Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 1 addition & 3 deletions doc/source/configuration/ipa.rst
Original file line number Diff line number Diff line change
Expand Up @@ -32,9 +32,7 @@ deployment:

stackhpc_ipa_arch: aarch64

The supported values are ``amd64`` and ``aarch64``. Rocky Linux 9 uses
``stackhpc_rocky_9_ipa_image_version`` for ``amd64`` and
``stackhpc_rocky_9_ipa_image_version_aarch64`` for ``aarch64``, similarly
The supported values are ``amd64`` and ``aarch64``.
Rocky Linux 10 uses ``stackhpc_rocky_10_ipa_image_version`` for ``amd64`` and
``stackhpc_rocky_10_ipa_image_version_aarch64`` for ``aarch64``.

Expand Down
24 changes: 2 additions & 22 deletions etc/kayobe/kolla-image-tags.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,25 +4,5 @@
# where the key is the OS distro and the value is the tag to deploy.
kolla_image_tags:
openstack:
rocky-10: 2026.1-rocky-10-20260701T090934
ubuntu-noble: 2026.1-ubuntu-noble-20260701T090934
bifrost:
rocky-10: 2026.1-rocky-10-20260625T132007
ubuntu-noble: 2026.1-ubuntu-noble-20260625T132007
ironic_http:
rocky-10: 2026.1-rocky-10-20260724T130738
ubuntu-noble: 2026.1-ubuntu-noble-20260724T130738
keystone_httpd:
rocky-10: 2026.1-rocky-10-20260724T130738
ubuntu-noble: 2026.1-ubuntu-noble-20260724T130738
letsencrypt_webserver:
rocky-10: 2026.1-rocky-10-20260724T130738
ubuntu-noble: 2026.1-ubuntu-noble-20260724T130738
nova:
rocky-10: 2026.1-rocky-10-20260702T080453
ubuntu-noble: 2026.1-ubuntu-noble-20260702T080453
prometheus:
rocky-10: 2026.1-rocky-10-20260702T080453
ubuntu-noble: 2026.1-ubuntu-noble-20260702T080453
valkey:
ubuntu-noble: 2026.1-ubuntu-noble-20260724T130738
rocky-10: 2026.1-rocky-10-20260805T101613
ubuntu-noble: 2026.1-ubuntu-noble-20260805T101613
28 changes: 25 additions & 3 deletions etc/kayobe/kolla/repos.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,100 +5,122 @@ ubuntu:
suite: "noble noble-updates noble-backports"
component: "main universe"
gpg_key: "/usr/share/keyrings/ubuntu-archive-keyring.gpg"
trusted: True
trusted: true
build_only: true
ubuntu-security:
url: "{{ stackhpc_repo_ubuntu_noble_security_url }}"
suite: "noble-security"
component: "main universe"
gpg_key: "/usr/share/keyrings/ubuntu-archive-keyring.gpg"
trusted: True
trusted: true
build_only: true
ubuntu-cloud-archive:
url: "{{ stackhpc_repo_ubuntu_cloud_archive_url }}"
component: "main"
gpg_key: "/usr/share/keyrings/ubuntu-cloud-keyring.gpg"
suite: "noble-updates/{{ openstack_release_codename }}"
trusted: True
trusted: true
build_only: true

