Skip to content

[container-image-scan] Container findings for python:alpine #49519

Description

@github-actions

Summary

Image: python:alpine
Pinned reference: python:alpine@sha256:26730869004e2b9c4b9ad09cab8625e81d256d1ce97e72df5520e806b1709f92

  • Vulnerabilities: 11 total — Critical: 0, High: 3, Medium: 8, Low: 0, Negligible: 0, Unknown: 0
  • License policy violations: 25

Remediation

  • Rebuild/update the image to pull in patched packages for the vulnerabilities listed below (fixed versions shown where available).
  • Review the licenses listed below against policy; consider replacing, removing, or granting an exception for flagged packages.
  • Re-run the scan after remediation to confirm the findings are resolved.

Critical & High severity vulnerabilities

[High] CVE-2026-11940: python@3.14.6 (fix: 3.15.0b4) ((nvd.nist.gov/redacted)
[High] CVE-2026-11972: python@3.14.6 (fix: 3.15.0b4) ((nvd.nist.gov/redacted)
[High] CVE-2026-15308: python@3.14.6 (fix: 3.15.0) ((nvd.nist.gov/redacted)
Medium / Low / Negligible / Unknown vulnerabilities (8 findings, 8 unique)
[Medium] CVE-2025-15366: python@3.14.6 (fix: 3.15.0a6) ((nvd.nist.gov/redacted)
[Medium] CVE-2025-15367: python@3.14.6 (fix: 3.15.0a6) ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: busybox-binsh@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: busybox@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: ssl_client@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-0864: python@3.14.6 (fix: 3.15.0b4) ((nvd.nist.gov/redacted)
[Medium] CVE-2026-12003: python@3.14.6 (fix: 3.15.0b3) ((nvd.nist.gov/redacted)
[Medium] CVE-2026-4360: python@3.14.6 ((nvd.nist.gov/redacted)
License policy violations (25 findings, 25 unique)
.python-rundeps@20260616.002228 (no licenses found)
Simple Launcher@1.1.0.14 (no licenses found)
alpine-baselayout-data@3.7.2-r1 (GPL-2.0-only)
alpine-baselayout@3.7.2-r1 (GPL-2.0-only)
apk-tools@3.0.6-r0 (GPL-2.0-only)
busybox-binsh@1.37.0-r31 (GPL-2.0-only)
busybox@1.37.0-r31 (GPL-2.0-only)
ca-certificates-bundle@20260611-r0 (MPL-2.0)
ca-certificates@20260611-r0 (MPL-2.0)
gdbm@1.26-r0 (GPL-3.0-or-later)
libapk@3.0.6-r0 (GPL-2.0-only)
libbz2@1.0.8-r6 (bzip2-1.0.6)
libncursesw@6.6_p20260516-r0 (X11)
libpanelw@6.6_p20260516-r0 (X11)
musl-utils@1.2.6-r2 (GPL-2.0-or-later)
ncurses-terminfo-base@6.6_p20260516-r0 (X11)
python@3.14.6 (no licenses found)
readline@8.3.3-r1 (GPL-3.0-or-later)
scanelf@1.3.9-r1 (GPL-2.0-only)
sqlite-libs@3.53.2-r0 (blessing)
ssl_client@1.37.0-r31 (GPL-2.0-only)
tzdata@2026b-r0 (Public-Domain)
xz-libs@5.8.3-r0 (0BSD, AND, GPL-2.0-or-later, LGPL-2.1-or-later, Public-Domain)
zlib@1.3.2-r0 (Zlib)
zstd-libs@1.5.7-r2 (GPL-2.0-or-later)

Generated by 🛡️ Daily Container Image Security Scan · auto · 285.1 AIC · ⌖ 8.51 AIC · ⊞ 6.3K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions