Replies: 2 comments
|
Recommended path is to migrate to Xberg v5. Kreuzberg v4.9.9 is the last v4 line and should be treated as legacy; ongoing dependency/base-image security updates are expected to land in Xberg releases. At the moment we are not planning a patched v4 image for CVE‑2026‑9076. Since this is in OpenSSL/Debian rather than Kreuzberg application code, the fix path is: Debian publishes the fixed package → the Xberg base image is rebuilt → a new Xberg image is released. If you must remain on v4 short term, the safest workaround is to rebuild the v4 image against a Debian base that contains the fixed OpenSSL package and validate that artifact with your scanner. For planning, treat Xberg v5 as the supported security-update path. |
0 replies
|
Thanks for the guidance. There is an official patch available for
CVE‑2026‑9076
so I will switch to v5 and wait for the update,
…On Tue, Jun 30, 2026 at 12:13 PM VectorPeak ***@***.***> wrote:
Recommended path is to migrate to Xberg v5. Kreuzberg v4.9.9 is the last
v4 line and should be treated as legacy; ongoing dependency/base-image
security updates are expected to land in Xberg releases.
At the moment we are not planning a patched v4 image for CVE‑2026‑9076.
Since this is in OpenSSL/Debian rather than Kreuzberg application code, the
fix path is: Debian publishes the fixed package → the Xberg base image is
rebuilt → a new Xberg image is released.
If you must remain on v4 short term, the safest workaround is to rebuild
the v4 image against a Debian base that contains the fixed OpenSSL package
and validate that artifact with your scanner. For planning, treat Xberg v5
as the supported security-update path.
—
Reply to this email directly, view it on GitHub
<#1184?email_source=notifications&email_token=AEIQG6B2PEKLTO7EFAYA4V35CPRKDA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCNZUHA3DONRRUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVRTG633UMVZF6Y3MNFRWW#discussioncomment-17486761>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AEIQG6FQBKP7DJMRSAVAKAL5CPRKDAVCNFSNUABIKJSXA33TNF2G64TZHM4TENJUGM2DGMJXHNCGS43DOVZXG2LPNY5TCMBTGQ3TIMJQUF3AE>
.
Triage notifications, keep track of coding agent tasks and review pull
requests on the go with GitHub Mobile for iOS
<https://github.com/notifications/mobile/ios/AEIQG6A7S4AWI24GIC2SZXT5CPRKDA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCNZUHA3DONRRUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVJTG633UMVZF62LPOM>
and Android
<https://github.com/notifications/mobile/android/AEIQG6FTN3RQD5LC4GLP6QT5CPRKDA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCNZUHA3DONRRUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVZTG633UMVZF6YLOMRZG62LE>.
Download it today!
You are receiving this because you authored the thread.Message ID:
***@***.***>
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
We’re using Kreuzberg v4.9.9 and identified a vulnerability from OpenSSL/Debian (CVE‑2026‑9076).
Should we stay on v4.9.9 or migrate to Xberg (v5)?
Will a patched v4 image be released?
If not, are fixes only expected in Xberg releases?
Any guidance on recommended path or timeline would help.
Thanks!
All reactions