rpm:
appstream:
baseurl: "{{ stackhpc_repo_rocky_10_appstream_url }}"
gpgkey: "https://dl.rockylinux.org/pub/rocky/RPM-GPG-KEY-Rocky-10"
name: "appstream"
build_only: true
baseos:
baseurl: "{{ stackhpc_repo_rocky_10_baseos_url }}"
gpgkey: "https://dl.rockylinux.org/pub/rocky/RPM-GPG-KEY-Rocky-10"
name: "baseos"
build_only: true
ceph:
baseurl: "{{ stackhpc_repo_centos_stream_10_storage_ceph_squid_url }}"
gpgkey: "https://www.centos.org/keys/RPM-GPG-KEY-CentOS-SIG-Storage"
name: "centos-ceph-squid"
build_only: true
crb:
baseurl: "{{ stackhpc_repo_rocky_10_crb_url }}"
gpgkey: "https://dl.rockylinux.org/pub/rocky/RPM-GPG-KEY-Rocky-10"
name: "crb"
build_only: true
docker-ce:
baseurl: "{{ stackhpc_repo_centos_stream_10_docker_url }}"
gpgkey: "https://download.docker.com/linux/centos/gpg"
name: "docker-ce"
build_only: true
epel:
baseurl: "{{ stackhpc_repo_epel_10_url }}"
gpgkey: "https://dl.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL-$releasever"
name: "epel"
build_only: true
erlang:
baseurl: "{{ stackhpc_repo_rhel9_rabbitmq_erlang_url }}"
gpgkey: "https://github.com/rabbitmq/signing-keys/releases/download/3.0/cloudsmith.rabbitmq-erlang.E495BB49CC4BBE5B.key"
name: "rabbitmq_rabbitmq-erlang"
build_only: true
extras:
baseurl: "{{ stackhpc_repo_rocky_10_extras_url }}"
gpgkey: "https://dl.rockylinux.org/pub/rocky/RPM-GPG-KEY-Rocky-10"
name: "extras"
build_only: true
fluentd:
baseurl: "{{ stackhpc_repo_rhel_10_fluent_6_url }}"
gpgkey: "https://fluentd.cdn.cncf.io/GPG-KEY-fluent-package"
name: "fluent-package-lts"
build_only: true
grafana:
baseurl: "{{ stackhpc_repo_grafana_url }}"
gpgkey: "https://rpm.grafana.com/gpg.key"
name: "grafana"
build_only: true
hacluster:
baseurl: "{{ stackhpc_repo_rocky_10_highavailability_url }}"
gpgkey: "https://dl.rockylinux.org/pub/rocky/RPM-GPG-KEY-Rocky-10"
name: "highavailability"
build_only: true
mariadb:
baseurl: "{{ stackhpc_repo_rhel_10_mariadb_11_4_url }}"
gpgkey: "https://downloads.mariadb.com/MariaDB/RPM-GPG-KEY-MariaDB"
name: "mariadb"
build_only: true
opensearch:
baseurl: "{{ stackhpc_repo_opensearch_3_x_yum_url }}"
gpgkey: "https://artifacts.opensearch.org/publickeys/opensearch-release.pgp"
repo_gpgcheck: 1
name: "opensearch-3.x"
build_only: true
opensearch-dashboards:
baseurl: "{{ stackhpc_repo_opensearch_dashboards_3_x_yum_url }}"
gpgkey: "https://artifacts.opensearch.org/publickeys/opensearch-release.pgp"
repo_gpgcheck: 1
name: "opensearch-dashboards-3.x"
build_only: true
openvswitch:
baseurl: "{{ stackhpc_repo_centos_stream_10_nfv_openvswitch_url }}"
gpgkey: "https://www.centos.org/keys/RPM-GPG-KEY-CentOS-SIG-NFV"
name: "centos-nfv-openvswitch"
build_only: true
proxysql:
baseurl: "{{ stackhpc_repo_almalinux_10_proxysql_3_0_url }}"
gpgkey: "https://repo.proxysql.com/ProxySQL/proxysql-3.0.x/repo_pub_key"
name: "proxysql"
build_only: true
rabbitmq:
baseurl: "{{ stackhpc_repo_rhel9_rabbitmq_server_url }}"
gpgkey: |
https://github.com/rabbitmq/signing-keys/releases/download/3.0/cloudsmith.rabbitmq-server.9F4587F226208342.key
https://github.com/rabbitmq/signing-keys/releases/download/3.0/rabbitmq-release-signing-key.asc
name: "rabbitmq_rabbitmq-server"
build_only: true
security:
baseurl: "{{ stackhpc_repo_rocky_10_security_url }}"
gpgkey: "https://dl.rockylinux.org/pub/rocky/RPM-GPG-KEY-Rocky-10"
name: "security"
build_only: true

