Summary
Image: ghcr.io/github/gh-aw-firewall/squid:0.27.44
- Vulnerabilities: 0 Critical / 14 High / 8 Medium / 0 Low / 0 Negligible
- License policy violations: 37
Vulnerabilities
High
All High findings are in bind-libs@9.20.24-r0 / bind-tools@9.20.24-r0 (fix: 9.20.26-r0):
CVE-2026-11605, CVE-2026-11622, CVE-2026-13204, CVE-2026-12617, CVE-2026-11331, CVE-2026-11721, CVE-2026-13321
Medium (8)
CVE-2026-10822: bind-libs@9.20.24-r0, bind-tools@9.20.24-r0 (fix: 9.20.26-r0)
CVE-2026-10723: bind-libs@9.20.24-r0, bind-tools@9.20.24-r0 (fix: 9.20.26-r0)
CVE-2025-60876: busybox@1.37.0-r31, busybox-binsh@1.37.0-r31, ssl_client@1.37.0-r31 (no fix listed)
CVE-2026-58055: nghttp2-libs@1.69.0-r0 (no fix listed)
License Policy Violations
37 violations, all standard Alpine base-layer / squid dependency licenses: GPL-2.0/LGPL family (apk-tools, libapk, busybox*, alpine-baselayout*, musl-utils, libgcc, libstdc++, libcap2, zstd-libs, libcom_err, keyutils-libs, net-tools, mii-tool, scanelf, logrotate, squid@7.6-r0, libltdl, acl-libs, libidn2, libunistring, userspace-rcu), GPL-3.0 (bash, readline), X11 (libncursesw, ncurses-terminfo-base), MPL-2.0 (bind-libs, bind-tools, ca-certificates-bundle), curl license (curl, libcurl), Zlib (zlib), plus multi-license combos (libmd: AND/Beerware/Domain/Public; xz-libs: 0BSD/AND/GPL-2.0-or-later/LGPL-2.1-or-later/Public-Domain) and sqlite-libs@3.53.2-r0 under the non-standard "blessing" license identifier. No packages with missing license data.
Remediation
- Upgrade
bind-libs/bind-tools to 9.20.26-r0 to resolve all 14 High and 2 of the 8 Medium findings.
- Monitor upstream for
busybox/nghttp2-libs fixes (not yet published) for the remaining Medium CVEs.
- Rebuild image from a refreshed Alpine base once packages are updated.
- Review Grant policy allowlist for standard Alpine GPL/LGPL/X11/MPL packages that are expected components of a squid-based image; verify the
sqlite-libs "blessing" license classification is intentional/acceptable.
Generated by 🛡️ Daily Container Image Security Scan · auto · 229 AIC · ⌖ 2.79 AIC · ⊞ 6.4K · ◷
Summary
Image:
ghcr.io/github/gh-aw-firewall/squid:0.27.44Vulnerabilities
High
All High findings are in
bind-libs@9.20.24-r0/bind-tools@9.20.24-r0(fix: 9.20.26-r0):CVE-2026-11605,CVE-2026-11622,CVE-2026-13204,CVE-2026-12617,CVE-2026-11331,CVE-2026-11721,CVE-2026-13321Medium (8)
CVE-2026-10822:bind-libs@9.20.24-r0,bind-tools@9.20.24-r0(fix: 9.20.26-r0)CVE-2026-10723:bind-libs@9.20.24-r0,bind-tools@9.20.24-r0(fix: 9.20.26-r0)CVE-2025-60876:busybox@1.37.0-r31,busybox-binsh@1.37.0-r31,ssl_client@1.37.0-r31(no fix listed)CVE-2026-58055:nghttp2-libs@1.69.0-r0(no fix listed)License Policy Violations
37 violations, all standard Alpine base-layer / squid dependency licenses: GPL-2.0/LGPL family (
apk-tools,libapk,busybox*,alpine-baselayout*,musl-utils,libgcc,libstdc++,libcap2,zstd-libs,libcom_err,keyutils-libs,net-tools,mii-tool,scanelf,logrotate,squid@7.6-r0,libltdl,acl-libs,libidn2,libunistring,userspace-rcu), GPL-3.0 (bash,readline), X11 (libncursesw,ncurses-terminfo-base), MPL-2.0 (bind-libs,bind-tools,ca-certificates-bundle), curl license (curl,libcurl), Zlib (zlib), plus multi-license combos (libmd: AND/Beerware/Domain/Public;xz-libs: 0BSD/AND/GPL-2.0-or-later/LGPL-2.1-or-later/Public-Domain) andsqlite-libs@3.53.2-r0under the non-standard "blessing" license identifier. No packages with missing license data.Remediation
bind-libs/bind-toolsto 9.20.26-r0 to resolve all 14 High and 2 of the 8 Medium findings.busybox/nghttp2-libsfixes (not yet published) for the remaining Medium CVEs.sqlite-libs"blessing" license classification is intentional/acceptable.