3.5 - Security fixes


3.5.4-funcrel

Fixes provided

CAST serviceCVESeverityDescription/PackageAffected CAST release
admin-centerCVE-2025-15467CRITICALopenssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing3.5.3
admin-centerCVE-2025-64720HIGHlibpng: LIBPNG buffer overflow3.5.3
admin-centerCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflow3.5.3
admin-centerCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_composite3.5.3
admin-centerCVE-2025-68973HIGHGnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write3.5.3
admin-centerCVE-2025-69419HIGHopenssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing3.5.3
admin-centerCVE-2026-22695HIGHlibpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read3.5.3
admin-centerCVE-2026-22801HIGHlibpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API3.5.3
ai-serviceCVE-2025-15467CRITICALopenssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing3.5.3
ai-serviceCVE-2025-65106HIGHlangchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates3.5.3
ai-serviceCVE-2025-68664CRITICALlangchain-core: LangChain: Arbitrary code execution via serialization injection3.5.3
ai-serviceCVE-2025-69223HIGHaiohttp: AIOHTTP’s HTTP Parser auto_decompress feature is vulnerable to zip bomb3.5.3
ai-serviceCVE-2025-69419HIGHopenssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing3.5.3
ai-serviceCVE-2026-0994HIGHpython: protobuf: Protobuf: Denial of Service due to recursion depth bypass3.5.3
ai-serviceCVE-2026-21441HIGHurllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)3.5.3
ai-serviceCVE-2026-23490HIGHpyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID3.5.3
analysis-nodeCVE-2025-14523HIGHlibsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins)3.5.3_core8.4.8
analysis-nodeCVE-2025-64720HIGHlibpng: LIBPNG buffer overflow3.5.3_core8.4.8
analysis-nodeCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflow3.5.3_core8.4.8
analysis-nodeCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_composite3.5.3_core8.4.8
analysis-nodeCVE-2025-68973HIGHGnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write3.5.3_core8.4.8
analysis-nodeCVE-2026-21441HIGHurllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)3.5.3_core8.4.8
analysis-nodeCVE-2026-21925HIGHopenjdk: Improve JMX connections (Oracle CPU 2026-01)3.5.3_core8.4.8
analysis-nodeCVE-2026-21933HIGHopenjdk: Improve HttpServer Request handling (Oracle CPU 2026-01)3.5.3_core8.4.8
analysis-nodeCVE-2026-21945HIGHopenjdk: Enhance Certificate Checking (Oracle CPU 2026-01)3.5.3_core8.4.8
auth-serviceCVE-2025-15467CRITICALopenssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing3.5.3
auth-serviceCVE-2025-64720HIGHlibpng: LIBPNG buffer overflow3.5.3
auth-serviceCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflow3.5.3
auth-serviceCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_composite3.5.3
auth-serviceCVE-2025-68973HIGHGnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write3.5.3
auth-serviceCVE-2025-69419HIGHopenssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing3.5.3
auth-serviceCVE-2026-22695HIGHlibpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read3.5.3
auth-serviceCVE-2026-22801HIGHlibpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API3.5.3
consoleCVE-2025-15467CRITICALopenssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing3.5.3
consoleCVE-2025-64720HIGHlibpng: LIBPNG buffer overflow3.5.3
consoleCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflow3.5.3
consoleCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_composite3.5.3
consoleCVE-2025-68973HIGHGnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write3.5.3
consoleCVE-2025-69419HIGHopenssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing3.5.3
consoleCVE-2026-22695HIGHlibpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read3.5.3
consoleCVE-2026-22801HIGHlibpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API3.5.3
dashboards-v3CVE-2025-68973HIGHGnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write3.5.3
etl-serviceCVE-2025-15467CRITICALopenssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing3.5.3
etl-serviceCVE-2025-69419HIGHopenssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing3.5.3
gatewayCVE-2025-15467CRITICALopenssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing3.5.3
gatewayCVE-2025-64720HIGHlibpng: LIBPNG buffer overflow3.5.3
gatewayCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflow3.5.3
gatewayCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_composite3.5.3
gatewayCVE-2025-68973HIGHGnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write3.5.3
gatewayCVE-2025-69419HIGHopenssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing3.5.3
gatewayCVE-2026-22695HIGHlibpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read3.5.3
gatewayCVE-2026-22801HIGHlibpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API3.5.3
neo4jCVE-2025-15467HIGHopenssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing3.5.3
neo4jCVE-2025-64720HIGHlibpng: LIBPNG buffer overflow3.5.3
neo4jCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflow3.5.3
neo4jCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_composite3.5.3
neo4jCVE-2025-68973HIGHGnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write3.5.3
viewerCVE-2025-15467CRITICALopenssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing3.5.3
viewerCVE-2025-69419HIGHopenssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing3.5.3
viewerCVE-2026-22695HIGHlibpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read3.5.3
viewerCVE-2026-22801HIGHlibpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API3.5.3

