[security][CVE-2026-14456] OpenSSL in runtime base images #160
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
CVE-2026-14456is newly disclosed and unaddressed in the runtime base images used by this repo. Current scans show it in bothoven/bun:1.3.11andredis:7.2, which are referenced bydeployment/docker/Dockerfile.service,deployment/docker/Dockerfile.web,deployment/docker/Dockerfile.ingest-options, anddeployment/docker/docker-compose.yml.Affected components
oven/bun:1.3.11on Debian 13.4 shipslibssl3t64 3.5.5-1~deb13u1andopenssl-provider-legacy 3.5.5-1~deb13u1redis:7.2on Debian 12.15 shipslibssl3 3.0.20-1~deb12u2Severity
CVE-2026-14456with a CISA-ADP CVSS 3.1 base score of7.5(HIGH)Low, but Debian/Trivy currently surface it as actionable in these runtime imagesProject impact
The issue is an unbounded memory-growth denial-of-service bug in the OpenSSL QUIC listener path. I did not find repo evidence that Islandflow explicitly enables an OpenSSL QUIC listener, so direct app exploitability is less certain than the raw image exposure. Even so, these deployed base images currently ship affected OpenSSL builds and should be refreshed so runtime risk does not linger.
Remediation
3.5.8+3.0.21+or a distro backport that fixes this CVESources
Current counters