[security][CVE-2026-11824] SQLite in Bun runtime image #166

Open
opened 2026-08-26 13:22:29 +00:00 by dirtydishes · 0 comments
Owner

New active CVE detected by the cve-security-triage automation.

  • CVE: CVE-2026-11824
  • Component: libsqlite3-0@3.46.1-7+deb13u1
  • In-repo runtime: oven/bun:1.3.11 via deployment/docker/Dockerfile.service, deployment/docker/Dockerfile.web, and deployment/docker/Dockerfile.ingest-options
  • Severity: High (CVSS 3.1 7.8 HIGH, CVSS 4.0 8.5 HIGH on NVD)
  • Fixed version: upstream SQLite 3.53.2; no patched Debian package version was reported by Trivy for this image digest

Project impact

The shipped Bun runtime image carries a vulnerable SQLite library. NVD says crafted FTS5 continuation page metadata can trigger a heap overflow during MATCH query processing. This repo does use SQLite-related tooling in deployment scripts and tests, and the vulnerable library remains present in the production base image until the Bun image digest moves to a patched SQLite build or Debian backport.

Recommended remediation

  • Move off oven/bun:1.3.11 to an image digest that includes patched SQLite or a Debian backport for this CVE
  • If Bun must stay pinned short-term, rebuild on a patched Debian 13 base or layer in the fixed SQLite package once available
  • Re-scan the exact pushed image digest after the base-image change

Run counters

  • unaddressed critical CVEs: 2
  • unaddressed medium/low CVEs: 77
  • unaddressed total CVEs: 92

Sources

New active CVE detected by the `cve-security-triage` automation. - CVE: `CVE-2026-11824` - Component: `libsqlite3-0@3.46.1-7+deb13u1` - In-repo runtime: `oven/bun:1.3.11` via `deployment/docker/Dockerfile.service`, `deployment/docker/Dockerfile.web`, and `deployment/docker/Dockerfile.ingest-options` - Severity: High (CVSS 3.1 7.8 HIGH, CVSS 4.0 8.5 HIGH on NVD) - Fixed version: upstream SQLite `3.53.2`; no patched Debian package version was reported by Trivy for this image digest Project impact The shipped Bun runtime image carries a vulnerable SQLite library. NVD says crafted FTS5 continuation page metadata can trigger a heap overflow during `MATCH` query processing. This repo does use SQLite-related tooling in deployment scripts and tests, and the vulnerable library remains present in the production base image until the Bun image digest moves to a patched SQLite build or Debian backport. Recommended remediation - Move off `oven/bun:1.3.11` to an image digest that includes patched SQLite or a Debian backport for this CVE - If Bun must stay pinned short-term, rebuild on a patched Debian 13 base or layer in the fixed SQLite package once available - Re-scan the exact pushed image digest after the base-image change Run counters - unaddressed critical CVEs: 2 - unaddressed medium/low CVEs: 77 - unaddressed total CVEs: 92 Sources - https://nvd.nist.gov/vuln/detail/CVE-2026-11824 - https://www.cve.org/CVERecord?id=CVE-2026-11824 - https://sqlite.org/releaselog/3_53_2.html
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#166
No description provided.