[security][CVE-2026-57433] perl-base in Bun and Redis images #167

Open
opened 2026-08-26 13:22:29 +00:00 by dirtydishes · 0 comments
Owner

New active CVE detected by the cve-security-triage automation.

  • CVE: CVE-2026-57433
  • Component: perl-base@5.40.1-6 in oven/bun:1.3.11 and perl-base@5.36.0-7+deb12u3 in redis:7.2
  • In-repo runtime: Bun base image from deployment/docker/Dockerfile.service, deployment/docker/Dockerfile.web, and deployment/docker/Dockerfile.ingest-options, plus redis:7.2 in deployment/docker/docker-compose.yml
  • Severity: High in Trivy; NVD lists the CVE with a CISA-ADP CVSS 3.1 vector but no numeric NVD score on the page
  • Fixed version: upstream Storable 3.41; no patched Debian package version was reported by Trivy for these image digests

Project impact

Both shipped runtime images carry the vulnerable Perl Storable code path through perl-base. NVD says crafted serialized SX_HOOK records can overflow an item count during deserialization and crash the process. Even though Islandflow does not directly use Perl application code, the vulnerable package is present in deployed runtime images and should be cleared from the base-image baseline.

Recommended remediation

  • Move to Bun and Redis image digests that include a Debian backport or newer Perl/Storable package fixing this CVE
  • If image tags must stay pinned, rebuild from a patched distro base once Debian publishes fixed packages
  • Re-scan the exact pushed image digests after the base-image change

Run counters

  • unaddressed critical CVEs: 2
  • unaddressed medium/low CVEs: 77
  • unaddressed total CVEs: 92

Sources

New active CVE detected by the `cve-security-triage` automation. - CVE: `CVE-2026-57433` - Component: `perl-base@5.40.1-6` in `oven/bun:1.3.11` and `perl-base@5.36.0-7+deb12u3` in `redis:7.2` - In-repo runtime: Bun base image from `deployment/docker/Dockerfile.service`, `deployment/docker/Dockerfile.web`, and `deployment/docker/Dockerfile.ingest-options`, plus `redis:7.2` in `deployment/docker/docker-compose.yml` - Severity: High in Trivy; NVD lists the CVE with a CISA-ADP CVSS 3.1 vector but no numeric NVD score on the page - Fixed version: upstream Storable `3.41`; no patched Debian package version was reported by Trivy for these image digests Project impact Both shipped runtime images carry the vulnerable Perl Storable code path through `perl-base`. NVD says crafted serialized SX_HOOK records can overflow an item count during deserialization and crash the process. Even though Islandflow does not directly use Perl application code, the vulnerable package is present in deployed runtime images and should be cleared from the base-image baseline. Recommended remediation - Move to Bun and Redis image digests that include a Debian backport or newer Perl/Storable package fixing this CVE - If image tags must stay pinned, rebuild from a patched distro base once Debian publishes fixed packages - Re-scan the exact pushed image digests after the base-image change Run counters - unaddressed critical CVEs: 2 - unaddressed medium/low CVEs: 77 - unaddressed total CVEs: 92 Sources - https://nvd.nist.gov/vuln/detail/CVE-2026-57433 - https://www.cve.org/CVERecord?id=CVE-2026-57433 - http://www.openwall.com/lists/oss-security/2026/07/13/7 - https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#167
No description provided.