Security Vulnerability Kapacitor Binaries

Hi Team,

With recent Trivy scan, we identified several High severity vulnerabilities, as highlighted in the table below. We would like to understand whether fixes for these issues are already planned. If not, could you please let us know if there is any plan or timeline to address them?

Our setup: We are using a Debian-based image with Kapacitor version 1.8.6, installed via the Debian package.

Trivy Vulnerability Scan Results (usr/bin/kapacitord)

Vulnerability ID Severity CVSS Score Title Vulnerable Version Fixed Version Triage Information
CVE-2026-34040 HIGH 7.8 Moby: Authorization bypass vulnerability v27.1.1+incompatible 29.3.1
CVE-2026-33997 MEDIUM 8.1 Moby: Privilege validation bypass during plugin installation v27.1.1+incompatible 29.3.1
CVE-2025-54410 LOW 5.2 Moby’s Firewalld reload removes bridge network isolation v27.1.1+incompatible 25.0.13, 28.0.0
CVE-2022-21698 HIGH 7.5 Prometheus client_golang: Denial of service using InstrumentHandlerCounter v1.10.0 1.11.1
CVE-2026-42154 HIGH Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint v1.8.2-0.20210331101223-3cafc58827d1 0.311.3, 0.305.2
CVE-2026-2303 MEDIUM Affecting package telegraf for versions less than 1.29.4-21 v1.5.1 1.17.7
CVE-2026-39828 HIGH Unauthorized command execution via discarded SSH permissions v0.51.0 0.52.0
CVE-2026-39829 HIGH Denial of Service via crafted public key with excessive parameters v0.51.0 0.52.0
CVE-2026-39830 HIGH Denial of Service via resource leak from unsolicited SSH responses v0.51.0 0.52.0
CVE-2026-39831 HIGH Security key bypass due to missing user presence check v0.51.0 0.52.0
CVE-2026-39832 HIGH Security bypass due to improper handling of key restrictions v0.51.0 0.52.0
CVE-2026-39835 HIGH Denial of Service via crafted SSH certificate v0.51.0 0.52.0
CVE-2026-42508 HIGH Revocation bypass via unchecked SignatureKey v0.51.0 0.52.0
CVE-2026-46595 HIGH Authorization bypass due to skipped source-address validation v0.51.0 0.52.0
CVE-2026-46597 HIGH Denial of Service via crafted AES-GCM packet decoder inputs v0.51.0 0.52.0
CVE-2026-39827 MEDIUM Denial of Service via repeated rejected channel openings v0.51.0 0.52.0
CVE-2026-39833 MEDIUM Security bypass due to unenforced key confirmation v0.51.0 0.52.0
CVE-2026-39834 MEDIUM Denial of Service due to integer overflow in SSH channel write v0.51.0 0.52.0
CVE-2026-46598 MEDIUM Denial of Service via malformed input v0.51.0 0.52.0
CVE-2026-25681 HIGH Arbitrary code execution via Cross-Site Scripting v0.54.0 0.55.0
CVE-2026-27136 HIGH Cross-Site Scripting via HTML parsing bypass v0.54.0 0.55.0
CVE-2026-39821 HIGH Privilege escalation via incorrect Punycode label processing v0.54.0 0.55.0
CVE-2026-25680 MEDIUM Denial of Service due to excessive HTML parsing v0.54.0 0.55.0
CVE-2026-42502 MEDIUM Cross-Site Scripting via unexpected HTML tree rendering v0.54.0 0.55.0
CVE-2026-42506 MEDIUM Cross-Site Scripting via arbitrary HTML parsing v0.54.0 0.55.0
CVE-2026-46600 UNKNOWN Parsing an invalid SVCB or HTTPS RR can panic v0.54.0 0.56.0
CVE-2026-56852 UNKNOWN Infinite loop on invalid input v0.37.0 0.39.0
GHSA-hrxh-6v49-42gf HIGH gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities v1.81.1 1.82.1
CVE-2026-27145 HIGH crypto/x509: Denial of Service via excessive processing of DNS SAN entries v1.25.10 1.25.11, 1.26.4
CVE-2026-39822 HIGH os.Root: Symlink following vulnerability allows directory traversal v1.25.10 1.25.12, 1.26.5, 1.27.0-rc.2
CVE-2026-42504 HIGH MIME: Denial of Service via maliciously crafted MIME header v1.25.10 1.25.11, 1.26.4
CVE-2026-42505 MEDIUM crypto/tls: Information disclosure in Encrypted Client Hello v1.25.10 1.25.12, 1.26.5, 1.27.0-rc.2
CVE-2026-42507 MEDIUM net/textproto: Misleading error messages via input injection v1.25.10 1.25.11, 1.26.4

