Skip to main content

agent-runtime Security Scan

View Release Notes
Securityv3.12.0Generated 2026-07-31 09:23:27 UTC
Critical
2 found
High
23 found
Scan Date
Jul 31, 2026

Scanner: Docker Scout

Critical vulnerabilities: 2

High vulnerabilities: 22

Medium vulnerabilities: 14

Critical

CVEPackageInstalledFixedDescription
CVE-2026-59873tar6.2.17.5.19CVE-2026-59873: Allocation of Resources Without Limits or Throttling
CVE-2026-59873tar6.2.17.5.19CVE-2026-59873: Allocation of Resources Without Limits or Throttling

High

CVEPackageInstalledFixedDescription
CVE-2026-26960tar6.2.17.5.8CVE-2026-26960: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-26960tar6.2.17.5.8CVE-2026-26960: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-64756glob10.4.511.1.0CVE-2025-64756: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec...
CVE-2026-14257brace-expansion2.0.25.0.8CVE-2026-14257: Uncontrolled Resource Consumption
CVE-2026-27903minimatch9.0.59.0.7CVE-2026-27903: Inefficient Algorithmic Complexity
CVE-2026-27904minimatch9.0.59.0.7CVE-2026-27904: Inefficient Regular Expression Complexity
CVE-2026-33671picomatch4.0.24.0.4CVE-2026-33671: Inefficient Regular Expression Complexity
CVE-2026-48815sigstore3.1.04.1.1CVE-2026-48815: Improper Verification of Cryptographic Signature
CVE-2026-13149brace-expansion2.0.22.1.2CVE-2026-13149: Uncontrolled Resource Consumption
CVE-2026-23745tar6.2.17.5.3CVE-2026-23745: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-23745tar6.2.17.5.3CVE-2026-23745: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-24842tar6.2.17.5.7CVE-2026-24842: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-24842tar6.2.17.5.7CVE-2026-24842: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-29786tar6.2.17.5.10CVE-2026-29786: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-29786tar6.2.17.5.10CVE-2026-29786: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-31802tar6.2.17.5.11CVE-2026-31802: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-31802tar6.2.17.5.11CVE-2026-31802: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-26996minimatch9.0.510.2.1CVE-2026-26996: Inefficient Regular Expression Complexity
CVE-2026-59874tar6.2.17.5.18CVE-2026-59874: Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-59874tar6.2.17.5.18CVE-2026-59874: Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-23950tar6.2.17.5.4CVE-2026-23950: Improper Handling of Unicode Encoding
CVE-2026-23950tar6.2.17.5.4CVE-2026-23950: Improper Handling of Unicode Encoding

Medium

CVEPackageInstalledFixedDescription
CVE-2026-33672picomatch4.0.24.0.4CVE-2026-33672: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollut...
CVE-2026-42338ip-address9.0.510.1.1CVE-2026-42338: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-59871tar6.2.17.5.18CVE-2026-59871: Incorrect Type Conversion or Cast
CVE-2026-59871tar6.2.17.5.18CVE-2026-59871: Incorrect Type Conversion or Cast
CVE-2026-59875tar6.2.17.5.17CVE-2026-59875: Uncaught Exception
CVE-2026-59875tar6.2.17.5.17CVE-2026-59875: Uncaught Exception
GHSA-r292-9mhp-454mtar6.2.17.5.21GHSA-r292-9mhp-454m: Uncontrolled Resource Consumption
GHSA-r292-9mhp-454mtar6.2.17.5.21GHSA-r292-9mhp-454m: Uncontrolled Resource Consumption
GHSA-r292-9mhp-454mtar6.2.17.5.21GHSA-r292-9mhp-454m: Uncontrolled Resource Consumption
CVE-2026-48758core2.0.03.2.1CVE-2026-48758: Improper Verification of Cryptographic Signature
CVE-2023-49092rsa0.9.10not fixedCVE-2023-49092
CVE-2026-33750brace-expansion2.0.25.0.5CVE-2026-33750: Uncontrolled Resource Consumption
CVE-2026-53655tar6.2.17.5.16CVE-2026-53655: Interpretation Conflict
CVE-2026-53655tar6.2.17.5.16CVE-2026-53655: Interpretation Conflict
© 2026 Dify All rights reserved.Enterprise release information is confidential. Do not distribute externally.