Summary
Image: ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44@sha256:b50fbadba1...
5 High, 14 Medium, 3 Low vulnerabilities; 35 license policy violations.
Remediation
- Update Node.js to >= 22.23.2 / 24.18.1 / 26.5.1 to resolve all
node@22.23.1 CVEs (CVE-2026-56846, 56848, 56850, 58039-58045, 58039, 58044).
- Update
brace-expansion to >= 5.0.9, ip-address to >= 10.3.1, undici to >= 6.28.0, tar to >= 7.5.21, @opentelemetry/core to >= 2.8.0.
- Update Alpine
busybox/ssl_client/nghttp2-libs once patched packages are published (CVE-2025-60876, CVE-2026-58055).
- License violations are largely standard Alpine base-layer GPL-2.0/LGPL packages and Node/npm bundled BlueOak-1.0.0 dependencies — treat as accepted policy exception for base-OS/npm-runtime packages.
awf-api-proxy@1.0.0 (no licenses found) is the first-party package and should have a license field added to its package.json.
Vulnerabilities
22 vulnerabilities, primarily Node.js core and its bundled deps
| Severity |
ID |
Package |
Installed |
Fixed |
| High |
CVE-2026-56846 |
node |
22.23.1 |
22.23.2, 24.18.1 |
| High |
CVE-2026-56848 |
node |
22.23.1 |
22.23.2, 24.18.1, 26.5.1 |
| High |
GHSA-rgw5-rvv9-x895 |
brace-expansion |
5.0.7 |
5.0.9 |
| High |
GHSA-mh99-v99m-4gvg |
brace-expansion |
5.0.7 |
5.0.8 |
| High |
GHSA-mwp4-54f8-5fhr |
ip-address |
10.2.0 |
10.3.1 |
| High |
CVE-2026-58043 |
node |
22.23.1 |
22.23.2, 24.18.1, 26.5.1 |
| Medium |
CVE-2026-58042 |
node |
22.23.1 |
22.23.2, 24.18.1, 26.5.1 |
| Medium |
GHSA-8988-4f7v-96qf |
@opentelemetry/core |
1.30.1 |
2.8.0 |
| Medium |
CVE-2025-60876 |
busybox |
1.37.0-r31 |
not specified |
| Medium |
CVE-2025-60876 |
busybox-binsh |
1.37.0-r31 |
not specified |
| Medium |
CVE-2025-60876 |
ssl_client |
1.37.0-r31 |
not specified |
| Medium |
CVE-2026-58041 |
node |
22.23.1 |
22.23.2, 24.18.1, 26.5.1 |
| Medium |
GHSA-4xrf-jv44-h6hh |
ip-address |
10.2.0 |
10.2.2 |
| Medium |
CVE-2026-58040 |
node |
22.23.1 |
22.23.2, 24.18.1, 26.5.1 |
| Medium |
GHSA-22jq-vg5j-6vgg |
ip-address |
10.2.0 |
10.2.1 |
| Medium |
CVE-2026-58055 |
nghttp2-libs |
1.69.0-r0 |
not specified |
| Medium |
CVE-2026-58045 |
node |
22.23.1 |
22.23.2, 24.18.1, 26.5.1 |
| Medium |
GHSA-8xcm-r25x-g524 |
undici |
6.27.0 |
6.28.0 |
| Medium |
GHSA-v3r7-h72x-cjcm |
undici |
6.27.0 |
6.28.0 |
| Medium |
GHSA-m8rv-5g2x-5cg5 |
undici |
6.27.0 |
6.28.0 |
| Medium |
CVE-2026-56850 |
node |
22.23.1 |
22.23.2, 24.18.1, 26.5.1 |
| Medium |
GHSA-r292-9mhp-454m |
tar |
7.5.19 |
7.5.21 |
| Low |
CVE-2026-58044 |
node |
22.23.1 |
22.23.2, 24.18.1, 26.5.1 |
| Low |
