Updated 2026-10-11 01:32 UTC from the nightly scan of the published images.
Actionable — fix available (3)
Cleared by merging the automated base-image / npm update PR, or by bumping the affected package.
Awareness (11)
Tracked for visibility only, never pages the review team. See Reason for why
each one isn't gated: no upstream fix yet, or, for npm-bundled dependencies,
the fix exists in the library but npm hasn't shipped a release bundling it.
| Severity |
ID |
Package |
Installed |
Fix |
Reason |
| HIGH |
CVE-2026-102276 |
brace-expansion |
5.0.9 |
5.0.10, 3.0.7, 2.1.5, 1.1.19 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| HIGH |
CVE-2026-102278 |
brace-expansion |
5.0.9 |
5.0.11, 3.0.8, 2.1.6, 1.1.20 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| HIGH |
CVE-2026-19534 |
undici |
6.28.0 |
6.28.1, 7.29.1, 8.10.2 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| HIGH |
CVE-2026-93748 |
http-cache-semantics |
4.2.0 |
|
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| MEDIUM |
CVE-2026-101910 |
ip-address |
10.5.0 |
10.5.1 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| MEDIUM |
CVE-2026-101911 |
ip-address |
10.5.0 |
10.7.1 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| MEDIUM |
CVE-2026-101912 |
ip-address |
10.5.0 |
10.7.1 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| MEDIUM |
CVE-2026-101913 |
ip-address |
10.5.0 |
10.5.1 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| MEDIUM |
CVE-2026-102277 |
brace-expansion |
5.0.9 |
5.0.12, 3.0.9, 2.1.7, 1.1.21 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| MEDIUM |
CVE-2026-104844 |
postcss-selector-parser |
7.1.4 |
7.1.6 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
| MEDIUM |
CVE-2026-85024 |
undici |
6.28.0 |
6.28.1, 7.29.1, 8.10.2 |
npm bundles this dependency itself; needs a new npm release, not just a newer library |
Updated 2026-10-11 01:32 UTC from the nightly scan of the published images.
Actionable — fix available (3)
Cleared by merging the automated base-image / npm update PR, or by bumping the affected package.
Awareness (11)
Tracked for visibility only, never pages the review team. See Reason for why
each one isn't gated: no upstream fix yet, or, for npm-bundled dependencies,
the fix exists in the library but npm hasn't shipped a release bundling it.