Phase 1: Critical Docker Image Security Fixes #363

Closed
opened 2026-02-12 18:33:37 +00:00 by jason.woltje · 0 comments
Owner

Findings

  • OpenBao image (quay.io/openbao/openbao:2): 1 CRITICAL + 4 HIGH CVEs

    • CVE-2025-68121 (CRITICAL): Go stdlib crypto/tls session resumption
    • CVE-2024-8185 (HIGH): DoS via Raft join requests
    • CVE-2024-9180 (HIGH): Root namespace privilege escalation
    • CVE-2025-59043 (HIGH): DoS via malicious JSON
    • CVE-2025-64761 (HIGH): Identity group root escalation
  • Postgres image (postgres:17-alpine): 1 CRITICAL + 5 HIGH CVEs in gosu binary

    • CVE-2025-68121 (CRITICAL): Go stdlib crypto/tls session resumption
    • CVE-2025-58183, CVE-2025-61726, CVE-2025-61728, CVE-2025-61729, CVE-2025-61730 (all HIGH)

Acceptance Criteria

  • OpenBao image updated to patched version
  • Postgres image/gosu updated to patched version
  • Trivy scans pass with no CRITICAL/HIGH findings
  • No regressions in existing functionality
## Findings - **OpenBao image** (quay.io/openbao/openbao:2): 1 CRITICAL + 4 HIGH CVEs - CVE-2025-68121 (CRITICAL): Go stdlib crypto/tls session resumption - CVE-2024-8185 (HIGH): DoS via Raft join requests - CVE-2024-9180 (HIGH): Root namespace privilege escalation - CVE-2025-59043 (HIGH): DoS via malicious JSON - CVE-2025-64761 (HIGH): Identity group root escalation - **Postgres image** (postgres:17-alpine): 1 CRITICAL + 5 HIGH CVEs in gosu binary - CVE-2025-68121 (CRITICAL): Go stdlib crypto/tls session resumption - CVE-2025-58183, CVE-2025-61726, CVE-2025-61728, CVE-2025-61729, CVE-2025-61730 (all HIGH) ## Acceptance Criteria - [ ] OpenBao image updated to patched version - [ ] Postgres image/gosu updated to patched version - [ ] Trivy scans pass with no CRITICAL/HIGH findings - [ ] No regressions in existing functionality
jason.woltje added this to the M11-CIPipeline (0.0.11) milestone 2026-02-12 18:33:37 +00:00
jason.woltje added the security label 2026-02-12 18:33:37 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: mosaic/stack#363