical CVE-2023-29405 stdlib go1.19 1.19.10 The go command may e...
Read more

dev-f823a00

dev-f823a00 Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 02 Sep 23:21

📦 frappe-suite — v16.33.0-dev+f823a00

Release type: prerelease • Commit: f823a00

Security: 🛡️ ❌ Critical — 45 critical and 419 high vulnerabilities detected

Image Availability

Registry Image Tags
Docker Hub docker.io/hlhd/frappe-suite dev-f823a00 latest-dev latest-v16-dev
cr.pcfae.com cr.pcfae.com/hlhd/frappe-suite dev-f823a00 latest-dev latest-v16-dev
GitHub Container Registry ghcr.io/homelabhd/frappe-suite dev-f823a00 latest-dev latest-v16-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/frappe-suite

docker pull docker.io/hlhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c

cr.pcfae.com/hlhd/frappe-suite

docker pull cr.pcfae.com/hlhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c

ghcr.io/homelabhd/frappe-suite

docker pull ghcr.io/homelabhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c

Notable Changes

Documentation

  • refresh generated badges (stagefreight)

Maintenance

  • governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)

Security

🛡️ ❌ Critical — 45 critical and 419 high vulnerabilities detected

Vulnerability details (45 critical, 419 high, 558 medium, 387 low)
Severity CVE Package Installed Fixed Description
Critical CVE-2026-58016 libglib2.0-0 2.74.6-2+deb12u9 A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with...
Critical CVE-2026-33845 libgnutls30 3.7.9-2+deb12u5 3.7.9-2+deb12u7 A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read...
Critical CVE-2026-42010 libgnutls30 3.7.9-2+deb12u5 3.7.9-2+deb12u7 A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames...
Critical CVE-2026-13221 libperl5.36 5.36.0-7+deb12u3 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When...
Critical CVE-2026-42496 libperl5.36 5.36.0-7+deb12u3 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()...
Critical CVE-2026-8376 libperl5.36 5.36.0-7+deb12u3 Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of...
Critical CVE-2025-7458 libsqlite3-0 3.40.1-2+deb12u2 An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of...
Critical CVE-2026-6653 libxml2 2.9.14+dfsg-1.3~deb12u6 Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper...
Critical CVE-2026-13221 perl 5.36.0-7+deb12u3 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When...
Critical CVE-2026-42496 perl 5.36.0-7+deb12u3 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()...
Critical CVE-2026-8376 perl 5.36.0-7+deb12u3 Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of...
Critical CVE-2026-13221 perl-base 5.36.0-7+deb12u3 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When...
Critical CVE-2026-42496 perl-base 5.36.0-7+deb12u3 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()...
Critical CVE-2026-8376 perl-base 5.36.0-7+deb12u3 Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of...
Critical CVE-2026-13221 perl-modules-5.36 5.36.0-7+deb12u3 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When...
Critical CVE-2026-42496 perl-modules-5.36 5.36.0-7+deb12u3 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()...
Critical CVE-2026-8376 perl-modules-5.36 5.36.0-7+deb12u3 Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of...
Critical CVE-2023-45853 zlib1g 1:1.2.13.dfsg-1 zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6
Critical CVE-2023-45133 @babel/traverse 7.21.5 7.23.2, 8.0.0-alpha.4 babel: arbitrary code execution
Critical CVE-2022-37601 loader-utils 0.2.17 2.0.3, 1.4.1 loader-utils: prototype pollution in function parseQuery in parseQuery.js
Critical CVE-2026-41242 protobufjs 7.2.6 8.0.1, 7.5.5 protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields
Critical CVE-2026-9277 shell-quote 1.8.1 1.8.4 shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators
Critical CVE-2026-59873 tar 7.5.1 7.5.19 tar: node-tar: Denial of Service via crafted gzip bomb
Critical CVE-2026-54466 websocket-driver 0.7.4 0.7.5 websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...
Critical CVE-2023-24538 stdlib v1.19 1.19.8, 1.20.3 Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals...
Critical CVE-2023-24540 stdlib v1.19 1.19.9, 1.20.4 Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript...
Critical CVE-2024-24790 stdlib v1.19 1.21.11, 1.22.4 The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
Critical CVE-2025-68121 stdlib v1.19 1.24.13, 1.25.7, 1.26.0-rc.3 During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may...
Critical GHSA-76p3-8jx3-jpfq loader-utils 0.2.17 1.4.1 Prototype pollution in webpack loader-utils
Critical GO-2023-1703 stdlib go1.19 1.19.8 Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals...
Critical GO-2024-2887 stdlib go1.19 1.21.11 The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
Critical CVE-2023-29404 stdlib go1.19 1.19.10 The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code...
Critical CVE-2023-29405 stdlib go1.19 1.19.10 The go command may e...
Read more