Skip to content

latest-dev

Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 02 Sep 23:21
· 1 commit to main since this release

πŸ“¦ frappe-suite β€” v16.33.0-dev+f823a00

Release type: prerelease β€’ Commit: f823a00

Security: πŸ›‘οΈ ❌ Critical β€” 45 critical and 419 high vulnerabilities detected

Image Availability

Registry Image Tags
Docker Hub docker.io/hlhd/frappe-suite dev-f823a00 latest-dev latest-v16-dev
cr.pcfae.com cr.pcfae.com/hlhd/frappe-suite dev-f823a00 latest-dev latest-v16-dev
GitHub Container Registry ghcr.io/homelabhd/frappe-suite dev-f823a00 latest-dev latest-v16-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/frappe-suite

docker pull docker.io/hlhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c

cr.pcfae.com/hlhd/frappe-suite

docker pull cr.pcfae.com/hlhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c

ghcr.io/homelabhd/frappe-suite

docker pull ghcr.io/homelabhd/frappe-suite@sha256:442ece78cac1275c7e7a14a736464058f3eb8202d5eea4b90ce5871d33c33f4c

Notable Changes

Documentation

  • refresh generated badges (stagefreight)

Maintenance

  • governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)

Security

πŸ›‘οΈ ❌ Critical β€” 45 critical and 419 high vulnerabilities detected

Vulnerability details (45 critical, 419 high, 558 medium, 387 low)
Severity CVE Package Installed Fixed Description
Critical CVE-2026-58016 libglib2.0-0 2.74.6-2+deb12u9 β€” A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with...
Critical CVE-2026-33845 libgnutls30 3.7.9-2+deb12u5 3.7.9-2+deb12u7 A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read...
Critical CVE-2026-42010 libgnutls30 3.7.9-2+deb12u5 3.7.9-2+deb12u7 A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames...
Critical CVE-2026-13221 libperl5.36 5.36.0-7+deb12u3 β€” Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When...
Critical CVE-2026-42496 libperl5.36 5.36.0-7+deb12u3 β€” Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()...
Critical CVE-2026-8376 libperl5.36 5.36.0-7+deb12u3 β€” Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of...
Critical CVE-2025-7458 libsqlite3-0 3.40.1-2+deb12u2 β€” An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of...
Critical CVE-2026-6653 libxml2 2.9.14+dfsg-1.3~deb12u6 β€” Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper...
Critical CVE-2026-13221 perl 5.36.0-7+deb12u3 β€” Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When...
Critical CVE-2026-42496 perl 5.36.0-7+deb12u3 β€” Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()...
Critical CVE-2026-8376 perl 5.36.0-7+deb12u3 β€” Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of...
Critical CVE-2026-13221 perl-base 5.36.0-7+deb12u3 β€” Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When...
Critical CVE-2026-42496 perl-base 5.36.0-7+deb12u3 β€” Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()...
Critical CVE-2026-8376 perl-base 5.36.0-7+deb12u3 β€” Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of...
Critical CVE-2026-13221 perl-modules-5.36 5.36.0-7+deb12u3 β€” Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When...
Critical CVE-2026-42496 perl-modules-5.36 5.36.0-7+deb12u3 β€” Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()...
Critical CVE-2026-8376 perl-modules-5.36 5.36.0-7+deb12u3 β€” Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of...
Critical CVE-2023-45853 zlib1g 1:1.2.13.dfsg-1 β€” zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6
Critical CVE-2023-45133 @babel/traverse 7.21.5 7.23.2, 8.0.0-alpha.4 babel: arbitrary code execution
Critical CVE-2022-37601 loader-utils 0.2.17 2.0.3, 1.4.1 loader-utils: prototype pollution in function parseQuery in parseQuery.js
Critical CVE-2026-41242 protobufjs 7.2.6 8.0.1, 7.5.5 protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields
Critical CVE-2026-9277 shell-quote 1.8.1 1.8.4 shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators
Critical CVE-2026-59873 tar 7.5.1 7.5.19 tar: node-tar: Denial of Service via crafted gzip bomb
Critical CVE-2026-54466 websocket-driver 0.7.4 0.7.5 websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...
Critical CVE-2023-24538 stdlib v1.19 1.19.8, 1.20.3 Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals...
Critical CVE-2023-24540 stdlib v1.19 1.19.9, 1.20.4 Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript...
Critical CVE-2024-24790 stdlib v1.19 1.21.11, 1.22.4 The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
