Skip to content

Bump tunnel server APT_CACHE_BUST to clear libpcre2 CVE-2026-103111 - #156

Merged
ashiramin merged 1 commit into
mainfrom
fix/tunnel-server-pcre2-cve
Oct 5, 2026
Merged

ashiramin merged 1 commit into
mainfrom
fix/tunnel-server-pcre2-cve

Conversation

@ashiramin

Copy link
Copy Markdown
Contributor

The nightly Tunnel server image / Scan image check fails on main (run) with CVE-2026-103111 in libpcre2-8-0.

The runtime stage's cached apt layer (APT_CACHE_BUST=2026-09-14) predates the fix. This bumps it to 2026-10-05 so a fresh layer pulls 10.42-1+deb12u2 from bookworm-security. It's the same remedy #152 used for the agent image.

Verified locally: I built server/docker/Dockerfile. The image has libpcre2-8-0 10.42-1+deb12u2, and trivy image --severity HIGH,CRITICAL --ignore-unfixed reports 0 findings for both the OS packages and the Go binary.

🤖 Generated with Claude Code

https://claude.ai/code/session_01R1qAeP7ucrGLTfEakhxQT6

The nightly Trivy scan of cortex-axon-tunnel-server:main flags
CVE-2026-103111 in libpcre2-8-0. The cached apt layer (busted 2026-09-14)
predates the fix; a fresh layer pulls 10.42-1+deb12u2 from
bookworm-security. A local build scans clean for fixable HIGH/CRITICAL.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01R1qAeP7ucrGLTfEakhxQT6
@ashiramin
ashiramin merged commit 9214326 into main Oct 5, 2026
23 checks passed
@ashiramin
ashiramin deleted the fix/tunnel-server-pcre2-cve branch October 5, 2026 15:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants