[security][CVE-2026-57433] perl-base in runtime base images #153

Open
opened 2026-07-21 22:18:57 +00:00 by dirtydishes · 0 comments
Owner

New active runtime-image CVE detected by the cve-security-triage automation on 2026-07-21.

  • CVE: CVE-2026-57433
  • Affected component: perl-base / Storable in runtime base images
  • In-repo runtime surface:
    • deployment/docker/Dockerfile.service -> oven/bun:1.3.11 (Trivy reports perl-base 5.40.1-6)
    • deployment/docker/Dockerfile.web -> oven/bun:1.3.11 (same base image family)
    • deployment/docker/Dockerfile.ingest-options -> oven/bun:1.3.11 (same base image family)
    • deployment/docker/docker-compose.yml -> redis:7.2 (Trivy reports perl-base 5.36.0-7+deb12u3)
  • Severity: Critical in current Trivy/vendor classification
  • Score: no NVD CVSS score populated yet at triage time
  • Concise impact: these shipped runtime images include vulnerable Perl/Storable packages; a crafted serialized payload that reaches Perl Storable deserialization can panic/terminate the process in the affected package.
  • Remediation guidance:
    • Refresh to base images that include patched Perl/Storable packages once upstream images publish fixes.
    • Prefer image digests or newer tags over floating redis:7.2 once a fixed build is available.
    • Re-scan oven/bun:1.3.11 successors and the pinned Redis image candidate before rollout.

Counters for this run:

  • unaddressed critical CVEs: 7
  • unaddressed medium/low CVEs: 126
  • unaddressed total CVEs: 171

Sources:

New active runtime-image CVE detected by the `cve-security-triage` automation on 2026-07-21. - CVE: `CVE-2026-57433` - Affected component: `perl-base` / Storable in runtime base images - In-repo runtime surface: - `deployment/docker/Dockerfile.service` -> `oven/bun:1.3.11` (Trivy reports `perl-base` `5.40.1-6`) - `deployment/docker/Dockerfile.web` -> `oven/bun:1.3.11` (same base image family) - `deployment/docker/Dockerfile.ingest-options` -> `oven/bun:1.3.11` (same base image family) - `deployment/docker/docker-compose.yml` -> `redis:7.2` (Trivy reports `perl-base` `5.36.0-7+deb12u3`) - Severity: Critical in current Trivy/vendor classification - Score: no NVD CVSS score populated yet at triage time - Concise impact: these shipped runtime images include vulnerable Perl/Storable packages; a crafted serialized payload that reaches Perl Storable deserialization can panic/terminate the process in the affected package. - Remediation guidance: - Refresh to base images that include patched Perl/Storable packages once upstream images publish fixes. - Prefer image digests or newer tags over floating `redis:7.2` once a fixed build is available. - Re-scan `oven/bun:1.3.11` successors and the pinned Redis image candidate before rollout. Counters for this run: - unaddressed critical CVEs: 7 - unaddressed medium/low CVEs: 126 - unaddressed total CVEs: 171 Sources: - https://nvd.nist.gov/vuln/detail/CVE-2026-57433 - https://www.cve.org/CVERecord?id=CVE-2026-57433 - https://security-tracker.debian.org/tracker/CVE-2026-57433
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#153
No description provided.