Hi Team,
With recent Trivy scan, we identified several High severity vulnerabilities, as highlighted in the table below. We would like to understand whether fixes for these issues are already planned. If not, could you please let us know if there is any plan or timeline to address them?
Our setup: We are using a Debian-based image with Kapacitor version 1.8.6, installed via the Debian package.
Trivy Vulnerability Scan Results (usr/bin/kapacitord)
| Vulnerability ID | Severity | CVSS Score | Title | Vulnerable Version | Fixed Version | Triage Information |
|---|---|---|---|---|---|---|
| CVE-2026-34040 | HIGH | 7.8 | Moby: Authorization bypass vulnerability | v27.1.1+incompatible | 29.3.1 | |
| CVE-2026-33997 | MEDIUM | 8.1 | Moby: Privilege validation bypass during plugin installation | v27.1.1+incompatible | 29.3.1 | |
| CVE-2025-54410 | LOW | 5.2 | Moby’s Firewalld reload removes bridge network isolation | v27.1.1+incompatible | 25.0.13, 28.0.0 | |
| CVE-2022-21698 | HIGH | 7.5 | Prometheus client_golang: Denial of service using InstrumentHandlerCounter |
v1.10.0 | 1.11.1 | |
| CVE-2026-42154 | HIGH | Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint | v1.8.2-0.20210331101223-3cafc58827d1 | 0.311.3, 0.305.2 | ||
| CVE-2026-2303 | MEDIUM | Affecting package telegraf for versions less than 1.29.4-21 |
v1.5.1 | 1.17.7 | ||
| CVE-2026-39828 | HIGH | Unauthorized command execution via discarded SSH permissions | v0.51.0 | 0.52.0 | ||
| CVE-2026-39829 | HIGH | Denial of Service via crafted public key with excessive parameters | v0.51.0 | 0.52.0 | ||
| CVE-2026-39830 | HIGH | Denial of Service via resource leak from unsolicited SSH responses | v0.51.0 | 0.52.0 | ||
| CVE-2026-39831 | HIGH | Security key bypass due to missing user presence check | v0.51.0 | 0.52.0 | ||
| CVE-2026-39832 | HIGH | Security bypass due to improper handling of key restrictions | v0.51.0 | 0.52.0 | ||
| CVE-2026-39835 | HIGH | Denial of Service via crafted SSH certificate | v0.51.0 | 0.52.0 | ||
| CVE-2026-42508 | HIGH | Revocation bypass via unchecked SignatureKey |
v0.51.0 | 0.52.0 | ||
| CVE-2026-46595 | HIGH | Authorization bypass due to skipped source-address validation | v0.51.0 | 0.52.0 | ||
| CVE-2026-46597 | HIGH | Denial of Service via crafted AES-GCM packet decoder inputs | v0.51.0 | 0.52.0 | ||
| CVE-2026-39827 | MEDIUM | Denial of Service via repeated rejected channel openings | v0.51.0 | 0.52.0 | ||
| CVE-2026-39833 | MEDIUM | Security bypass due to unenforced key confirmation | v0.51.0 | 0.52.0 | ||
| CVE-2026-39834 | MEDIUM | Denial of Service due to integer overflow in SSH channel write | v0.51.0 | 0.52.0 | ||
| CVE-2026-46598 | MEDIUM | Denial of Service via malformed input | v0.51.0 | 0.52.0 | ||
| CVE-2026-25681 | HIGH | Arbitrary code execution via Cross-Site Scripting | v0.54.0 | 0.55.0 | ||
| CVE-2026-27136 | HIGH | Cross-Site Scripting via HTML parsing bypass | v0.54.0 | 0.55.0 | ||
| CVE-2026-39821 | HIGH | Privilege escalation via incorrect Punycode label processing | v0.54.0 | 0.55.0 | ||
| CVE-2026-25680 | MEDIUM | Denial of Service due to excessive HTML parsing | v0.54.0 | 0.55.0 | ||
| CVE-2026-42502 | MEDIUM | Cross-Site Scripting via unexpected HTML tree rendering | v0.54.0 | 0.55.0 | ||
| CVE-2026-42506 | MEDIUM | Cross-Site Scripting via arbitrary HTML parsing | v0.54.0 | 0.55.0 | ||
| CVE-2026-46600 | UNKNOWN | Parsing an invalid SVCB or HTTPS RR can panic | v0.54.0 | 0.56.0 | ||
| CVE-2026-56852 | UNKNOWN | Infinite loop on invalid input | v0.37.0 | 0.39.0 | ||
| GHSA-hrxh-6v49-42gf | HIGH | gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities | v1.81.1 | 1.82.1 | ||
| CVE-2026-27145 | HIGH | crypto/x509: Denial of Service via excessive processing of DNS SAN entries |
v1.25.10 | 1.25.11, 1.26.4 | ||
