[security][CVE-2026-11822] SQLite in Bun runtime image #165
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
New active CVE detected by the
cve-security-triageautomation.CVE-2026-11822libsqlite3-0@3.46.1-7+deb13u1oven/bun:1.3.11viadeployment/docker/Dockerfile.service,deployment/docker/Dockerfile.web, anddeployment/docker/Dockerfile.ingest-options3.53.2; no patched Debian package version was reported by Trivy for this image digestProject impact
The shipped Bun runtime image carries a vulnerable SQLite library. NVD says crafted FTS5 page data can trigger memory corruption when an FTS5
MATCHquery runs. This repo does use SQLite-related tooling in deployment scripts and tests, and the vulnerable library remains present in the production base image until the Bun image digest moves to a patched SQLite build or Debian backport.Recommended remediation
oven/bun:1.3.11to an image digest that includes patched SQLite or a Debian backport for this CVERun counters
Sources