CVE-2026-58039 |
node |
22.23.1 |
22.23.2, 24.18.1, 26.5.1 |
| Low |
CVE-2026-56847 |
node |
22.23.1 |
22.23.2, 24.18.1, 26.5.1 |
License Violations
35 rejected/unknown licenses
| Package |
Version |
License(s) |
| isexe |
4.0.0 |
BlueOak-1.0.0 |
| npm |
11.18.0 |
Artistic-2.0 |
| zstd-libs |
1.5.7-r2 |
GPL-2.0-or-later |
| path-scurry |
2.0.2 |
BlueOak-1.0.0 |
| tar |
7.5.19 |
BlueOak-1.0.0 |
| musl-utils |
1.2.6-r2 |
GPL-2.0-or-later |
| minipass |
7.1.3 |
BlueOak-1.0.0 |
| alpine-baselayout-data |
3.7.2-r1 |
GPL-2.0-only |
| apk-tools |
3.0.6-r0 |
GPL-2.0-only |
| libapk |
3.0.6-r0 |
GPL-2.0-only |
| scanelf |
1.3.9-r1 |
GPL-2.0-only |
| ca-certificates-bundle |
20260611-r0 |
MPL-2.0 |
| common-ancestor-path |
2.0.0 |
BlueOak-1.0.0 |
| libcurl |
8.21.0-r0 |
curl |
| spdx-license-ids |
3.0.23 |
CC0-1.0 |
| libidn2 |
2.3.8-r0 |
GPL-2.0-or-later, LGPL-3.0-or-later |
| awf-api-proxy |
1.0.0 |
no licenses found (first-party package — add license field) |
| yallist |
5.0.0 |
BlueOak-1.0.0 |
| libgcc |
15.2.0-r5 |
GPL-2.0-or-later, LGPL-2.1-or-later |
| zlib |
1.3.2-r0 |
Zlib |
| libunistring |
1.4.2-r0 |
GPL-2.0-or-later, LGPL-3.0-or-later |
| chownr |
3.0.0 |
BlueOak-1.0.0 |
| curl |
8.21.0-r0 |
curl |
| busybox |
1.37.0-r31 |
GPL-2.0-only |
| glob |
13.0.6 |
BlueOak-1.0.0 |
| busybox-binsh |
1.37.0-r31 |
GPL-2.0-only |
| minipass-flush |
1.0.6 |
BlueOak-1.0.0 |
| qrcode-terminal |
0.12.0 |
Apache 2.0 |
| minimatch |
10.2.5 |
BlueOak-1.0.0 |
| lru-cache |
11.5.1 |
BlueOak-1.0.0 |
| libstdc++ |
15.2.0-r5 |
GPL-2.0-or-later, LGPL-2.1-or-later |
| spdx-exceptions |
2.5.0 |
CC-BY-3.0 |
| node |
22.23.1 |
no licenses found |
| alpine-baselayout |
3.7.2-r1 |
GPL-2.0-only |
| ssl_client |
1.37.0-r31 |
GPL-2.0-only |
Generated by 🛡️ Daily Container Image Security Scan · auto · 327.5 AIC · ⌖ 10.6 AIC · ⊞ 6.5K · ◷
Summary
Image:
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44@sha256:b50fbadba1...5 High, 14 Medium, 3 Low vulnerabilities; 35 license policy violations.
Remediation
node@22.23.1CVEs (CVE-2026-56846, 56848, 56850, 58039-58045, 58039, 58044).brace-expansionto >= 5.0.9,ip-addressto >= 10.3.1,undicito >= 6.28.0,tarto >= 7.5.21,@opentelemetry/coreto >= 2.8.0.busybox/ssl_client/nghttp2-libsonce patched packages are published (CVE-2025-60876, CVE-2026-58055).awf-api-proxy@1.0.0 (no licenses found)is the first-party package and should have alicensefield added to its package.json.Vulnerabilities
22 vulnerabilities, primarily Node.js core and its bundled deps
@opentelemetry/coreLicense Violations
35 rejected/unknown licenses
licensefield)