[security][CVE-2026-28389] OpenSSL in Bun runtime image #135

Open
opened 2026-07-16 13:21:08 +00:00 by dirtydishes · 0 comments
Owner

Automation detected a newly untracked active high-severity CVE in the shipped runtime surface.

  • CVE: CVE-2026-28389
  • Affected component: OpenSSL in Bun runtime image
  • Severity: HIGH
  • In-repo version(s): libssl3t64 3.5.5-1deb13u1; openssl-provider-legacy 3.5.5-1deb13u1 in oven/bun:1.3.11
  • Project impact: The Bun runtime image ships vulnerable OpenSSL client packages, so applications using policy-checked certificate validation inherit this OpenSSL bug until the base image is refreshed.
  • Remediation: Rebuild from an oven/bun base that includes Debian 13 OpenSSL 3.5.5-1~deb13u2 or newer.

Counters for this run:

  • unaddressed critical CVEs: 6
  • unaddressed medium/low CVEs: 119
  • unaddressed total CVEs: 163

Sources:

Automation detected a newly untracked active high-severity CVE in the shipped runtime surface. - CVE: CVE-2026-28389 - Affected component: OpenSSL in Bun runtime image - Severity: HIGH - In-repo version(s): libssl3t64 3.5.5-1~deb13u1; openssl-provider-legacy 3.5.5-1~deb13u1 in oven/bun:1.3.11 - Project impact: The Bun runtime image ships vulnerable OpenSSL client packages, so applications using policy-checked certificate validation inherit this OpenSSL bug until the base image is refreshed. - Remediation: Rebuild from an oven/bun base that includes Debian 13 OpenSSL 3.5.5-1~deb13u2 or newer. Counters for this run: - unaddressed critical CVEs: 6 - unaddressed medium/low CVEs: 119 - unaddressed total CVEs: 163 Sources: - https://nvd.nist.gov/vuln/detail/CVE-2026-28389 - https://avd.aquasec.com/nvd/cve-2026-28389
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#135
No description provided.