Updated 2026-09-01 01:26 UTC from the nightly scan of the published images.
Actionable — fix available (24)
Cleared by merging the automated base-image / npm update PR, or by bumping the affected package.
Awareness (9)
Tracked for visibility only, never pages the review team. See Reason for why
each one isn't gated: no upstream fix yet, or, for npm-bundled dependencies,
the fix exists in the library but npm hasn't shipped a release bundling it.
| Severity |
ID |
Package |
Installed |
Fix |
Reason |
| HIGH |
CVE-2026-14257 |
brace-expansion |
5.0.7 |
5.0.8, 3.0.3, 2.1.3, 1.1.17 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| HIGH |
CVE-2026-69152 |
brace-expansion |
5.0.7 |
1.1.18, 2.1.4, 3.0.6, 5.0.9 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| HIGH |
CVE-2026-69192 |
ip-address |
10.2.0 |
10.3.1 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| HIGH |
CVE-2026-73566 |
tar |
7.5.19 |
7.5.21 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| MEDIUM |
CVE-2026-15157 |
undici |
6.27.0 |
6.28.0, 7.29.0, 8.9.0 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| MEDIUM |
CVE-2026-16728 |
undici |
6.27.0 |
6.28.0, 7.29.0, 8.9.0 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| MEDIUM |
CVE-2026-16729 |
undici |
6.27.0 |
6.28.0, 7.29.0, 8.9.0 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| MEDIUM |
CVE-2026-54272 |
ip-address |
10.2.0 |
10.2.1 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| MEDIUM |
CVE-2026-69198 |
ip-address |
10.2.0 |
10.2.2 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
Updated 2026-09-01 01:26 UTC from the nightly scan of the published images.
Actionable — fix available (24)
Cleared by merging the automated base-image / npm update PR, or by bumping the affected package.
Awareness (9)
Tracked for visibility only, never pages the review team. See Reason for why
each one isn't gated: no upstream fix yet, or, for npm-bundled dependencies,
the fix exists in the library but npm hasn't shipped a release bundling it.