Security Advisories

This page lists Common Vulnerabilities and Exposures (CVEs) addressed in each Kloudfuse release, together with any HIGH or CRITICAL CVEs that remain unresolved pending upstream fixes. All Kloudfuse service images are scanned with Trivy and AWS Inspector after each release. For the raw scan reports, see the GCS security reports bucket.

For release-by-release feature and fix details, see also Release Notes.

About This Page

Rows are sorted CRITICAL → HIGH → MEDIUM → LOW within each table. CVE IDs link to the National Vulnerability Database, the Red Hat Security Advisory, or a GitHub Security Advisory. The Fixed In column shows what change (toolchain bump, dependency upgrade, base OS refresh) resolved the CVE. The Status column in the outstanding table explains why a fix is not yet available.

Release 4.3.0

Fixed CVEs (28 total — 4 Critical, 24 High)

CVE Severity CVSS Affected Component Fixed In Remediation

CVE-2026-15925

CRITICAL

9.2

snowflake-connector-python (datadog-agent)

snowflake-connector-python 4.7.3

Resolved by upgrading the pinned snowflake-connector-python package bundled by the Datadog Agent image build.

CVE-2026-53713

CRITICAL

9.1

github.com/envoyproxy/gateway (datadog-agent, datadog-cluster-agent)

Datadog Agent 7.82.3

Envoy Gateway vulnerability resolved by upgrading the bundled Datadog Agent release, which carries envoyproxy/gateway forward from v1.7.1 to v1.7.4.

CVE-2026-75595

CRITICAL

9.1

io.netty:netty-handler (ZooKeeper, logs-parser, Pinot)

netty 4.1.137.Final / 4.1.138.Final

Heap overflow in netty’s DNS-over-HTTPS response parsing, resolved by upgrading the pinned netty version across the affected services.

CVE-2026-75604

CRITICAL

9.0

next (jackson-fips)

next 16.3.4

Unauthenticated remote code execution in the Next.js Image Optimization API, resolved by upgrading next while staying on the 16.x line.

CVE-2026-33818

HIGH

7.5

Go stdlib (all FIPS service images)

Go 1.26.7 FIPS toolchain

Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7 across all affected service images.

CVE-2026-39821

HIGH

8.2

Go stdlib (all FIPS service images)

Go 1.26.7 FIPS toolchain

Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7.

CVE-2026-46600

HIGH

7.5

Go stdlib (all FIPS service images)

Go 1.26.7 FIPS toolchain

Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7.

CVE-2026-56853

HIGH

7.5

Go stdlib (all FIPS service images)

Go 1.26.7 FIPS toolchain

Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7.

CVE-2026-56858

HIGH

8.1

Go stdlib (all FIPS service images)

Go 1.26.7 FIPS toolchain

Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7.

CVE-2026-56859

HIGH

7.5

Go stdlib (all FIPS service images)

Go 1.26.7 FIPS toolchain

Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7.

CVE-2026-56860

HIGH

7.5

Go stdlib (all FIPS service images)

Go 1.26.7 FIPS toolchain

Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7.

CVE-2026-56862

HIGH

7.5

Go stdlib (all FIPS service images)

Go 1.26.7 FIPS toolchain

Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7.

GHSA-f88m-g3jw-g9cj

HIGH

7.0

sharp (jackson-fips)

sharp 0.35.0

Arbitrary code execution vulnerability in the sharp image-processing library. Resolved by forcing the transitive dependency to version 0.35.0 or later.

CVE-2026-53714

HIGH

7.4

github.com/envoyproxy/gateway (datadog-agent, datadog-cluster-agent)

Datadog Agent 7.82.3

Envoy Gateway vulnerability resolved by upgrading the bundled Datadog Agent release, which carries envoyproxy/gateway forward from v1.7.1 to v1.7.4.

CVE-2026-46600

HIGH

7.5

golang.org/x/net (datadog-agent, datadog-cluster-agent)

Datadog Agent 7.82.3

Resolved by upgrading the bundled Datadog Agent release, which carries golang.org/x/net forward from v0.55.0 to v0.57.0.

