Skip to main content
Testkube 2.8.0 is out! Autonomous AI Agents, Custom AI Models, fail-fast and input/output parameters for Workflows, and much more. Read More

testkube-tw-toolkit-2.8.3_linux_arm64

digestsha256:f3e118c7969f1c49809bc1031392ca61748c2633e3816ca8812d14b10da5ca09
vulnerabilitiescritical: 0 high: 8 medium: 19 low: 6 unspecified: 9
platformlinux/arm64
size48 MB
packages218
critical: 0 high: 4 medium: 6 low: 0 libssl3 3.3.5-r0 (apk)

pkg:apk/alpine/libssl3@3.3.5-r0?arch=aarch64&distro=alpine-3.20.8&upstream=openssl

# tw-toolkit.Dockerfile (24:24)
FROM ${ALPINE_IMAGE}

high : CVE--2025--15467

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.705%
EPSS Percentile72nd percentile
Description

high : CVE--2025--69421

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.036%
EPSS Percentile10th percentile
Description

high : CVE--2025--69420

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.303%
EPSS Percentile54th percentile
Description

high : CVE--2025--69419

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.063%
EPSS Percentile20th percentile
Description

medium : CVE--2025--66199

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.067%
EPSS Percentile21st percentile
Description

medium : CVE--2025--15468

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.022%
EPSS Percentile6th percentile
Description

medium : CVE--2026--22795

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.021%
EPSS Percentile6th percentile
Description

medium : CVE--2026--22796

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.117%
EPSS Percentile30th percentile
Description

medium : CVE--2025--68160

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.027%
EPSS Percentile8th percentile
Description

medium : CVE--2025--69418

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.008%
EPSS Percentile1st percentile
Description
critical: 0 high: 1 medium: 9 low: 1 libcurl 8.14.1-r2 (apk)

pkg:apk/alpine/libcurl@8.14.1-r2?arch=aarch64&distro=alpine-3.20.8&upstream=curl

# tw-toolkit.Dockerfile (25:25)
RUN apk --no-cache add ca-certificates libssl3 git openssh-client

high : CVE--2026--3805

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.039%
EPSS Percentile12th percentile
Description

medium : CVE--2026--3784

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.015%
EPSS Percentile3rd percentile
Description

medium : CVE--2026--1965

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.054%
EPSS Percentile17th percentile
Description

medium : CVE--2025--14017

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.007%
EPSS Percentile1st percentile
Description

medium : CVE--2025--13034

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.011%
EPSS Percentile1st percentile
Description

medium : CVE--2026--3783

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.016%
EPSS Percentile4th percentile
Description

medium : CVE--2025--15079

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.035%
EPSS Percentile10th percentile
Description

medium : CVE--2025--14819

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.045%
EPSS Percentile14th percentile
Description

medium : CVE--2025--14524

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.026%
EPSS Percentile7th percentile
Description

medium : CVE--2025--10966

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.020%
EPSS Percentile5th percentile
Description

low : CVE--2025--15224

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.084%
EPSS Percentile24th percentile
Description
critical: 0 high: 1 medium: 1 low: 0 c-ares 1.33.1-r0 (apk)

pkg:apk/alpine/c-ares@1.33.1-r0?arch=aarch64&distro=alpine-3.20.8

# tw-toolkit.Dockerfile (25:25)
RUN apk --no-cache add ca-certificates libssl3 git openssh-client

high : CVE--2025--31498

Affected range<=1.33.1-r0
Fixed versionNot Fixed
EPSS Score0.618%
EPSS Percentile70th percentile
Description

medium : CVE--2025--62408

Affected range<=1.33.1-r0
Fixed versionNot Fixed
EPSS Score0.019%
EPSS Percentile5th percentile
Description
critical: 0 high: 1 medium: 0 low: 0 nghttp2-libs 1.62.1-r0 (apk)

pkg:apk/alpine/nghttp2-libs@1.62.1-r0?arch=aarch64&distro=alpine-3.20.8&upstream=nghttp2

# tw-toolkit.Dockerfile (25:25)
RUN apk --no-cache add ca-certificates libssl3 git openssh-client

high : CVE--2026--27135

Affected range<=1.62.1-r0
Fixed versionNot Fixed
EPSS Score0.017%
EPSS Percentile4th percentile
Description
critical: 0 high: 1 medium: 0 low: 0 github.com/docker/cli 29.3.0+incompatible (golang)

pkg:golang/github.com/docker/cli@29.3.0%2Bincompatible

# tw-toolkit.Dockerfile (28:28)
COPY --from=build /app/testworkflow-init /init

high : CVE--2025--15558

Affected range>=19.03.0+incompatible
Fixed versionNot Fixed
EPSS Score0.023%
EPSS Percentile6th percentile
Description