Trivy Vulnerability Scan Results (usr/bin/kapacitor)

Vulnerability ID Severity CVSS Score Title Vulnerable Version Fixed Version Triage Information
CVE-2026-39828 HIGH Unauthorized command execution via discarded SSH permissions v0.51.0 0.52.0
CVE-2026-39829 HIGH Denial of Service via crafted public key with excessive parameters v0.51.0 0.52.0
CVE-2026-39830 HIGH Denial of Service via resource leak from unsolicited SSH responses v0.51.0 0.52.0
CVE-2026-39831 HIGH Security key bypass due to missing user presence check v0.51.0 0.52.0
CVE-2026-39832 HIGH Security bypass due to improper handling of key restrictions v0.51.0 0.52.0
CVE-2026-39835 HIGH Denial of Service via crafted SSH certificate v0.51.0 0.52.0
CVE-2026-42508 HIGH Revocation bypass via unchecked SignatureKey v0.51.0 0.52.0
CVE-2026-46595 HIGH Authorization bypass due to skipped source-address validation v0.51.0 0.52.0
CVE-2026-46597 HIGH Denial of Service via crafted AES-GCM packet decoder inputs v0.51.0 0.52.0
CVE-2026-39827 MEDIUM Denial of Service via repeated rejected channel openings v0.51.0 0.52.0
CVE-2026-39833 MEDIUM Security bypass due to unenforced key confirmation v0.51.0 0.52.0
CVE-2026-39834 MEDIUM Denial of Service due to integer overflow in SSH channel write v0.51.0 0.52.0
CVE-2026-46598 MEDIUM Denial of Service via malformed input v0.51.0 0.52.0
CVE-2026-56852 UNKNOWN Infinite loop on invalid input v0.37.0 0.39.0
CVE-2026-27145 HIGH crypto/x509: Denial of Service via excessive processing of DNS SAN entries v1.25.10 1.25.11, 1.26.4
CVE-2026-39822 HIGH os.Root: Symlink following vulnerability allows directory traversal v1.25.10 1.25.12, 1.26.5, 1.27.0-rc.2
CVE-2026-42504 HIGH MIME: Denial of Service via maliciously crafted MIME header v1.25.10 1.25.11, 1.26.4
CVE-2026-42505 MEDIUM crypto/tls: Information disclosure in Encrypted Client Hello v1.25.10 1.25.12, 1.26.5, 1.27.0-rc.2
CVE-2026-42507 MEDIUM net/textproto: Misleading error messages via input injection v1.25.10 1.25.11, 1.26.4

Trivy Vulnerability Scan Results (usr/bin/tickfmt)

Vulnerability ID Severity CVSS Score Title Vulnerable Version Fixed Version Triage Information
CVE-2026-27145 HIGH crypto/x509: Denial of Service via excessive processing of DNS SAN entries v1.25.10 1.25.11, 1.26.4
CVE-2026-39822 HIGH os.Root: Symlink following vulnerability allows directory traversal v1.25.10 1.25.12, 1.26.5, 1.27.0-rc.2
CVE-2026-42504 HIGH MIME: Denial of Service via maliciously crafted MIME header v1.25.10 1.25.11, 1.26.4
CVE-2026-42505 MEDIUM crypto/tls: Information disclosure in Encrypted Client Hello v1.25.10 1.25.12, 1.26.5, 1.27.0-rc.2
CVE-2026-42507 MEDIUM net/textproto: Misleading error messages via input injection v1.25.10 1.25.11, 1.26.4

Please let us know if you need any additional details from our side.

Thanks

Hey there,

For future correspondence like this, please contact us by email at security@influxdata.com, as that goes directly to our security team and notifies them immediately. The community forum isn’t really the best venue to have these conversations. I’ve been told you’ve already sent an email with the same content as this post to that address already, so please expect a reply from them there.