rocky-aarch64:
erlang:
baseurl: "{{ stackhpc_repo_rhel9_rabbitmq_erlang_27_url }}"
gpgkey: "https://download.copr.fedorainfracloud.org/results/@openstack-kolla/rabbitmq-erlang-27/pubkey.gpg"
name: "copr-rabbitmq-erlang"
build_only: true
6 changes: 2 additions & 4 deletions etc/kayobe/pulp-ipa-image-versions.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,6 @@
---
# IPA image versioning tags
#TODO: Switch once RL10 images are available
stackhpc_rocky_9_ipa_image_version: "2025.1-20260420T095100"
stackhpc_rocky_9_ipa_image_version_aarch64: "2025.1-20260420T095100"
stackhpc_rocky_10_ipa_image_version: "2025.1-20260805T091024"
stackhpc_rocky_10_ipa_image_version_aarch64: "2025.1-20260805T091024"
stackhpc_rocky_10_ipa_image_version: "2026.1-20260813T115725"
stackhpc_rocky_10_ipa_image_version_aarch64: "2026.1-20260813T115725"
stackhpc_ubuntu_noble_ipa_image_version: "2025.1-20260420T095100"
86 changes: 43 additions & 43 deletions etc/kayobe/pulp-repo-versions.yml
Original file line number Diff line number Diff line change
@@ -1,49 +1,49 @@
---
# This file is autogenerated by Ansible using the following workflow:
# https://github.com/stackhpc/stackhpc-release-train/actions/workflows/package-update-kayobe.yml
stackhpc_pulp_repo_almalinux_10_proxysql_3_0_version: 20260605T211649
stackhpc_pulp_repo_centos_stream_10_docker_aarch64_version: 20260620T010620
stackhpc_pulp_repo_centos_stream_10_docker_version: 20260619T215327
stackhpc_pulp_repo_centos_stream_10_nfv_openvswitch_aarch64_version: 20260603T233007
stackhpc_pulp_repo_centos_stream_10_nfv_openvswitch_version: 20260602T230909
stackhpc_pulp_repo_centos_stream_10_storage_ceph_squid_aarch64_version: 20260603T233007
stackhpc_pulp_repo_centos_stream_10_storage_ceph_squid_version: 20260602T230909
stackhpc_pulp_repo_doca_3_2_2_rhel10_aarch64_version: 20260326T091359
stackhpc_pulp_repo_doca_3_2_2_rhel10_x86_64_version: 20260326T091359
stackhpc_pulp_repo_docker_ce_ubuntu_noble_version: 20260622T222357
stackhpc_pulp_repo_elrepo_10_aarch64_version: 20260220T152827
stackhpc_pulp_repo_elrepo_10_version: 20260620T002710
stackhpc_pulp_repo_epel_10_aarch64_version: 20260624T000231
stackhpc_pulp_repo_epel_10_version: 20260623T220913
stackhpc_pulp_repo_ubuntu_noble_fluent_6_version: 20260615T110539
stackhpc_pulp_repo_rhel_10_fluent_6_version: 20260327T202539
stackhpc_pulp_repo_grafana_version: 20260623T210745
stackhpc_pulp_repo_almalinux_10_proxysql_3_0_version: 20260804T131930
stackhpc_pulp_repo_centos_stream_10_docker_aarch64_version: 20260804T131930
stackhpc_pulp_repo_centos_stream_10_docker_version: 20260804T131930
stackhpc_pulp_repo_centos_stream_10_nfv_openvswitch_aarch64_version: 20260804T131930
stackhpc_pulp_repo_centos_stream_10_nfv_openvswitch_version: 20260804T131930
stackhpc_pulp_repo_centos_stream_10_storage_ceph_squid_aarch64_version: 20260804T131930
stackhpc_pulp_repo_centos_stream_10_storage_ceph_squid_version: 20260804T131930
stackhpc_pulp_repo_doca_3_2_2_rhel10_aarch64_version: 20260804T131930
stackhpc_pulp_repo_doca_3_2_2_rhel10_x86_64_version: 20260804T131930
stackhpc_pulp_repo_docker_ce_ubuntu_noble_version: 20260804T131930
stackhpc_pulp_repo_elrepo_10_aarch64_version: 20260804T131930
stackhpc_pulp_repo_elrepo_10_version: 20260804T131930
stackhpc_pulp_repo_epel_10_aarch64_version: 20260804T131930
stackhpc_pulp_repo_epel_10_version: 20260804T131930
stackhpc_pulp_repo_grafana_apt_version: 20260622T222446
stackhpc_pulp_repo_grafana_version: 20260804T131930
stackhpc_pulp_repo_opensearch_3_x_yum_version: 20260610T213138
stackhpc_pulp_repo_opensearch_dashboards_3_x_yum_version: 20260610T213138
stackhpc_pulp_repo_rhel9_rabbitmq_erlang_27_aarch64_version: 20260112T224827
stackhpc_pulp_repo_rhel9_rabbitmq_erlang_version: 20260616T214234