Docker CLI Plugins: Uncontrolled Search Path Element Leads to Local Privilege Escalation on Windows in github.com/docker/cli

critical: 0 high: 0 medium: 2 low: 2 openssh-keygen 9.7_p1-r5 (apk)

pkg:apk/alpine/openssh-keygen@9.7_p1-r5?arch=aarch64&distro=alpine-3.20.8&upstream=openssh

# tw-toolkit.Dockerfile (25:25)
RUN apk --no-cache add ca-certificates libssl3 git openssh-client

medium : CVE--2025--32728

Affected range<=9.7_p1-r5
Fixed versionNot Fixed
EPSS Score0.274%
EPSS Percentile51st percentile
Description

medium : CVE--2026--35414

Affected range<=9.7_p1-r5
Fixed versionNot Fixed
EPSS Score0.016%
EPSS Percentile4th percentile
Description

low : CVE--2025--61985

Affected range<=9.7_p1-r5
Fixed versionNot Fixed
EPSS Score0.016%
EPSS Percentile4th percentile
Description

low : CVE--2025--61984

Affected range<=9.7_p1-r5
Fixed versionNot Fixed
EPSS Score0.011%
EPSS Percentile1st percentile
Description
critical: 0 high: 0 medium: 1 low: 2 ssl_client 1.36.1-r30 (apk)

pkg:apk/alpine/ssl_client@1.36.1-r30?arch=aarch64&distro=alpine-3.20.8&upstream=busybox

# tw-toolkit.Dockerfile (24:24)
FROM ${ALPINE_IMAGE}

medium : CVE--2025--60876

Affected range<=1.36.1-r30
Fixed versionNot Fixed
EPSS Score0.064%
EPSS Percentile20th percentile
Description

low : CVE--2025--46394

Affected range<1.36.1-r31
Fixed version1.36.1-r31
EPSS Score0.083%
EPSS Percentile24th percentile
Description

low : CVE--2024--58251

Affected range<1.36.1-r31
Fixed version1.36.1-r31
EPSS Score0.077%
EPSS Percentile23rd percentile
Description
critical: 0 high: 0 medium: 0 low: 1 zlib 1.3.1-r1 (apk)

pkg:apk/alpine/zlib@1.3.1-r1?arch=aarch64&distro=alpine-3.20.8

# tw-toolkit.Dockerfile (24:24)
FROM ${ALPINE_IMAGE}

low : CVE--2026--27171

Affected range<=1.3.1-r1
Fixed versionNot Fixed
EPSS Score0.007%
EPSS Percentile1st percentile
Description
critical: 0 high: 0 medium: 0 low: 0 unspecified: 7stdlib 1.26.1 (golang)

pkg:golang/stdlib@1.26.1

# tw-toolkit.Dockerfile (28:28)
COPY --from=build /app/testworkflow-init /init

unspecified : CVE--2026--33810

Affected range
>=1.26.0-0
<1.26.2
Fixed version1.26.2
Description

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint.

This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

unspecified : CVE--2026--32289

Affected range
>=1.26.0-0
<1.26.2
Fixed version1.26.2
Description

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied.

These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

unspecified : CVE--2026--32288

Affected range
>=1.26.0-0
<1.26.2
Fixed version1.26.2
Description

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

unspecified : CVE--2026--32283

Affected range
>=1.26.0-0
<1.26.2
Fixed version1.26.2
Description

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service.

This only affects TLS 1.3.

unspecified : CVE--2026--32282

Affected range
>=1.26.0-0
<1.26.2
Fixed version1.26.2
Description

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root.

The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

unspecified : CVE--2026--32281

Affected range
>=1.26.0-0
<1.26.2
Fixed version1.26.2
Description

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service.

This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

unspecified : CVE--2026--32280

Affected range
>=1.26.0-0
<1.26.2
Fixed version1.26.2
Description

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.

critical: 0 high: 0 medium: 0 low: 0 unspecified: 2github.com/jackc/pgx/v5 5.9.1 (golang)

pkg:golang/github.com/jackc/pgx/v5@5.9.1

# tw-toolkit.Dockerfile (28:28)
COPY --from=build /app/testworkflow-init /init

unspecified : CVE--2026--33816

Affected range>=0
Fixed versionNot Fixed
Description

Memory-safety vulnerability in github.com/jackc/pgx/v5.

unspecified : CVE--2026--33815

Affected range>=0
Fixed versionNot Fixed
Description

Memory-safety vulnerability in github.com/jackc/pgx/v5.