Critical CVE-2025-68121 stdlib v1.19 1.24.13, 1.25.7, 1.26.0-rc.3 During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may...
Critical GHSA-76p3-8jx3-jpfq loader-utils 0.2.17 1.4.1 Prototype pollution in webpack loader-utils
Critical GO-2023-1703 stdlib go1.19 1.19.8 Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals...
Critical GO-2024-2887 stdlib go1.19 1.21.11 The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
Critical CVE-2023-29404 stdlib go1.19 1.19.10 The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code...
Critical CVE-2023-29405 stdlib go1.19 1.19.10 The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code...
Critical CVE-2023-29402 stdlib go1.19 1.19.10 The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo...
Critical GO-2023-1752 stdlib go1.19 1.19.9 Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript...
Critical CVE-2023-24531 stdlib go1.19 1.21.0-0 Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad...
Critical GHSA-w7jw-789q-3m8p shell-quote 1.8.1 1.8.4 shell-quote quote() does not escape newlines in object .op values
Critical GO-2026-4337 stdlib go1.19 1.24.13 During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may...
Critical GO-2025-3563 stdlib go1.19 1.23.8 The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines...
Critical GHSA-xq3m-2v4x-88gg protobufjs 7.2.6 7.5.5 Arbitrary code execution in protobufjs
Critical CVE-2026-27143 stdlib go1.19 1.25.9 Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially...
Critical GHSA-23hp-3jrh-7fpw tar 7.5.1 7.5.19 node-tar: Decompression/parse DoS via unlimited input
Critical GHSA-67hx-6x53-jw92 @babel/traverse 7.21.5 7.23.2 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
Critical GHSA-xv26-6w52-cph6 websocket-driver 0.7.4 0.7.5 websocket-driver: Message corruption via abuse of protocol length headers
Critical GHSA-2jcg-qqmg-46q6 monorepo-symlink-test 0.0.0 β€” Malware in monorepo-symlink-test
High CVE-2026-53613 bsdutils 1:2.38.1-5+deb12u3 β€” util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
High CVE-2026-12064 curl 7.88.1-10+deb12u15 β€” When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl...
High CVE-2026-6276 curl 7.88.1-10+deb12u15 β€” Using libcurl, when a custom Host: header is first set for an HTTP request and a second request is subsequently done using the same easy handle but without the custom Host: header set, the...
High CVE-2026-8286 curl 7.88.1-10+deb12u15 β€” A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
High CVE-2026-8458 curl 7.88.1-10+deb12u15 β€” libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent...
High CVE-2026-8927 curl 7.88.1-10+deb12u15 β€” When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests...
High CVE-2026-41992 gzip 1.12-1 β€” GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single...
High CVE-2026-54369 libacl1 2.3.1-3 β€” acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that...
High CVE-2026-53613 libblkid1 2.38.1-5+deb12u3 β€” util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
High CVE-2026-12064 libcurl3-gnutls 7.88.1-10+deb12u15 β€” When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl...
High CVE-2026-6276 libcurl3-gnutls 7.88.1-10+deb12u15 β€” Using libcurl, when a custom Host: header is first set for an HTTP request and a second request is subsequently done using the same easy handle but without the custom Host: header set, the...
High CVE-2026-8286 libcurl3-gnutls 7.88.1-10+deb12u15 β€” A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
High CVE-2026-8458 libcurl3-gnutls 7.88.1-10+deb12u15 β€” libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent...
High CVE-2026-8927 libcurl3-gnutls 7.88.1-10+deb12u15 β€” When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests...
High CVE-2026-12064 libcurl4 7.88.1-10+deb12u15 β€” When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl...
High CVE-2026-6276 libcurl4 7.88.1-10+deb12u15 β€” Using libcurl, when a custom Host: header is first set for an HTTP request and a second request is subsequently done using the same easy handle but without the custom Host: header set, the...
High CVE-2026-8286 libcurl4 7.88.1-10+deb12u15 β€” A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
High CVE-2026-8458 libcurl4 7.88.1-10+deb12u15 β€” libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent...
High CVE-2026-8927 libcurl4 7.88.1-10+deb12u15 β€” When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests...