Known security issues (not yet fixed)

CAST serviceCVESeverityDescription/PackageAffected CAST release
ai-serviceCVE-2026-0861HIGHglibc: Integer overflow in memalign leads to heap corruption3.5.4
ai-serviceCVE-2026-23949HIGHjaraco.context: jaraco.context: Path traversal via malicious tar archives3.5.4
ai-serviceCVE-2026-24049HIGHwheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking3.5.4
neo4jCVE-2025-12183HIGHlz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure3.5.4
neo4jCVE-2025-6176HIGHScrapy: python-scrapy: brotli: Python brotli decompression bomb DoS3.5.4
neo4jCVE-2025-66566HIGHlz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing3.5.4
neo4jCVE-2026-24881HIGHGnuPG: GnuPG: Remote code execution and denial of service via crafted CMS EnvelopedData message3.5.4
neo4jCVE-2026-24882HIGHGnuPG: GnuPG: Stack-based buffer overflow in tpm2daemon allows arbitrary code execution3.5.4
sso-serviceCVE-2025-59250HIGHJDBC Driver for SQL Server has improper input validation issue3.5.4
sso-serviceCVE-2025-64720HIGHlibpng: LIBPNG buffer overflow3.5.4
sso-serviceCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflow3.5.4
sso-serviceCVE-2025-66021HIGHcom.googlecode.owasp-java-html-sanitizer/owasp-java-html-sanitizer: OWASP Java HTML Sanitizer vulnerable to XSS3.5.4
sso-serviceCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_composite3.5.4
sso-serviceCVE-2025-6965HIGHsqlite: Integer Truncation in SQLite3.5.4
sso-serviceCVE-2026-21945HIGHopenjdk: Enhance Certificate Checking (Oracle CPU 2026-01)3.5.4
sso-serviceCVE-2026-22184HIGHzlib: zlib: Arbitrary code execution via buffer overflow in untgz utility3.5.4
viewerCVE-2026-21932HIGHopenjdk: Enhance Handling of URIs (Oracle CPU 2026-01)3.5.4
viewerCVE-2026-21945HIGHopenjdk: Enhance Certificate Checking (Oracle CPU 2026-01)3.5.4

3.5.3-funcrel

SBOM

The SBOMs provided for CAST Imaging are generated in CycloneDXexternal link format (version 1.6) and delivered in JSON BOM output format. CycloneDX is a widely adopted industry standard for Software Bill of Materials, enabling interoperability with security, compliance, and supply chain risk management tools.

Fixes provided

CAST serviceCVESeverityDescription/PackageAffected CAST release
ai-serviceCVE-2025-66418HIGHurllib3: urllib3: Unbounded decompression chain leads to resource exhaustion3.5.0-funcrel
ai-serviceCVE-2025-66471HIGHurllib3 is a user-friendly HTTP client library for Python. Starting in …3.5.0-funcrel
analysis-nodeCVE-2025-66418HIGHurllib3: urllib3: Unbounded decompression chain leads to resource exhaustion3.5.0_core8.4.7
analysis-nodeCVE-2025-66471HIGHurllib3 is a user-friendly HTTP client library for Python. Starting in …3.5.0_core8.4.7
etl-serviceCVE-2025-61729HIGHcrypto/x509: Excessive resource consumption when printing error string for host certificate validation in crypto/x5093.5.0-funcrel
sso-serviceCVE-2025-6965HIGHsqlite: Integer Truncation in SQLite3.5.0-funcrel
viewerCVE-2025-61729HIGHcrypto/x509: Excessive resource consumption when printing error string for host certificate validation in crypto/x5093.5.0-funcrel
viewerCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_composite3.5.0-funcrel

Known security issues (not yet fixed)