stackhpc_pulp_repo_rhel9_rabbitmq_server_version: 20260616T214234
stackhpc_pulp_repo_rhel_10_mariadb_11_4_aarch64_version: 20260527T210633
stackhpc_pulp_repo_rhel_10_mariadb_11_4_version: 20260527T210633
stackhpc_pulp_repo_rocky_10_2_appstream_aarch64_version: 20260620T010620
stackhpc_pulp_repo_rocky_10_2_appstream_source_version: 20260620T003535
stackhpc_pulp_repo_rocky_10_2_appstream_version: 20260620T002710
stackhpc_pulp_repo_rocky_10_2_baseos_aarch64_version: 20260620T010620
stackhpc_pulp_repo_rocky_10_2_baseos_source_version: 20260620T003535
stackhpc_pulp_repo_rocky_10_2_baseos_version: 20260620T003803
stackhpc_pulp_repo_rocky_10_2_crb_aarch64_version: 20260620T010620
stackhpc_pulp_repo_rocky_10_2_crb_source_version: 20260602T004048
stackhpc_pulp_repo_rocky_10_2_crb_version: 20260620T002710
stackhpc_pulp_repo_rocky_10_2_extras_aarch64_version: 20260602T012631
stackhpc_pulp_repo_rocky_10_2_extras_source_version: 20260602T004048
stackhpc_pulp_repo_rocky_10_2_extras_version: 20260602T001113
stackhpc_pulp_repo_rocky_10_2_highavailability_aarch64_version: 20260602T012631
stackhpc_pulp_repo_rocky_10_2_highavailability_source_version: 20260602T004048
stackhpc_pulp_repo_rocky_10_2_highavailability_version: 20260602T001113
stackhpc_pulp_repo_rocky_10_2_security_aarch64_version: 20260606T230245
stackhpc_pulp_repo_rocky_10_2_security_source_version: 20260605T232846
stackhpc_pulp_repo_rocky_10_2_security_version: 20260606T223509
stackhpc_pulp_repo_ubuntu_cloud_archive_version: 20260621T235438
stackhpc_pulp_repo_ubuntu_noble_security_version: 20260622T030723
stackhpc_pulp_repo_ubuntu_noble_version: 20260622T030723
stackhpc_pulp_repo_rhel9_rabbitmq_erlang_27_aarch64_version: 20260804T131930
stackhpc_pulp_repo_rhel9_rabbitmq_erlang_version: 20260804T131930
stackhpc_pulp_repo_rhel9_rabbitmq_server_version: 20260804T131930
stackhpc_pulp_repo_rhel_10_fluent_6_version: 20260804T131930
stackhpc_pulp_repo_rhel_10_mariadb_11_4_aarch64_version: 20260804T131930
stackhpc_pulp_repo_rhel_10_mariadb_11_4_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_appstream_aarch64_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_appstream_source_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_appstream_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_baseos_aarch64_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_baseos_source_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_baseos_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_crb_aarch64_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_crb_source_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_crb_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_extras_aarch64_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_extras_source_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_extras_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_highavailability_aarch64_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_highavailability_source_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_highavailability_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_security_aarch64_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_security_source_version: 20260804T131930
stackhpc_pulp_repo_rocky_10_2_security_version: 20260804T131930
stackhpc_pulp_repo_ubuntu_cloud_archive_version: 20260804T131930
stackhpc_pulp_repo_ubuntu_noble_fluent_6_version: 20260615T110539
stackhpc_pulp_repo_ubuntu_noble_security_version: 20260804T131930
stackhpc_pulp_repo_ubuntu_noble_version: 20260804T131930
12 changes: 6 additions & 6 deletions etc/kayobe/seed.yml
Original file line number Diff line number Diff line change
Expand Up @@ -114,17 +114,17 @@ seed_pulp_container_enabled: true