High CVE-2025-59375 libexpat1 2.5.0-1+deb12u3 β€” firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing
High CVE-2026-25210 libexpat1 2.5.0-1+deb12u3 β€” In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.
High CVE-2026-45186 libexpat1 2.5.0-1+deb12u3 β€” In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
High CVE-2026-66046 libexpat1 2.5.0-1+deb12u3 β€” Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with...
High CVE-2026-58010 libglib2.0-0 2.74.6-2+deb12u9 β€” A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check...
High CVE-2026-58011 libglib2.0-0 2.74.6-2+deb12u9 β€” A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the...
High CVE-2026-58012 libglib2.0-0 2.74.6-2+deb12u9 β€” A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the G_REGEX_RAW compile flag and case-change replacement escapes because the string_append...
High CVE-2026-58013 libglib2.0-0 2.74.6-2+deb12u9 β€” A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing...
High CVE-2026-58014 libglib2.0-0 2.74.6-2+deb12u9 β€” A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value...
High CVE-2026-58015 libglib2.0-0 2.74.6-2+deb12u9 β€” A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server...
High CVE-2026-33846 libgnutls30 3.7.9-2+deb12u5 3.7.9-2+deb12u7 A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS...
High CVE-2026-3833 libgnutls30 3.7.9-2+deb12u5 3.7.9-2+deb12u7 A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of nameConstraints labels, specifically for dNSName (DNS) or rfc822Name (email)...
High CVE-2026-42009 libgnutls30 3.7.9-2+deb12u5 3.7.9-2+deb12u7 A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic...
High CVE-2023-25193 libharfbuzz-subset0 6.0.0+dfsg-3 β€” hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
High CVE-2023-25193 libharfbuzz0b 6.0.0+dfsg-3 β€” hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
High CVE-2023-2953 libldap-2.5-0 2.5.13+dfsg-5 β€” A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
High CVE-2026-53613 libmount1 2.38.1-5+deb12u3 β€” util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
High CVE-2025-69720 libncurses6 6.4-4 β€” The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
High CVE-2025-69720 libncursesw6 6.4-4 β€” The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
High CVE-2026-42497 libperl5.36 5.36.0-7+deb12u3 β€” Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without...
High CVE-2026-48962 libperl5.36 5.36.0-7+deb12u3 β€” IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string...
High CVE-2026-57432 libperl5.36 5.36.0-7+deb12u3 β€” Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count...
High CVE-2026-57433 libperl5.36 5.36.0-7+deb12u3 β€” Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and...
High CVE-2026-9538 libperl5.36 5.36.0-7+deb12u3 β€” Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data...
High CVE-2026-53613 libsmartcols1 2.38.1-5+deb12u3 β€” util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
High CVE-2026-37555 libsndfile1 1.2.0-1+deb12u1 β€” An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not...
High CVE-2026-11822 libsqlite3-0 3.40.1-2+deb12u2 β€” SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution...
High CVE-2026-11824 libsqlite3-0 3.40.1-2+deb12u2 β€” SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a...
High CVE-2026-58050 libssh2-1 1.10.0-3+b1 β€” libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without...
High CVE-2026-7598 libssh2-1 1.10.0-3+b1 β€” A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c...
High CVE-2025-69720 libtinfo6 6.4-4 β€” The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
High CVE-2026-53613 libuuid1 2.38.1-5+deb12u3 β€” util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
High CVE-2026-53613 mount 2.38.1-5+deb12u3 β€” util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
High CVE-2025-69720 ncurses-base 6.4-4 β€” The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
High CVE-2025-69720 ncurses-bin 6.4-4 β€” The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
High CVE-2026-42533 nginx 1.22.1-9+deb12u9 β€” A vulnerability exists in NGINX Plus and NGINX Open Source when a mapΒ directive uses regex matching and a string expression references the map's regex capture variables before referencing the map...

... and 1309 more of lower severity (see full report in release assets)

---
Full changelog
  • [f823a00] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [7349335] refresh generated badges (stagefreight)