Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 9 additions & 14 deletions .trivyignore
Original file line number Diff line number Diff line change
Expand Up @@ -31,14 +31,6 @@ CVE-2026-42577 exp:2026-09-11
# See: UID2-7376
CVE-2026-2100 exp:2026-09-01

# CVE-2026-56131 / CVE-2026-56407 / CVE-2026-56408 — libexpat stack exhaustion / integer overflows
# in the Alpine base image. uid2-admin is a pure Java service; the JVM parses XML via the built-in
# JAXP/Xerces implementation, not the native libexpat C library, and there are no JNI bindings or
# native deps that call into libexpat, so the crafted-XML attack path is not reachable. Fixed in
# Alpine v3.23 libexpat >= 2.8.2-r0; the pinned eclipse-temurin base image has not yet been rebuilt with it.
# See: UID2-7456
CVE-2026-56131 exp:2026-08-09
CVE-2026-56407 exp:2026-08-09
# CVE-2026-56408 — libexpat (Alpine base image, transitive via eclipse-temurin:21-jre-
# alpine-3.23) (HIGH).
# Not exploitable here: Dockerfile FROM eclipse-temurin:21-jre-alpine-3.23; libexpat not apk-
Expand All @@ -47,16 +39,19 @@ CVE-2026-56407 exp:2026-08-09
# See: UID2-7656
CVE-2026-56408 exp:2026-11-11

# jackson-core async parser maxNumberLength bypass (GHSA-r7wm-3cxj-wff9) - incomplete fix for
# GHSA-72hv-8253-57qq. Not exploitable: services only use the synchronous ObjectMapper API, not
# jackson-core's non-blocking/async parser. A jackson bump is also in flight via uid2-shared
# (PR #631) and will flow on the next release. See: UID2-7557 (predecessor UID2-6670)
GHSA-r7wm-3cxj-wff9 exp:2026-08-23

# CVE-2026-40984 — io.micrometer:micrometer-core (transitive via micrometer-registry-
# prometheus/-jmx); micrometer-jetty11/12 not present (HIGH).
# Not exploitable here: pom.xml:112/126/132 vertx-micrometer + micrometer-registry-
# jmx/-prometheus 1.12.2; Main.java:396 VertxPrometheusOptions.setStartEmbeddedServer for
# /metrics; HTTP instrumentation via Vert.x, not micrometer-jetty/servlet binders
# See: UID2-7662
CVE-2026-40984 exp:2026-11-11

# CVE-2026-11822 / CVE-2026-11824 — sqlite-libs arbitrary code execution/crash via crafted
# FTS5 input, in the Alpine base image (transitive via eclipse-temurin:21-jre-alpine-3.23).
# Not exploitable here: sqlite-libs is not apk-added in the Dockerfile (only libpng/libcrypto3/
# libssl3/musl/musl-utils/gnutls are); uid2-admin is a pure Java/Vert.x service with no SQLite/
# JDBC dependency and no JNI bindings, so the FTS5 query engine is never invoked.
# See: UID2-7748
CVE-2026-11822 exp:2026-11-26
CVE-2026-11824 exp:2026-11-26