seed_pulp_container:
pulp:
image: quay.io/pulp/pulp
image: "quay.io/pulp/pulp"
pre: "{{ kayobe_config_path }}/containers/pulp/pre.yml"
post: "{{ kayobe_config_path }}/containers/pulp/post.yml"
tag: "3.81.0"
tag: "3.85.26"
network_mode: host
# Override deploy_containers_defaults.init == true to ensure
# s6-overlay-suexec starts as pid 1
init: false
env:
PULP_CONTENT_WORKERS: "{{ [ansible_facts.processor_vcpus * 2 + 1, 12] | min }}"
PULP_API_WORKERS: "{{ [ansible_facts.processor_vcpus * 2 + 1, 12] | min }}"
PULP_CONTENT_WORKERS: "{{ [ansible_facts.processor_vcpus * 2 + 1, 12] | min | string }}"
PULP_API_WORKERS: "{{ [ansible_facts.processor_vcpus * 2 + 1, 12] | min | string }}"
PULP_HTTPS: "{{ 'true' if pulp_enable_tls | bool else 'false' }}"
volumes:
- /opt/kayobe/containers/pulp:/etc/pulp
Expand All @@ -139,9 +139,9 @@ seed_squid_container_enabled: false

seed_squid_container:
squid:
image: ghcr.io/stackhpc/docker-squid
image: ubuntu/squid
pre: "{{ kayobe_config_path }}/containers/squid_proxy/pre.yml"
tag: "6.10"
tag: "7.2-26.04_edge"
network_mode: host
volumes:
- squid_spool:/var/spool/squid
Expand Down
4 changes: 1 addition & 3 deletions etc/kayobe/stackhpc-ipa-images.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,6 @@ stackhpc_ipa_image_url: "{{ stackhpc_release_pulp_content_url }}/ipa-images/\

# IPA image version tag selection
stackhpc_ipa_image_version: >-
{{ stackhpc_rocky_9_ipa_image_version_aarch64 if os_distribution == 'rocky' and os_release == '9' and stackhpc_ipa_arch == 'aarch64' else
stackhpc_rocky_10_ipa_image_version_aarch64 if os_distribution == 'rocky' and os_release == '10' and stackhpc_ipa_arch == 'aarch64' else
stackhpc_rocky_9_ipa_image_version if os_distribution == 'rocky' and os_release == '9' else
{{ stackhpc_rocky_10_ipa_image_version_aarch64 if os_distribution == 'rocky' and os_release == '10' and stackhpc_ipa_arch == 'aarch64' else
stackhpc_rocky_10_ipa_image_version if os_distribution == 'rocky' and os_release == '10' else
stackhpc_ubuntu_noble_ipa_image_version if os_distribution == 'ubuntu' and os_release == 'noble' }}
7 changes: 7 additions & 0 deletions etc/kayobe/trivy/allowed-vulnerabilities.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,10 +27,17 @@ fluentd_allowed_vulnerabilities:
- CVE-2026-42257
- CVE-2026-42258

# Should be fixed once Grafana 13.1.2 RPM is released
grafana_allowed_vulnerabilities:
- GHSA-r277-6w6q-xmqw

Comment on lines +30 to +33

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== allowed file =="
cat -n etc/kayobe/trivy/allowed-vulnerabilities.yml

echo
echo "== related docs/options references =="
rg -n "allowed-vulnerabilities|allow.*vulner|grafana_allowed_vulnerabilities|opensearch|CVE-2026-59873|GHSA-r277-6w6q-xmqw" -S .

Repository: stackhpc/stackhpc-kayobe-config

Length of output: 12702


🌐 Web query:

CVE-2026-59873 node-tar package affected versions fixed version

💡 Result:

CVE-2026-59873 is a critical Denial of Service (DoS) vulnerability affecting the node-tar package [1][2]. Affected versions: All versions up to and including 7.5.18 [1][2]. Fixed version: 7.5.19 [1][3][2]. The vulnerability arises because the library fails to enforce hard upper bounds on total decompressed data, entry counts, or decompression ratios [3][4]. This allows an attacker to use a maliciously crafted "Gzip Bomb" to exhaust server resources, such as disk space and CPU, leading to potential service outages [1][2]. Users are advised to upgrade to version 7.5.19 or higher to mitigate this risk [1][3].

