Skip to main content

api-insecure Security Scan

View Release Notes
Securityv3.9.10Generated 2026-08-13 08:11:29 UTC
Critical
Clean
High
18 found
Scan Date
Aug 13, 2026

Scanner: Docker Scout

Critical vulnerabilities: 10

High vulnerabilities: 25

Critical

CVEPackageInstalledFixedDescription
CVE-2026-33186grpc1.77.01.79.3CVE-2026-33186: Improper Authorization
CVE-2026-39830crypto0.45.00.52.0CVE-2026-39830: Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2026-39831crypto0.45.00.52.0CVE-2026-39831: Missing Authorization
CVE-2026-39832crypto0.45.00.52.0CVE-2026-39832: Improper Preservation of Permissions
CVE-2026-39833crypto0.45.00.52.0CVE-2026-39833: Missing Authorization
CVE-2026-39834crypto0.45.00.52.0CVE-2026-39834: Integer Overflow or Wraparound
CVE-2026-42508crypto0.45.00.52.0CVE-2026-42508: Improper Certificate Validation
CVE-2026-39821net0.47.00.55.0CVE-2026-39821
CVE-2025-68121stdlib1.25.51.25.7CVE-2025-68121
CVE-2026-46595crypto0.45.00.52.0CVE-2026-46595: Incorrect Implementation of Authentication Algorithm

High

CVEPackageInstalledFixedDescription
CVE-2026-24051sdk1.38.01.40.0CVE-2026-24051: Untrusted Search Path
CVE-2026-45022v55.16.45.19.0CVE-2026-45022: Incorrect Behavior Order: Validate Before Canonicalize
CVE-2026-71556v55.16.45.19.2CVE-2026-71556: Improper Link Resolution Before File Access ('Link Following')
CVE-2026-39883sdk1.38.01.43.0CVE-2026-39883: Untrusted Search Path
CVE-2025-61726stdlib1.25.51.25.6CVE-2025-61726
CVE-2026-25679stdlib1.25.51.25.8CVE-2026-25679
CVE-2026-29181otel1.38.01.41.0CVE-2026-29181: Uncontrolled Resource Consumption
CVE-2026-32280stdlib1.25.51.25.9CVE-2026-32280
CVE-2026-32281stdlib1.25.51.25.9CVE-2026-32281
CVE-2026-32283stdlib1.25.51.25.9CVE-2026-32283
CVE-2026-33811stdlib1.25.51.25.10CVE-2026-33811
CVE-2026-33814net0.47.01.25.10CVE-2026-33814
CVE-2026-33814net0.47.01.25.10CVE-2026-33814
CVE-2026-39820stdlib1.25.51.25.10CVE-2026-39820
CVE-2026-39829crypto0.45.00.52.0CVE-2026-39829: Improper Validation of Specified Quantity in Input
CVE-2026-39836stdlib1.25.51.25.10CVE-2026-39836
CVE-2026-41602thrift0.22.00.23.0CVE-2026-41602: Integer Overflow or Wraparound
CVE-2026-42499stdlib1.25.51.25.10CVE-2026-42499
CVE-2026-42504stdlib1.25.51.25.11CVE-2026-42504
CVE-2026-46597crypto0.45.00.52.0CVE-2026-46597: Incorrect Type Conversion or Cast
CVE-2026-57585msgpack1.1.21.2.1CVE-2026-57585
GHSA-6v7p-g79w-8964msgpack1.1.21.2.1GHSA-6v7p-g79w-8964: Use After Free
CVE-2025-47273setuptools70.3.078.1.1CVE-2025-47273: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-44973v55.6.25.9.0CVE-2026-44973: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
GHSA-hrxh-6v49-42gfgrpc1.77.01.82.1GHSA-hrxh-6v49-42gf: Uncaught Exception
© 2026 Dify All rights reserved.Enterprise release information is confidential. Do not distribute externally.