CVE-2026-56852

HIGH

7.5

golang.org/x/text (datadog-agent, datadog-cluster-agent)

Datadog Agent 7.82.3

Resolved by upgrading the bundled Datadog Agent release, which carries golang.org/x/text forward from v0.37.0 to v0.40.0.

GHSA-hrxh-6v49-42gf

HIGH

8.8

google.golang.org/grpc (datadog-agent, datadog-cluster-agent)

Datadog Agent 7.82.3

Resolved by upgrading the bundled Datadog Agent release, which carries grpc forward from v1.81.1 to v1.82.1.

CVE-2026-84304

HIGH

8.7

google.golang.org/grpc (datadog-agent, datadog-cluster-agent)

grpc v1.83.2

A subsequent grpc HIGH CVE re-pinned directly to v1.83.2, since the Datadog Agent’s own vendored grpc release had not yet caught up.

CVE-2026-84445

HIGH

google.golang.org/grpc (datadog-agent, datadog-cluster-agent)

grpc v1.83.2

Denial-of-service in grpc-go xDS servers, resolved by the same v1.83.2 re-pin as CVE-2026-84304.

CVE-2026-53488

HIGH

8.8

containerd/containerd (datadog-agent, datadog-cluster-agent)

Datadog Agent 7.82.3

Resolved by upgrading the bundled Datadog Agent release, which migrated off the vulnerable v1 containerd module entirely in favor of containerd/containerd/v2.

CVE-2026-56864 / CVE-2026-56865

HIGH

7.5 / 8.8

golang.org/x/mod (datadog-agent, datadog-cluster-agent)

golang.org/x/mod 0.40.0

The Datadog Agent 7.82.3 release did not fully carry this dependency forward, so it was patched directly to version 0.40.0.

CVE-2026-56740 / CVE-2026-56741

HIGH

7.5

org.jline:jline-remote-telnet (Pinot)

jline 3.30.14

Resolved by upgrading the pinned jline.version, which covers the jline-remote-telnet artifact from the same multi-module release.

CVE-2026-54428

HIGH

7.5

org.apache.httpcomponents.core5:httpcore5-h2 (Pinot)

httpcore5 5.4.3

Denial of service via oversized HTTP/2 HPACK header blocks, resolved by bumping the pinned httpcore5 version and adding an explicit dependency-management entry for httpcore5-h2.

CVE-2026-54399

HIGH

7.5

org.apache.httpcomponents.core5:httpcore5 (Pinot)

httpcore5 5.4.3

Resolved by the same httpcore5 version bump as CVE-2026-54428.

CVE-2026-59902

HIGH

7.5

io.netty:netty-transport-sctp (Pinot)

netty 4.1.137.Final

Resolved by the same pinned netty version bump that addressed the httpcore5 and jline CVEs above.

GHSA-3f6p-5ww8-9rcr

HIGH

8.2

mysql2 (jackson-fips)

mysql2 3.22.0

Auth-plugin downgrade in mysql2 that could leak plaintext credentials, resolved by upgrading the pinned dependency.

GHSA-2x7j-588g-ccc2

HIGH

7.5

nodemailer (jackson-fips)

nodemailer 9.1.1

Quadratic-time denial of service in nodemailer’s address parser, resolved by upgrading the pinned dependency.

CVE-2026-11822 / CVE-2026-11824

HIGH

7.5

sqlite-libs (Base OS, all ubi9-minimal-cc-based images)

RHEL 9.8 errata base image refresh

Resolved by refreshing the ubi9-minimal-cc / ubi9-cc-go-builder base image digest to the latest available RHEL 9.8 errata across the fleet. Still outstanding for `kf-vector’s separate base image — see below.

Outstanding CVEs (High / Critical)

CVE Severity Affected Component Status & Rationale

GHSA-r277-6w6q-xmqw

CRITICAL

github.com/getkin/kin-openapi (grafana)

Blocked by an upstream Grafana dependency pin that has not yet been updated.