CAST serviceCVESeverityDescription/PackageJustificationAffected CAST release
admin-centerCVE-2025-64720HIGHlibpng: LIBPNG buffer overflowThis CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
admin-centerCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflowThis CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
admin-centerCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_compositeNote that this CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
ai-serviceCVE-2025-65106HIGHlangchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates3.5.3-funcrel
auth-serviceCVE-2025-64720HIGHlibpng: LIBPNG buffer overflowThis CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
auth-serviceCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflowThis CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
auth-serviceCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_compositeNote that this CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
consoleCVE-2025-64720HIGHlibpng: LIBPNG buffer overflowThis CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
consoleCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflowThis CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
consoleCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_compositeNote that this CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
gatewayCVE-2025-64720HIGHlibpng: LIBPNG buffer overflowThis CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
gatewayCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflowThis CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
gatewayCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_compositeNote that this CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
neo4jCVE-2025-12183HIGHlz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure3.5.3-funcrel
neo4jCVE-2025-6176HIGHScrapy: python-scrapy: brotli: Python brotli decompression bomb DoS3.5.3-funcrel
neo4jCVE-2025-64720HIGHlibpng: LIBPNG buffer overflowThis CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
neo4jCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflowThis CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
neo4jCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_compositeNote that this CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
neo4jCVE-2025-66566HIGHlz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing3.5.3-funcrel
sso-serviceCVE-2025-59250HIGHJDBC Driver for SQL Server has improper input validation issue.This CVE was present in 3.5.0-funcrel. The library containing the CVE mssql-jdbchas been updated in 3.5.3-funcrel. The new version (msqsl-jdbc:13.2.1) contains the fix for the CVE, however, Trivy considers the version is still vulnerable (see discussion hereexternal link).3.5.3-funcrel
sso-serviceCVE-2025-64720HIGHlibpng: LIBPNG buffer overflowThis CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
sso-serviceCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflowThis CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel
sso-serviceCVE-2025-66021HIGHcom.googlecode.owasp-java-html-sanitizer/owasp-java-html-sanitizer: OWASP Java HTML Sanitizer vulnerable to XSS.This OWASP sanitizer library is a dependency from Keycloak and should be updated by the vendor.3.5.3-funcrel
sso-serviceCVE-2025-66293HIGHlibpng: LIBPNG out-of-bounds read in png_image_read_compositeNote that this CVE requires a fix on the base image, eclipse-temurin:21-jre-alpine. The impacts should be limited as there is no PNG file manipulation within the project.3.5.3-funcrel

3.5.2-funcrel

Fixes provided

None.

3.5.0-funcrel

Fixes provided

CAST serviceCVESeverityDescription/PackageAffected CAST release
ai-serviceCVE-2025-65106HIGHlangchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates3.4.5-funcrel
analysis-nodeCVE-2025-59375HIGHexpat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing3.4.5_core8.4.7
analysis-nodeCVE-2025-8176HIGHlibtiff: LibTIFF Use-After-Free Vulnerability3.4.5_core8.4.7
neo4jCVE-2023-43000HIGHwebkitgtk: Processing maliciously crafted web content may lead to memory corruption3.4.5-funcrel
neo4jCVE-2025-11021HIGHlibsoup: Out-of-Bounds Read in Cookie Date Handling of libsoup HTTP Library3.4.5-funcrel
neo4jCVE-2025-13502HIGHwebkit: WebKitGTK / WPE WebKit: Out-of-bounds read and integer underflow vulnerability leading to DoS3.4.5-funcrel
neo4jCVE-2025-43272HIGHwebkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash3.4.5-funcrel
neo4jCVE-2025-43342HIGHwebkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash3.4.5-funcrel
neo4jCVE-2025-43343HIGHwebkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash3.4.5-funcrel
neo4jCVE-2025-43368HIGHwebkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash3.4.5-funcrel
neo4jCVE-2025-43419HIGHwebkitgtk: Processing maliciously crafted web content may lead to memory corruption3.4.5-funcrel
neo4jCVE-2025-43421HIGHwebkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash3.4.5-funcrel
neo4jCVE-2025-43425HIGHwebkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash3.4.5-funcrel
neo4jCVE-2025-43427HIGHwebkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash3.4.5-funcrel
neo4jCVE-2025-43429HIGHwebkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash3.4.5-funcrel
neo4jCVE-2025-43430HIGHwebkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash3.4.5-funcrel
neo4jCVE-2025-43431HIGHwebkitgtk: Processing maliciously crafted web content may lead to memory corruption3.4.5-funcrel
neo4jCVE-2025-43432HIGHwebkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash3.4.5-funcrel
neo4jCVE-2025-43434HIGHwebkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash3.4.5-funcrel
neo4jCVE-2025-43440HIGHwebkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash3.4.5-funcrel
neo4jCVE-2025-43443HIGHwebkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash3.4.5-funcrel
neo4jCVE-2025-59375HIGHexpat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing3.4.5-funcrel
neo4jCVE-2025-6965HIGHsqlite: Integer Truncation in SQLite3.4.5-funcrel
neo4jCVE-2025-8176HIGHlibtiff: LibTIFF Use-After-Free Vulnerability3.4.5-funcrel
neo4jCVE-2025-9900HIGHlibtiff: Libtiff Write-What-Where3.4.5-funcrel
viewerCVE-2025-64720HIGHlibpng: LIBPNG buffer overflow3.4.5-funcrel
viewerCVE-2025-65018HIGHlibpng: LIBPNG heap buffer overflow3.4.5-funcrel