Skip to content

docs: [#429] document deployer scan pass-2 - CRITICAL pending OpenTofu upstream#458

Merged
josecelano merged 1 commit intomainfrom
429-deployer-cves
Apr 15, 2026
Merged

docs: [#429] document deployer scan pass-2 - CRITICAL pending OpenTofu upstream#458
josecelano merged 1 commit intomainfrom
429-deployer-cves

Conversation

@josecelano
Copy link
Copy Markdown
Member

Summary

Documents Remediation Pass 2 for the torrust/tracker-deployer Docker image CVE scan (issue #429).

Changes

  • docs/security/docker/scans/torrust-tracker-deployer.md — added Pass 2 scan entry (Apr 15, 2026) with full CVE tables and decision rationale
  • docs/security/docker/scans/README.md — updated deployer row: 46 HIGH / 1 CRITICAL, Apr 15, 2026
  • docs/issues/429-deployer-cves.md — checked off completed steps; filled Outcome
  • project-words.txt — added cpython, kenv, libexpat

Scan results (Pass 2 — Apr 15, 2026)

Image rebuilt --no-cache with OpenTofu v1.11.6 (latest).

Target HIGH CRITICAL
Debian OS (trixie 13.4) 42 0
usr/bin/tofu 4 1
Total 46 1

Decision

Issue #429 remains open.

The CRITICAL CVE-2026-33186 (gRPC-Go authorization bypass via HTTP/2 path validation) is
present in google.golang.org/grpc v1.76.0 embedded in usr/bin/tofu. The fix requires
grpc-go ≥ 1.79.3; OpenTofu v1.11.6 has not yet updated this dependency.

All Debian OS HIGH CVEs are affected/will_not_fix/<no-dsa> with no trixie
backports available — accepted risk (same status as backup/Caddy OS layers).

Revisit: when OpenTofu ships v1.11.7+ or v1.12.x with upgraded grpc-go.

Related to #429

…u upstream

Rebuilt torrust/tracker-deployer:local with --no-cache (OpenTofu v1.11.6).
Trivy v0.69.3 scan: 46 HIGH / 1 CRITICAL (was 44H/1C in pass-1).

CRITICAL CVE-2026-33186 (grpc-go gRPC auth bypass) remains in usr/bin/tofu.
Fix requires OpenTofu to upgrade google.golang.org/grpc to v1.79.3+.

All Debian OS HIGH CVEs are affected/will_not_fix with no trixie backport.

Leave #429 open. Revisit when OpenTofu ships grpc-go >= 1.79.3.
@josecelano
Copy link
Copy Markdown
Member Author

ACK f466dfb

@josecelano josecelano merged commit c80af74 into main Apr 15, 2026
29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant