Skip to main content

enterpriseFrontend Security Scan

View Release Notes
Securityv3.9.8Generated 2026-07-27 08:02:54 UTC
Critical
Clean
High
52 found
Scan Date
Jul 27, 2026

Scanner: Docker Scout

Critical vulnerabilities: 0

High vulnerabilities: 7

Medium vulnerabilities: 6

Critical

No critical vulnerabilities found.

High

CVEPackageInstalledFixedDescription
GHSA-f88m-g3jw-g9cjsharp0.34.50.35.0GHSA-f88m-g3jw-g9cj: Dependency on Vulnerable Third-Party Component
CVE-2026-14257brace-expansion5.0.65.0.8CVE-2026-14257: Uncontrolled Resource Consumption
CVE-2026-13149brace-expansion5.0.65.0.7CVE-2026-13149: Uncontrolled Resource Consumption
CVE-2026-64641next16.2.616.2.11CVE-2026-64641: Excessive Iteration
CVE-2026-64642next16.2.616.2.11CVE-2026-64642: Improper Authorization
CVE-2026-64645next16.2.616.2.11CVE-2026-64645: Server-Side Request Forgery (SSRF)
CVE-2026-64649next16.2.616.2.11CVE-2026-64649: Server-Side Request Forgery (SSRF)

Medium

CVEPackageInstalledFixedDescription
GHSA-r292-9mhp-454mtar7.5.197.5.21GHSA-r292-9mhp-454m: Uncontrolled Resource Consumption
CVE-2026-64648next16.2.616.2.11CVE-2026-64648: Use of Cache Containing Sensitive Information
CVE-2026-64643next16.2.616.2.11CVE-2026-64643: Insertion of Sensitive Information Into Sent Data
CVE-2026-64644next16.2.616.2.11CVE-2026-64644: Inefficient Algorithmic Complexity
CVE-2026-64646next16.2.616.2.11CVE-2026-64646: Allocation of Resources Without Limits or Throttling
CVE-2026-64647next16.2.616.2.11CVE-2026-64647: Improper Encoding or Escaping of Output
© 2026 Dify All rights reserved.Enterprise release information is confidential. Do not distribute externally.