Skip to content

[container-image-scan] Container findings for semgrep/semgrep:latest #49520

Description

@github-actions

Summary

Image: semgrep/semgrep:latest
Pinned reference: semgrep/semgrep:latest@sha256:bdf7013b2c3634a487671158da77c554f531742326b543a9464d2adf6c433ac8

  • Vulnerabilities: 76 total — Critical: 8, High: 32, Medium: 30, Low: 4, Negligible: 1, Unknown: 1
  • License policy violations: 59

Remediation

  • Rebuild/update the image to pull in patched packages for the vulnerabilities listed below (fixed versions shown where available).
  • Review the licenses listed below against policy; consider replacing, removing, or granting an exception for flagged packages.
  • Re-run the scan after remediation to confirm the findings are resolved.

Critical & High severity vulnerabilities

[Critical] CVE-2026-10536: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[Critical] CVE-2026-11564: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[Critical] CVE-2026-11856: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[Critical] CVE-2026-8924: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[Critical] CVE-2026-8925: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[Critical] CVE-2026-8926: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[Critical] CVE-2026-8927: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[Critical] CVE-2026-9079: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-11352: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-11586: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-11822: sqlite-libs@3.51.2-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-11824: sqlite-libs@3.51.2-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-11940: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-11972: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-12064: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-15308: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-32631: git@2.52.0-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-3298: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-3644: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-4224: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-4786: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-6100: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-7210: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-8286: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-8932: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-9080: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-9545: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-9546: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-9547: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[High] CVE-2026-9669: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[High] GHSA-58pv-8j8x-9vj2: jaraco-context@5.3.0 (fix: 6.1.0) (https://github.com/advisories/GHSA-58pv-8j8x-9vj2)
[High] GHSA-8rrh-rw8j-w5fx: wheel@0.45.1 (fix: 0.46.2) (https://github.com/advisories/GHSA-8rrh-rw8j-w5fx)
[High] GHSA-hvrp-rf83-w775: mcp@1.23.3 (fix: 1.27.2) (https://github.com/advisories/GHSA-hvrp-rf83-w775)
[High] GHSA-jpw9-pfvf-9f58: mcp@1.23.3 (fix: 1.27.2) (https://github.com/advisories/GHSA-jpw9-pfvf-9f58)
[High] GHSA-vj7q-gjh5-988w: mcp@1.23.3 (fix: 1.28.1) (https://github.com/advisories/GHSA-vj7q-gjh5-988w)
[High] GO-2026-4970: stdlib@go1.25.10 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2) (https://go.dev/issue/79005)
[High] GO-2026-5037: stdlib@go1.25.10 (fix: 1.25.11, 1.26.4) (https://go.dev/cl/783621)
[High] GO-2026-5038: stdlib@go1.25.10 (fix: 1.25.11, 1.26.4) (https://go.dev/issue/79217)
[High] GO-2026-5942: golang.org/x/net@v0.55.0 (fix: 0.56.0) (https://go.dev/cl/786345)
[High] GO-2026-5970: golang.org/x/text@v0.38.0 (fix: 0.39.0) (https://go.dev/issue/80142)
Medium / Low / Negligible / Unknown vulnerabilities (36 findings, 36 unique)
[Low] CVE-2025-13462: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Low] CVE-2026-1703: py3-pip@25.1.1-r1 ((nvd.nist.gov/redacted)
[Low] CVE-2026-4519: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Low] GHSA-6vgw-5pg2-w6jp: pip@25.1.1 (fix: 26.0) (https://github.com/advisories/GHSA-6vgw-5pg2-w6jp)