CVE-2026-56854

CRITICAL

golang.org/x/crypto (grafana)

Deferred pending a full Grafana version upgrade, rather than patching individual transitive dependencies piecemeal.

CVE-2026-76905

HIGH

github.com/getkin/kin-openapi (grafana)

Same upstream Grafana dependency pin as above.

CVE-2026-77354

HIGH

github.com/getkin/kin-openapi (grafana)

Same upstream Grafana dependency pin as above.

CVE-2026-84304

HIGH

google.golang.org/grpc (grafana)

Same Grafana version-upgrade deferral as above. This CVE is already fixed for datadog-agent — see the Fixed CVEs table.

CVE-2026-84445

HIGH

google.golang.org/grpc (grafana)

Same as above.

CVE-2026-46600

HIGH

golang.org/x/net (grafana)

Same Grafana version-upgrade deferral as above. This CVE is already fixed for datadog-agent and the FIPS service images — see the Fixed CVEs table.

CVE-2026-56852

HIGH

golang.org/x/text (grafana)

Same Grafana version-upgrade deferral as above. This CVE is already fixed for datadog-agent — see the Fixed CVEs table.

CVE-2026-43871

HIGH

github.com/apache/thrift (grafana)

Same Grafana version-upgrade deferral as above.

CVE-2026-21728

HIGH

github.com/grafana/tempo (grafana)

Tracks the same upstream dependency chain as the prometheus CVEs below.

CVE-2026-28377

HIGH

github.com/grafana/tempo (grafana)

Tracks the same upstream dependency chain as the prometheus CVEs below.

CVE-2026-42151

HIGH

github.com/prometheus/prometheus (grafana, logs-query-service)

Requires a coordinated dependency upgrade with compatibility validation before it can be applied.

CVE-2026-42154

HIGH

github.com/prometheus/prometheus (grafana, logs-query-service)

Same as above.

CVE-2026-50271

HIGH

ddtrace (datadog-agent, datadog-cluster-agent)

Fix requires a major-version upgrade (3.x to 4.x); deliberately not attempted this cycle.

CVE-2026-41567

HIGH

github.com/docker/docker, github.com/moby/moby (envoy-gateway-fips, grafana)

No fixed version has been published as a consumable Go module — the fix corresponds to a Docker product release, not a Go module tag currently available upstream.

CVE-2026-42306

HIGH

github.com/docker/docker, github.com/moby/moby (envoy-gateway-fips, grafana)

Same as above.

CVE-2026-34040

HIGH

github.com/moby/moby (grafana)

Same as above.

CVE-2026-11822 / CVE-2026-11824

HIGH

sqlite-libs (kf-vector)

kf-vector builds from a separate Amazon Linux 2023 base image, not ubi9-minimal-cc — the fleet-wide RHEL errata refresh (see Fixed CVEs table) does not apply here. Needs a dedicated Amazon Linux package refresh or a base-image migration.

CVE-2026-11940

HIGH

python3 / python3-libs / python-unversioned-command (kf-vector)

Same separate Amazon Linux 2023 base image as above.

CVE-2026-44690 / CVE-2026-55973

HIGH

unbound-libs (kf-vector)

Same separate Amazon Linux 2023 base image as above.

CVE-2026-11352

HIGH

curl-minimal / libcurl-minimal (advance-functions, Pinot, UI)

Not yet published by Red Hat for the RHEL 9.8 stream.

CVE-2026-11586

HIGH

curl-minimal / libcurl-minimal (advance-functions, Pinot, UI)

Not yet published by Red Hat for the RHEL 9.8 stream.

CVE-2026-8925

HIGH

curl-minimal / libcurl-minimal (advance-functions, Pinot, UI)

Not yet published by Red Hat for the RHEL 9.8 stream.

CVE-2026-22020

HIGH

java-21-openjdk-headless (logs-parser, Pinot, ZooKeeper), libpng (UI)

Not yet published by Red Hat for the RHEL 9.8 stream.

CVE-2026-44172

HIGH

mariadb-connector-c (advance-functions, UI)

Not yet published by Red Hat for the RHEL 9.8 stream.