[security][CVE-2026-57433] perl-base in Bun and Redis images #167
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
New active CVE detected by the
cve-security-triageautomation.CVE-2026-57433perl-base@5.40.1-6inoven/bun:1.3.11andperl-base@5.36.0-7+deb12u3inredis:7.2deployment/docker/Dockerfile.service,deployment/docker/Dockerfile.web, anddeployment/docker/Dockerfile.ingest-options, plusredis:7.2indeployment/docker/docker-compose.yml3.41; no patched Debian package version was reported by Trivy for these image digestsProject impact
Both shipped runtime images carry the vulnerable Perl Storable code path through
perl-base. NVD says crafted serialized SX_HOOK records can overflow an item count during deserialization and crash the process. Even though Islandflow does not directly use Perl application code, the vulnerable package is present in deployed runtime images and should be cleared from the base-image baseline.Recommended remediation
Run counters
Sources
github.com/Perl/perl5@e4f681784b.patch