| CVE-2026-39822 | HIGH | os.Root: Symlink following vulnerability allows directory traversal |
v1.25.10 | 1.25.12, 1.26.5, 1.27.0-rc.2 | ||
| CVE-2026-42504 | HIGH | MIME: Denial of Service via maliciously crafted MIME header | v1.25.10 | 1.25.11, 1.26.4 | ||
| CVE-2026-42505 | MEDIUM | crypto/tls: Information disclosure in Encrypted Client Hello |
v1.25.10 | 1.25.12, 1.26.5, 1.27.0-rc.2 | ||
| CVE-2026-42507 | MEDIUM | net/textproto: Misleading error messages via input injection |
v1.25.10 | 1.25.11, 1.26.4 |
Trivy Vulnerability Scan Results (usr/bin/kapacitor)
| Vulnerability ID | Severity | CVSS Score | Title | Vulnerable Version | Fixed Version | Triage Information |
|---|---|---|---|---|---|---|
| CVE-2026-39828 | HIGH | Unauthorized command execution via discarded SSH permissions | v0.51.0 | 0.52.0 | ||
| CVE-2026-39829 | HIGH | Denial of Service via crafted public key with excessive parameters | v0.51.0 | 0.52.0 | ||
| CVE-2026-39830 | HIGH | Denial of Service via resource leak from unsolicited SSH responses | v0.51.0 | 0.52.0 | ||
| CVE-2026-39831 | HIGH | Security key bypass due to missing user presence check | v0.51.0 | 0.52.0 | ||
| CVE-2026-39832 | HIGH | Security bypass due to improper handling of key restrictions | v0.51.0 | 0.52.0 | ||
| CVE-2026-39835 | HIGH | Denial of Service via crafted SSH certificate | v0.51.0 | 0.52.0 | ||
| CVE-2026-42508 | HIGH | Revocation bypass via unchecked SignatureKey |
v0.51.0 | 0.52.0 | ||
| CVE-2026-46595 | HIGH | Authorization bypass due to skipped source-address validation | v0.51.0 | 0.52.0 | ||
| CVE-2026-46597 | HIGH | Denial of Service via crafted AES-GCM packet decoder inputs | v0.51.0 | 0.52.0 | ||
| CVE-2026-39827 | MEDIUM | Denial of Service via repeated rejected channel openings | v0.51.0 | 0.52.0 | ||
| CVE-2026-39833 | MEDIUM | Security bypass due to unenforced key confirmation | v0.51.0 | 0.52.0 | ||
| CVE-2026-39834 | MEDIUM | Denial of Service due to integer overflow in SSH channel write | v0.51.0 | 0.52.0 | ||
| CVE-2026-46598 | MEDIUM | Denial of Service via malformed input | v0.51.0 | 0.52.0 | ||
| CVE-2026-56852 | UNKNOWN | Infinite loop on invalid input | v0.37.0 | 0.39.0 | ||
| CVE-2026-27145 | HIGH | crypto/x509: Denial of Service via excessive processing of DNS SAN entries |
v1.25.10 | 1.25.11, 1.26.4 | ||
| CVE-2026-39822 | HIGH | os.Root: Symlink following vulnerability allows directory traversal |
v1.25.10 | 1.25.12, 1.26.5, 1.27.0-rc.2 | ||
| CVE-2026-42504 | HIGH | MIME: Denial of Service via maliciously crafted MIME header | v1.25.10 | 1.25.11, 1.26.4 | ||
| CVE-2026-42505 | MEDIUM | crypto/tls: Information disclosure in Encrypted Client Hello |
v1.25.10 | 1.25.12, 1.26.5, 1.27.0-rc.2 | ||
| CVE-2026-42507 | MEDIUM | net/textproto: Misleading error messages via input injection |
v1.25.10 | 1.25.11, 1.26.4 |
Trivy Vulnerability Scan Results (usr/bin/tickfmt)
| Vulnerability ID | Severity | CVSS Score | Title | Vulnerable Version | Fixed Version | Triage Information |
|---|---|---|---|---|---|---|
| CVE-2026-27145 | HIGH | crypto/x509: Denial of Service via excessive processing of DNS SAN entries |
v1.25.10 | 1.25.11, 1.26.4 | ||
| CVE-2026-39822 | HIGH | os.Root: Symlink following vulnerability allows directory traversal |
v1.25.10 | 1.25.12, 1.26.5, 1.27.0-rc.2 | ||
| CVE-2026-42504 | HIGH | MIME: Denial of Service via maliciously crafted MIME header | v1.25.10 | 1.25.11, 1.26.4 | ||
| CVE-2026-42505 | MEDIUM | crypto/tls: Information disclosure in Encrypted Client Hello |
v1.25.10 | 1.25.12, 1.26.5, 1.27.0-rc.2 | ||
| CVE-2026-42507 | MEDIUM | net/textproto: Misleading error messages via input injection |
v1.25.10 | 1.25.11, 1.26.4 |
Please let us know if you need any additional details from our side.
Thanks