[Medium] CVE-2025-12781: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-13837: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-15366: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-15367: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: busybox-binsh@1.37.0-r30 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: busybox@1.37.0-r30 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: ssl_client@1.37.0-r30 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-8869: py3-pip@25.1.1-r1 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-0864: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-12003: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-1502: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-2297: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-3219: py3-pip@25.1.1-r1 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-3276: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-3446: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-4360: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-58055: nghttp2-libs@1.69.0-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-6019: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-6357: py3-pip@25.1.1-r1 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-7774: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-8328: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-8458: curl@8.20.0-r0 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-8643: py3-pip@25.1.1-r1 ((nvd.nist.gov/redacted)
[Medium] GHSA-4xh5-x5gv-qwph: pip@25.1.1 (fix: 25.3) (https://github.com/advisories/GHSA-4xh5-x5gv-qwph)
[Medium] GHSA-58qw-9mgm-455v: pip@25.1.1 (fix: 26.1) (https://github.com/advisories/GHSA-58qw-9mgm-455v)
[Medium] GHSA-h35f-9h28-mq5c: setuptools@80.9.0 (fix: 83.0.0) (https://github.com/advisories/GHSA-h35f-9h28-mq5c)
[Medium] GHSA-jp4c-xjxw-mgf9: pip@25.1.1 (fix: 26.1) (https://github.com/advisories/GHSA-jp4c-xjxw-mgf9)
[Medium] GHSA-wf93-45jw-7689: pip@25.1.1 (fix: 26.1.2) (https://github.com/advisories/GHSA-wf93-45jw-7689)
[Medium] GO-2026-5039: stdlib@go1.25.10 (fix: 1.25.11, 1.26.4) (https://go.dev/issue/79346)
[Medium] GO-2026-5856: stdlib@go1.25.10 (fix: 1.25.12, 1.26.5, 1.27.0-rc.2) (https://go.dev/cl/775960)
[Negligible] CVE-2026-3479: python3@3.12.13-r0 ((nvd.nist.gov/redacted)
[Unknown] GO-2026-5932: golang.org/x/crypto@v0.53.0 (https://go.dev/issue/44226)
License policy violations (59 findings, 59 unique)
alpine-baselayout-data@3.7.2-r0 (GPL-2.0-only)
alpine-baselayout@3.7.2-r0 (GPL-2.0-only)
annotated-types@0.7.0 (no licenses found)
apk-tools@3.0.6-r0 (GPL-2.0-only)
autocommand@2.2.2 (LGPLv3)
bash@5.3.3-r1 (GPL-3.0-or-later)
boltons@21.0.0 (BSD)
busybox-binsh@1.37.0-r30 (GPL-2.0-only)
busybox@1.37.0-r30 (GPL-2.0-only)
ca-certificates-bundle@20260611-r0 (MPL-2.0)
certifi@2026.7.22 (MPL-2.0)
cffi@2.1.0 (MIT-0)
colorama@0.4.6 (no licenses found)
curl@8.20.0-r0 (curl)
face@26.0.1 (no licenses found)
gdbm@1.26-r0 (GPL-3.0-or-later)
git-init-template@2.52.0-r0 (GPL-2.0-only)
git@2.52.0-r0 (GPL-2.0-only)
glom@25.12.0 (UNKNOWN)
googleapis-common-protos@1.75.0 (Apache 2.0)
libapk@3.0.6-r0 (GPL-2.0-only)
libbz2@1.0.8-r6 (bzip2-1.0.6)
libcurl@8.20.0-r0 (curl)
libgcc@15.2.0-r2 (GPL-2.0-or-later, LGPL-2.1-or-later)
libidn2@2.3.8-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
libncursesw@6.5_p20251123-r0 (X11)
libpanelw@6.5_p20251123-r0 (X11)
libstdc++`@15`.2.0-r2 (GPL-2.0-or-later, LGPL-2.1-or-later)
libunistring@1.4.1-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
markdown-it-py@4.2.0 (no licenses found)
musl-utils@1.2.5-r23 (GPL-2.0-or-later)
my-test-package@1.0 (UNKNOWN)
ncurses-terminfo-base@6.5_p20251123-r0 (X11)
openssh-client-common@10.2_p1-r0 (SSH-OpenSSH)
openssh-client-default@10.2_p1-r0 (SSH-OpenSSH)
openssh-keygen@10.2_p1-r0 (SSH-OpenSSH)
openssh-server-common@10.2_p1-r0 (SSH-OpenSSH)
openssh-server@10.2_p1-r0 (SSH-OpenSSH)
openssh-sftp-server@10.2_p1-r0 (SSH-OpenSSH)
openssh@10.2_p1-r0 (SSH-OpenSSH)
packaging@25.0 (no licenses found)
peewee@3.19.0 (no licenses found)
protobuf@6.33.6 (3-Clause BSD License)
pyc@3.12.13-r0 (PSF-2.0)
python3-pyc@3.12.13-r0 (PSF-2.0)
python3-pycache-pyc0@3.12.13-r0 (PSF-2.0)
python3@3.12.13-r0 (PSF-2.0)
readline@8.3.1-r0 (GPL-3.0-or-later)
scanelf@1.3.8-r2 (GPL-2.0-only)
semantic-version@2.10.0 (BSD)
semgrep@1.171.0 (LGPL-2.1-or-later)
sqlite-libs@3.51.2-r0 (blessing)
ssl_client@1.37.0-r30 (GPL-2.0-only)
typing-extensions@4.12.2 (0BSD, HPND)
typing-extensions@4.16.0 (PSF-2.0)
wrapt@1.17.3 (BSD)
xz-libs@5.8.3-r0 (0BSD, AND, GPL-2.0-or-later, LGPL-2.1-or-later, Public-Domain)
zlib@1.3.2-r0 (Zlib)
zstd-libs@1.5.7-r2 (GPL-2.0-or-later)

Generated by 🛡️ Daily Container Image Security Scan · auto · 285.1 AIC · ⌖ 8.51 AIC · ⊞ 6.3K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions