[security][CVE-2026-14456] OpenSSL in runtime base images #160

Open
opened 2026-08-18 13:18:57 +00:00 by dirtydishes · 0 comments
Owner

Summary

CVE-2026-14456 is newly disclosed and unaddressed in the runtime base images used by this repo. Current scans show it in both oven/bun:1.3.11 and redis:7.2, which are referenced by deployment/docker/Dockerfile.service, deployment/docker/Dockerfile.web, deployment/docker/Dockerfile.ingest-options, and deployment/docker/docker-compose.yml.

Affected components

  • oven/bun:1.3.11 on Debian 13.4 ships libssl3t64 3.5.5-1~deb13u1 and openssl-provider-legacy 3.5.5-1~deb13u1
  • redis:7.2 on Debian 12.15 ships libssl3 3.0.20-1~deb12u2

Severity

  • NVD lists CVE-2026-14456 with a CISA-ADP CVSS 3.1 base score of 7.5 (HIGH)
  • OpenSSL upstream labels the bug Low, but Debian/Trivy currently surface it as actionable in these runtime images

Project impact

The issue is an unbounded memory-growth denial-of-service bug in the OpenSSL QUIC listener path. I did not find repo evidence that Islandflow explicitly enables an OpenSSL QUIC listener, so direct app exploitability is less certain than the raw image exposure. Even so, these deployed base images currently ship affected OpenSSL builds and should be refreshed so runtime risk does not linger.

Remediation

  • Move Bun-based runtime images onto a Bun tag or digest that includes OpenSSL 3.5.8+
  • Move Redis onto a base image that includes OpenSSL 3.0.21+ or a distro backport that fixes this CVE
  • Re-scan the exact published image digests before rollout

Sources

Current counters

  • unaddressed critical CVEs: 3
  • unaddressed medium/low CVEs: 73
  • unaddressed total CVEs: 85
## Summary `CVE-2026-14456` is newly disclosed and unaddressed in the runtime base images used by this repo. Current scans show it in both `oven/bun:1.3.11` and `redis:7.2`, which are referenced by `deployment/docker/Dockerfile.service`, `deployment/docker/Dockerfile.web`, `deployment/docker/Dockerfile.ingest-options`, and `deployment/docker/docker-compose.yml`. ## Affected components - `oven/bun:1.3.11` on Debian 13.4 ships `libssl3t64 3.5.5-1~deb13u1` and `openssl-provider-legacy 3.5.5-1~deb13u1` - `redis:7.2` on Debian 12.15 ships `libssl3 3.0.20-1~deb12u2` ## Severity - NVD lists `CVE-2026-14456` with a CISA-ADP CVSS 3.1 base score of `7.5` (`HIGH`) - OpenSSL upstream labels the bug `Low`, but Debian/Trivy currently surface it as actionable in these runtime images ## Project impact The issue is an unbounded memory-growth denial-of-service bug in the OpenSSL QUIC listener path. I did not find repo evidence that Islandflow explicitly enables an OpenSSL QUIC listener, so direct app exploitability is less certain than the raw image exposure. Even so, these deployed base images currently ship affected OpenSSL builds and should be refreshed so runtime risk does not linger. ## Remediation - Move Bun-based runtime images onto a Bun tag or digest that includes OpenSSL `3.5.8+` - Move Redis onto a base image that includes OpenSSL `3.0.21+` or a distro backport that fixes this CVE - Re-scan the exact published image digests before rollout ## Sources - NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-14456 - CVE record: https://www.cve.org/CVERecord?id=CVE-2026-14456 - OpenSSL advisory: https://openssl-library.org/news/secadv/20260813.txt - OpenSSL vulnerability page: https://openssl-library.org/news/vulnerabilities/ ## Current counters - unaddressed critical CVEs: 3 - unaddressed medium/low CVEs: 73 - unaddressed total CVEs: 85
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#160
No description provided.