Citations:


🌐 Web query:

GHSA-r277-6w6q-xmqw getkin/kine-openapi affected versions fixed version

💡 Result:

The security advisory GHSA-r277-6w6q-xmqw identifies a critical "fail-open" authentication bypass vulnerability in the getkin/kin-openapi Go library [1][2]. Affected versions: All versions before 0.144.0 [3]. Fixed version: 0.144.0 [3]. The vulnerability exists in the ValidationHandler.Load function, which incorrectly replaced a nil AuthenticationFunc with NoopAuthenticationFunc by default [1][4]. Because NoopAuthenticationFunc always returns nil, this caused OpenAPI security requirements (such as API keys or OAuth tokens) to be silently bypassed for unauthenticated requests [1][5]. The fix in version 0.144.0 ensures that a nil AuthenticationFunc is not automatically replaced with the no-op version, causing such requests to correctly return an error instead of passing validation [5]. Users who intentionally require no-op authentication must now explicitly set h.AuthenticationFunc = openapi3filter.NoopAuthenticationFunc [5].

Citations:


🌐 Web query:

GitHub advisories GHSA-r277-6w6q-xmqw grafana affected packages node-tar GitHub advisories

💡 Result:

The GitHub advisory GHSA-r277-6w6q-xmqw identifies a critical-severity authentication bypass vulnerability in the Go package getkin/kin-openapi [1][2]. It is not directly related to node-tar; rather, it pertains to the ValidationHandler.Load method in kin-openapi, which incorrectly defaults to a NoopAuthenticationFunc when a nil AuthenticationFunc is provided, effectively disabling security checks for API requests [1]. While your query associated this advisory with Grafana and node-tar, the connection is as follows: - Grafana: The getkin/kin-openapi package is a dependency used within Grafana [3]. Consequently, Grafana instances may be affected by this vulnerability through that dependency [3]. - node-tar: There is no direct link between GHSA-r277-6w6q-xmqw and node-tar. The node-tar library has its own distinct set of security advisories (e.g., GHSA-8qq5-rm4j-mr97, GHSA-83g3-92jg-28cx, and GHSA-9ppj-qmqm-q256) regarding file system traversal and arbitrary file write vulnerabilities [4][5][6]. Users should review their dependencies to ensure they are using patched versions of getkin/kin-openapi and, separately, ensure node-tar is updated to a secure version to address its specific, unrelated vulnerabilities [4][5][6].

Citations:


🌐 Web query:

GitHub advisories CVE-2026-59873 node-tar GitHub advisories

💡 Result:

CVE-2026-59873 is a critical security vulnerability in the node-tar library (npm package tar) that involves a Denial of Service (DoS) condition caused by unlimited input processing [1][2][3]. Key details of the advisory: - Vulnerability Type: Decompression/parse DoS via unlimited input [1][2]. - Description: The node-tar library does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratios during archive extraction [1][4]. An attacker can exploit this by providing a maliciously crafted archive—often referred to as a "Gzip Bomb"—that causes the library to consume excessive disk space and CPU resources until the host service crashes or exhausts system storage [1][2][3]. - Impact: This vulnerability affects any application or service that uses node-tar to extract archives provided by untrusted sources, such as CI/CD pipelines, file-sharing platforms, or package registries [1][5]. - Affected Versions: All versions <= 7.5.18 [1][2]. - Patched Version: 7.5.19 [1][4]. - GitHub Advisory ID: GHSA-23hp-3jrh-7fpw [1][3]. - Severity: Critical (CVSS 4.0 base score 9.2) [1][6]. Users are advised to upgrade to version 7.5.19 or later to mitigate this risk [4][6].

Citations:


🌐 Web query:

OSV GHSA-r277-6w6q-xmqw packages grafana kin-openapi

💡 Result:

GHSA-r277-6w6q-xmqw is a critical severity (CVSS 9.1) authentication bypass vulnerability in the Go package getkin/kin-openapi [1][2]. The vulnerability occurs in the ValidationHandler.Load method, which incorrectly defaults to a NoopAuthenticationFunc when a nil AuthenticationFunc is provided [1][2]. Because the no-op function always returns nil (indicating success), any OpenAPI security requirements (such as API keys or OAuth tokens) in the specification are silently ignored [1][2]. This creates a fail-open condition where unauthenticated requests are permitted to access protected handlers [1][3][2]. This vulnerability impacts any application using kin-openapi's ValidationHandler as enforcement middleware if they rely on the default (nil) authentication configuration [1][2]. Because of the popularity and widespread use of the library, many projects, including various components within the Grafana ecosystem (such as grafana-plugin-sdk-go and others), have been identified as potentially affected or requiring dependency updates [4]. Users should update to a non-vulnerable version of getkin/kin-openapi where the issue is remediated. For instance, specific security advisories have tracked remediation across affected packages, including updates within Grafana-related distributions [5]. [1][2]

Citations:


🌐 Web query:

OSV CVE-2026-59873 packages node-tar

💡 Result:

CVE-2026-59873 is a critical Denial of Service (DoS) vulnerability in the node-tar library for Node.js [1][2][3]. The vulnerability arises because the library fails to enforce hard upper bounds on total decompressed data, entry counts, or decompression ratios during archive extraction and parsing [2][4][3]. An attacker can exploit this flaw by providing a maliciously crafted archive—specifically a "Gzip Bomb"—that causes the system to exhaust disk space and CPU resources [1][3]. This can lead to system-wide failures and service outages for any application using node-tar to extract archives from untrusted sources [1][3]. Key details regarding the vulnerability include: - Affected Versions: All versions of node-tar <= 7.5.18 [1][3]. - Patched Version: The vulnerability is fixed in version 7.5.19 [1][2][4]. - Severity: Rated as Critical with a CVSS 4.0 base score of 9.2 [2][3][5]. - Weakness: Classified as CWE-770 (Allocation of Resources Without Limits or Throttling) [3]. Users are strongly advised to update to node-tar version 7.5.19 or later to mitigate this risk [1][2][3].

Citations:


🌐 Web query:

GitHub CVE-2026-59873 OpenSearch Dashboards node-tar

💡 Result:

CVE-2026-59873 is a critical Denial of Service (DoS) vulnerability in the node-tar library (npm package 'tar') [1][2]. It is not a vulnerability specific to OpenSearch Dashboards, though OpenSearch Dashboards may be affected if it uses a vulnerable version of node-tar [1][3]. Vulnerability Details: The vulnerability arises because node-tar (versions 7.5.18 and below) fails to enforce hard upper bounds on total decompressed data, entry counts, or decompression ratios during extraction [1][2]. An attacker can provide a maliciously crafted "Gzip Bomb"—a small, compressed archive that expands into a massive amount of data—to cause resource exhaustion (disk space and CPU) on the server [1][2]. This can lead to system-wide failure or service outages [1][2]. Resolution: The issue was addressed and fixed in node-tar version 7.5.19 [1][4]. Users should upgrade to this version or higher to mitigate the risk [1][2]. Context regarding OpenSearch Dashboards: While OpenSearch Dashboards has experienced past security advisories related to its dependencies—including other issues in the node-tar library (e.g., CVE-2026-31802 and CVE-2026-26960)—CVE-2026-59873 is a separate, more recent issue affecting the upstream node-tar library itself [1][3][5]. Users of OpenSearch Dashboards should audit their environment for the vulnerable node-tar dependency and apply the necessary updates provided by the project maintainers if and when they issue a patch for the affected component [1][2].

Citations:


Confirm the dependency mapping before suppressing these critical advisories.

GHSA-r277-6w6q-xmqw affects getkin/kin-openapi before 0.144.0, and CVE-2026-59873 affects node-tar <= 7.5.18. Add evidence that the deployed Grafana and OpenSearch Dashboards images include the vulnerable dependency versions, and add an owner plus an expiry or removal condition tied to the fixed package release or RPM build.

Source: MCP tools

letsencrypt_lego_allowed_vulnerabilities:
- CVE-2025-68121
- CVE-2026-33186

opensearch_dashboards_allowed_vulnerabilities:
- CVE-2026-59873

prometheus_alertmanager_allowed_vulnerabilities:
- CVE-2026-33186

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
features:
- |
The Squid proxy container has been switched from a StackHPC-maintained
custom image, to a public image maintained by Canonical. The version of
Squid is bumped from 6.10 to 7.2. The old image was based on Rocky Linux 10,
and the new one is based on Ubuntu 26.04.
Loading