Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/api-proxy #52454

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44@sha256:b50fbadba1...

5 High, 14 Medium, 3 Low vulnerabilities; 35 license policy violations.

Remediation

  • Update Node.js to >= 22.23.2 / 24.18.1 / 26.5.1 to resolve all node@22.23.1 CVEs (CVE-2026-56846, 56848, 56850, 58039-58045, 58039, 58044).
  • Update brace-expansion to >= 5.0.9, ip-address to >= 10.3.1, undici to >= 6.28.0, tar to >= 7.5.21, @opentelemetry/core to >= 2.8.0.
  • Update Alpine busybox/ssl_client/nghttp2-libs once patched packages are published (CVE-2025-60876, CVE-2026-58055).
  • License violations are largely standard Alpine base-layer GPL-2.0/LGPL packages and Node/npm bundled BlueOak-1.0.0 dependencies — treat as accepted policy exception for base-OS/npm-runtime packages. awf-api-proxy@1.0.0 (no licenses found) is the first-party package and should have a license field added to its package.json.

Vulnerabilities

22 vulnerabilities, primarily Node.js core and its bundled deps
Severity ID Package Installed Fixed
High CVE-2026-56846 node 22.23.1 22.23.2, 24.18.1
High CVE-2026-56848 node 22.23.1 22.23.2, 24.18.1, 26.5.1
High GHSA-rgw5-rvv9-x895 brace-expansion 5.0.7 5.0.9
High GHSA-mh99-v99m-4gvg brace-expansion 5.0.7 5.0.8
High GHSA-mwp4-54f8-5fhr ip-address 10.2.0 10.3.1
High CVE-2026-58043 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Medium CVE-2026-58042 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Medium GHSA-8988-4f7v-96qf @opentelemetry/core 1.30.1 2.8.0
Medium CVE-2025-60876 busybox 1.37.0-r31 not specified
Medium CVE-2025-60876 busybox-binsh 1.37.0-r31 not specified
Medium CVE-2025-60876 ssl_client 1.37.0-r31 not specified
Medium CVE-2026-58041 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Medium GHSA-4xrf-jv44-h6hh ip-address 10.2.0 10.2.2
Medium CVE-2026-58040 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Medium GHSA-22jq-vg5j-6vgg ip-address 10.2.0 10.2.1
Medium CVE-2026-58055 nghttp2-libs 1.69.0-r0 not specified
Medium CVE-2026-58045 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Medium GHSA-8xcm-r25x-g524 undici 6.27.0 6.28.0
Medium GHSA-v3r7-h72x-cjcm undici 6.27.0 6.28.0
Medium GHSA-m8rv-5g2x-5cg5 undici 6.27.0 6.28.0
Medium CVE-2026-56850 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Medium GHSA-r292-9mhp-454m tar 7.5.19 7.5.21
Low CVE-2026-58044 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Low CVE-2026-58039 node 22.23.1 22.23.2, 24.18.1, 26.5.1
Low CVE-2026-56847 node 22.23.1 22.23.2, 24.18.1, 26.5.1

License Violations

35 rejected/unknown licenses
Package Version License(s)
isexe 4.0.0 BlueOak-1.0.0
npm 11.18.0 Artistic-2.0
zstd-libs 1.5.7-r2 GPL-2.0-or-later
path-scurry 2.0.2 BlueOak-1.0.0
tar 7.5.19 BlueOak-1.0.0
musl-utils 1.2.6-r2 GPL-2.0-or-later
minipass 7.1.3 BlueOak-1.0.0
alpine-baselayout-data 3.7.2-r1 GPL-2.0-only
apk-tools 3.0.6-r0 GPL-2.0-only
libapk 3.0.6-r0 GPL-2.0-only
scanelf 1.3.9-r1 GPL-2.0-only
ca-certificates-bundle 20260611-r0 MPL-2.0
common-ancestor-path 2.0.0 BlueOak-1.0.0
libcurl 8.21.0-r0 curl
spdx-license-ids 3.0.23 CC0-1.0
libidn2 2.3.8-r0 GPL-2.0-or-later, LGPL-3.0-or-later
awf-api-proxy 1.0.0 no licenses found (first-party package — add license field)
yallist 5.0.0 BlueOak-1.0.0
libgcc 15.2.0-r5 GPL-2.0-or-later, LGPL-2.1-or-later
zlib 1.3.2-r0 Zlib
libunistring 1.4.2-r0 GPL-2.0-or-later, LGPL-3.0-or-later
chownr 3.0.0 BlueOak-1.0.0
curl 8.21.0-r0 curl
busybox 1.37.0-r31 GPL-2.0-only
glob 13.0.6 BlueOak-1.0.0
busybox-binsh 1.37.0-r31 GPL-2.0-only
minipass-flush 1.0.6 BlueOak-1.0.0
qrcode-terminal 0.12.0 Apache 2.0
minimatch 10.2.5 BlueOak-1.0.0
lru-cache 11.5.1 BlueOak-1.0.0
libstdc++ 15.2.0-r5 GPL-2.0-or-later, LGPL-2.1-or-later
spdx-exceptions 2.5.0 CC-BY-3.0
node 22.23.1 no licenses found
alpine-baselayout 3.7.2-r1 GPL-2.0-only
ssl_client 1.37.0-r31 GPL-2.0-only

Generated by 🛡️ Daily Container Image Security Scan · auto · 327.5 AIC · ⌖ 10.6 AIC · ⊞ 6.5K ·

Metadata

Metadata

Assignees

No one assigned

    Labels

    cookieIssue Monster Loves Cookies!security

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions