mirror of
https://hubproxy.babadafafafafa.cn/https://github.com/jxxghp/MoviePilot.git
synced 2026-09-20 08:03:34 +08:00
86 lines
3.2 KiB
YAML
86 lines
3.2 KiB
YAML
vulnerabilities:
|
|
- id: CVE-2026-84445
|
|
paths:
|
|
- usr/bin/rclone
|
|
purls:
|
|
- pkg:golang/google.golang.org/grpc@v1.84.0-dev.0.20260723093437-b6eac429d7b6
|
|
expired_at: 2026-10-09
|
|
statement: The pinned rclone image d6f5448594ecefefcf09cfeaf85cb7a21a866328032576ce2c1813e7b59c66dc has no google.golang.org/grpc/xds functions in either its amd64 or arm64 Go function table. GHSA-2v4p-qf9q-27wj requires xds.NewGRPCServer, so the affected interceptor is not linked. Reassess this exception when upgrading rclone or before expiry; see docs/development-setup.md.
|
|
- id: GHSA-6v7p-g79w-8964
|
|
paths:
|
|
- Python
|
|
purls:
|
|
- pkg:pypi/msgpack@1.1.2
|
|
expired_at: 2026-11-20
|
|
statement: The finding belongs to the base image's system pip and is not imported by MoviePilot.
|
|
- id: CVE-2025-47273
|
|
paths:
|
|
- Python
|
|
purls:
|
|
- pkg:pypi/setuptools@70.3.0
|
|
expired_at: 2026-11-20
|
|
statement: The finding belongs to the base image's system pip and is not used for dependency installation.
|
|
- id: CVE-2026-33818
|
|
paths:
|
|
- usr/bin/rclone
|
|
purls:
|
|
- pkg:golang/stdlib@v1.26.5
|
|
expired_at: 2026-11-20
|
|
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
|
|
- id: CVE-2026-39821
|
|
paths:
|
|
- usr/bin/rclone
|
|
purls:
|
|
- pkg:golang/stdlib@v1.26.5
|
|
expired_at: 2026-11-20
|
|
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
|
|
- id: CVE-2026-46600
|
|
paths:
|
|
- usr/bin/rclone
|
|
purls:
|
|
- pkg:golang/stdlib@v1.26.5
|
|
expired_at: 2026-11-20
|
|
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
|
|
- id: CVE-2026-56853
|
|
paths:
|
|
- usr/bin/rclone
|
|
purls:
|
|
- pkg:golang/stdlib@v1.26.5
|
|
expired_at: 2026-11-20
|
|
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
|
|
- id: CVE-2026-56854
|
|
paths:
|
|
- usr/bin/rclone
|
|
purls:
|
|
- pkg:golang/golang.org/x/crypto@v0.54.0
|
|
expired_at: 2026-11-20
|
|
statement: The pinned stable rclone image has no release with the upstream x/crypto v0.55.0 fix yet; its SFTP callbacks do not set source-address permissions, so the affected path is not reachable. Reassess when this exception expires.
|
|
- id: CVE-2026-56858
|
|
paths:
|
|
- usr/bin/rclone
|
|
purls:
|
|
- pkg:golang/stdlib@v1.26.5
|
|
expired_at: 2026-11-20
|
|
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
|
|
- id: CVE-2026-56859
|
|
paths:
|
|
- usr/bin/rclone
|
|
purls:
|
|
- pkg:golang/stdlib@v1.26.5
|
|
expired_at: 2026-11-20
|
|
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
|
|
- id: CVE-2026-56860
|
|
paths:
|
|
- usr/bin/rclone
|
|
purls:
|
|
- pkg:golang/stdlib@v1.26.5
|
|
expired_at: 2026-11-20
|
|
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
|
|
- id: CVE-2026-56862
|
|
paths:
|
|
- usr/bin/rclone
|
|
purls:
|
|
- pkg:golang/stdlib@v1.26.5
|
|
expired_at: 2026-11-20
|
|
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
|