Skip to main content
Testkube 2.13.0 is out! New Advanced GitHub Integration, test case level flakiness, and much more! Read More

testkube-api-server-2.13.2_linux_arm64

digestsha256:fe10d1891227cf0115268736049780240b8a002ade0f4b8f00d99cbf968718d8
vulnerabilitiescritical: 4 high: 20 medium: 3 low: 0 unspecified: 4
platformlinux/arm64
size73 MB
packages258
critical: 2 high: 7 medium: 1 low: 0 libssl3 3.5.7-r0 (apk)

pkg:apk/alpine/libssl3@3.5.7-r0?arch=aarch64&distro=alpine-3.24.1&upstream=openssl

# api-server.Dockerfile (33:33)
FROM ${ALPINE_IMAGE}

critical : CVE--2026--63073

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score0.929%
EPSS Percentile59th percentile
Description

critical : CVE--2026--75803

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score0.221%
EPSS Percentile13th percentile
Description

high : CVE--2026--63076

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score1.350%
EPSS Percentile70th percentile
Description

high : CVE--2026--63075

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score0.480%
EPSS Percentile40th percentile
Description

high : CVE--2026--63072

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score0.676%
EPSS Percentile50th percentile
Description

high : CVE--2026--54874

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score0.524%
EPSS Percentile43rd percentile
Description

high : CVE--2026--18798

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score1.481%
EPSS Percentile72nd percentile
Description

high : CVE--2026--14457

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score0.984%
EPSS Percentile60th percentile
Description

high : CVE--2026--14456

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score0.729%
EPSS Percentile52nd percentile
Description

medium : CVE--2026--63074

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score0.495%
EPSS Percentile41st percentile
Description
critical: 2 high: 7 medium: 0 low: 0 unspecified: 1libcurl 8.21.0-r0 (apk)

pkg:apk/alpine/libcurl@8.21.0-r0?arch=aarch64&distro=alpine-3.24.1&upstream=curl

# api-server.Dockerfile (34:34)
RUN apk --no-cache upgrade && apk --no-cache add ca-certificates libssl3 git

critical : CVE--2026--19931

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score1.162%
EPSS Percentile65th percentile
Description

critical : CVE--2026--18924

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.897%
EPSS Percentile58th percentile
Description

high : CVE--2026--82209

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.540%
EPSS Percentile44th percentile
Description

high : CVE--2026--82208

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.425%
EPSS Percentile36th percentile
Description

high : CVE--2026--80255

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.684%
EPSS Percentile51st percentile
Description

high : CVE--2026--80231

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.937%
EPSS Percentile59th percentile
Description

high : CVE--2026--80230

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.566%
EPSS Percentile45th percentile
Description

high : CVE--2026--80229

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.899%
EPSS Percentile58th percentile
Description

high : CVE--2026--13608

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.644%
EPSS Percentile49th percentile
Description

unspecified : CVE--2026--80256

Affected range<8.22.0-r0
Fixed version8.22.0-r0
Description
critical: 0 high: 2 medium: 2 low: 0 libexpat 2.8.2-r0 (apk)

pkg:apk/alpine/libexpat@2.8.2-r0?arch=aarch64&distro=alpine-3.24.1&upstream=expat

# api-server.Dockerfile (34:34)
RUN apk --no-cache upgrade && apk --no-cache add ca-certificates libssl3 git

high : CVE--2026--76641

Affected range<2.8.4-r0
Fixed version2.8.4-r0
EPSS Score0.353%
EPSS Percentile29th percentile
Description

high : CVE--2026--66046

Affected range<2.8.4-r0
Fixed version2.8.4-r0
EPSS Score0.586%
EPSS Percentile46th percentile
Description

medium : CVE--2026--76956

Affected range<2.8.4-r0
Fixed version2.8.4-r0
EPSS Score0.287%
EPSS Percentile21st percentile
Description

medium : CVE--2026--76957

Affected range<2.8.4-r0
Fixed version2.8.4-r0
EPSS Score0.107%
EPSS Percentile1st percentile
Description
critical: 0 high: 2 medium: 0 low: 0 unspecified: 1golang.org/x/crypto 0.55.0 (golang)

pkg:golang/golang.org/x/crypto@0.55.0

# api-server.Dockerfile (36:36)
COPY --from=build /app /bin/app

high : CVE--2026--78662

Affected range<0.56.0
Fixed version0.56.0
EPSS Score0.315%
EPSS Percentile24th percentile
Description

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection.

Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.

high : CVE--2026--56855

Affected range<0.56.0
Fixed version0.56.0
EPSS Score0.378%
EPSS Percentile31st percentile
Description

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection.

Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.

unspecified : GO--2026--5932

Affected range>=0
Fixed versionNot Fixed
Description

The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.

If you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package.

critical: 0 high: 1 medium: 0 low: 0 google.golang.org/grpc 1.83.1 (golang)

pkg:golang/google.golang.org/grpc@1.83.1

# api-server.Dockerfile (36:36)
COPY --from=build /app /bin/app

high : CVE--2026--84445 Improper Validation of Array Index

Affected range
>=1.83.0
<1.83.2
Fixed version1.83.2
Description

A vulnerability exists in gRPC-Go servers configured with xds.NewGRPCServer() where a crafted request missing both :authority and Host headers can cause a server panic, resulting in a Denial of Service (DoS).

Servers built with xds.NewGRPCServer install an xDS routing interceptor on every RPC. This interceptor looks up the request’s :authority header to pick a virtual host. The HTTP/2 server transport previously accepted requests that had neither :authority nor Host. When this happened, the xDS routing interceptor attempted to access the first element of an empty slice of authorities, leading to an index out of bounds panic. Since the per-RPC goroutine does not recover from panics, the entire server process would terminate.

This panic occurs in the interceptor pipeline, meaning the transport credentials handshake (TLS, mTLS, or ALTS) and HTTP/2 connection establishment must complete successfully before the crafted request can reach this logic.

  • Insecure/Standard TLS: If the server permits insecure (plaintext) connections or standard credentials (where client certs are not checked), any unauthenticated remote attacker can trigger the crash.
  • mTLS / ALTS: If strict transport-level authentication is enforced at the network edge or transport layer (e.g., requiring a valid client certificate), the attacker must possess valid transport credentials to initiate the stream and trigger the panic.

Impact

An attacker can cause a complete outage of the gRPC server by sending a request missing both :authority and Host headers, provided they can successfully establish a transport connection.

Patches

The issue has been addressed in master (and backported to 1.83.2 and 1.82.2). The fix updates the HTTP/2 transport layer to reject requests missing both :authority and Host headers early, maintaining consistency with and other gRPC language implementations.

critical: 0 high: 1 medium: 0 low: 0 github.com/docker/cli 29.6.2+incompatible (golang)

pkg:golang/github.com/docker/cli@29.6.2%2Bincompatible

# api-server.Dockerfile (36:36)
COPY --from=build /app /bin/app

high : CVE--2025--15558

Affected range>=19.03.0+incompatible
Fixed versionNot Fixed
EPSS Score0.472%
EPSS Percentile39th percentile
Description

Docker CLI Plugins: Uncontrolled Search Path Element Leads to Local Privilege Escalation on Windows in github.com/docker/cli

critical: 0 high: 0 medium: 0 low: 0 unspecified: 1github.com/chrismellard/docker-credential-acr-env 0.0.0-20230304212654-82a0ddb27589 (golang)

pkg:golang/github.com/chrismellard/docker-credential-acr-env@0.0.0-20230304212654-82a0ddb27589

# api-server.Dockerfile (36:36)
COPY --from=build /app /bin/app

unspecified : GO--2026--6225

Affected range>=0
Fixed versionNot Fixed
Description

In github.com/chrismellard/docker-credential-acr-env/pkg/credhelper, the regular expression used by isACRRegistry to validate Azure Container Registry hostnames is unanchored. As a result, arbitrary hostnames containing the substring ".azurecr.io" (such as evil.azurecr.io.attacker.com) are treated as valid ACR registries, causing ACRCredHelper.Get to send the Azure Active Directory (AAD) access token to attacker-controlled hosts.

critical: 0 high: 0 medium: 0 low: 0 unspecified: 1nghttp2-libs 1.69.0-r0 (apk)

pkg:apk/alpine/nghttp2-libs@1.69.0-r0?arch=aarch64&distro=alpine-3.24.1&upstream=nghttp2

# api-server.Dockerfile (34:34)
RUN apk --no-cache upgrade && apk --no-cache add ca-certificates libssl3 git

unspecified : CVE--2026--58055

Affected range<1.70.0-r0
Fixed version1.70.0-r0
EPSS Score0.253%
EPSS Percentile17th percentile
Description