Skip to content

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/squid:0.27.44 #51022

Description

@github-actions

Summary

Image: ghcr.io/github/gh-aw-firewall/squid:0.27.44

  • Vulnerabilities: 0 Critical / 14 High / 8 Medium / 0 Low / 0 Negligible
  • License policy violations: 37

Vulnerabilities

High

All High findings are in bind-libs@9.20.24-r0 / bind-tools@9.20.24-r0 (fix: 9.20.26-r0):

  • CVE-2026-11605, CVE-2026-11622, CVE-2026-13204, CVE-2026-12617, CVE-2026-11331, CVE-2026-11721, CVE-2026-13321
Medium (8)
  • CVE-2026-10822: bind-libs@9.20.24-r0, bind-tools@9.20.24-r0 (fix: 9.20.26-r0)
  • CVE-2026-10723: bind-libs@9.20.24-r0, bind-tools@9.20.24-r0 (fix: 9.20.26-r0)
  • CVE-2025-60876: busybox@1.37.0-r31, busybox-binsh@1.37.0-r31, ssl_client@1.37.0-r31 (no fix listed)
  • CVE-2026-58055: nghttp2-libs@1.69.0-r0 (no fix listed)

License Policy Violations

37 violations, all standard Alpine base-layer / squid dependency licenses: GPL-2.0/LGPL family (apk-tools, libapk, busybox*, alpine-baselayout*, musl-utils, libgcc, libstdc++, libcap2, zstd-libs, libcom_err, keyutils-libs, net-tools, mii-tool, scanelf, logrotate, squid@7.6-r0, libltdl, acl-libs, libidn2, libunistring, userspace-rcu), GPL-3.0 (bash, readline), X11 (libncursesw, ncurses-terminfo-base), MPL-2.0 (bind-libs, bind-tools, ca-certificates-bundle), curl license (curl, libcurl), Zlib (zlib), plus multi-license combos (libmd: AND/Beerware/Domain/Public; xz-libs: 0BSD/AND/GPL-2.0-or-later/LGPL-2.1-or-later/Public-Domain) and sqlite-libs@3.53.2-r0 under the non-standard "blessing" license identifier. No packages with missing license data.

Remediation

  1. Upgrade bind-libs/bind-tools to 9.20.26-r0 to resolve all 14 High and 2 of the 8 Medium findings.
  2. Monitor upstream for busybox/nghttp2-libs fixes (not yet published) for the remaining Medium CVEs.
  3. Rebuild image from a refreshed Alpine base once packages are updated.
  4. Review Grant policy allowlist for standard Alpine GPL/LGPL/X11/MPL packages that are expected components of a squid-based image; verify the sqlite-libs "blessing" license classification is intentional/acceptable.

Generated by 🛡️ Daily Container Image Security Scan · auto · 229 AIC · ⌖ 2.79 AIC · ⊞ 6.4K ·

Metadata

Metadata

Labels

cookieIssue Monster Loves Cookies!security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions