chore(findings): elastic/kibana/kibana
Summary
elastic/kibana/kibana has 49 new findings discovered during continuous monitoring.
More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=elastic/kibana/kibana&tag=8.19.13&branch=master
EPSS (Exploit Prediction Scoring System) provides an estimate of the likelihood that a vulnerability will be exploited in the wild.
KEV (Known Exploited Vulnerabilities) indicates whether a vulnerability is actively being exploited according to CISA.
| id | source | severity | package | impact | workaround | epss_score | kev |
|---|---|---|---|---|---|---|---|
| CVE-2026-35213 | Twistlock CVE | High | @hapi/content-6.0.0 | 0.00359 | false | ||
| CVE-2026-33937 | Twistlock CVE | Low | handlebars-4.7.8 | 0.00155 | false | ||
| CVE-2026-33532 | Twistlock CVE | Low | yaml-1.10.2 | 0.00053 | false | ||
| CVE-2026-33532 | Twistlock CVE | Low | yaml-2.8.1 | 0.00053 | false | ||
| CVE-2026-33532 | Twistlock CVE | Low | yaml-2.3.4 | 0.00053 | false | ||
| CVE-2026-40190 | Twistlock CVE | Medium | langsmith-0.3.87 | 0.00052 | false | ||
| CVE-2026-33672 | Twistlock CVE | Low | picomatch-2.3.1 | 0.00052 | false | ||
| CVE-2026-41242 | Twistlock CVE | Critical | protobufjs-7.5.4 | 0.00050 | false | ||
| CVE-2026-41242 | Twistlock CVE | Critical | protobufjs-8.0.0 | 0.00050 | false | ||
| CVE-2026-27795 | Twistlock CVE | Medium | @langchain/community-0.3.45 | 0.00042 | false | ||
| CVE-2026-21717 | Anchore CVE | Medium | node-22.22.0 | 0.00035 | false | ||
| CVE-2026-21713 | Anchore CVE | Medium | node-22.22.0 | 0.00027 | false | ||
| CVE-2026-33671 | Twistlock CVE | Low | picomatch-2.3.1 | 0.00018 | false | ||
| CVE-2026-34757 | Anchore CVE | Medium | libpng-2:1.6.37-12.el9_7.2 | 0.00016 | false | ||
| CVE-2026-34757 | Twistlock CVE | Medium | libpng-2:1.6.37-12.el9_7.2 | 0.00016 | false | ||
| CVE-2026-21714 | Anchore CVE | Medium | node-22.22.0 | 0.00016 | false | ||
| CVE-2026-3449 | Twistlock CVE | Low | @tootallnate/once-2.0.0 | 0.00015 | false | ||
| CVE-2026-25528 | Twistlock CVE | Medium | langsmith-0.3.87 | 0.00014 | false | ||
| CVE-2026-26019 | Twistlock CVE | Medium | @langchain/community-0.3.45 | 0.00013 | false | ||
| CVE-2026-21716 | Anchore CVE | Low | node-22.22.0 | 0.00004 | false | ||
| GHSA-xq3m-2v4x-88gg | Anchore CVE | Critical | protobufjs-7.5.4 | N/A | N/A | ||
| GHSA-xq3m-2v4x-88gg | Anchore CVE | Critical | protobufjs-8.0.0 | N/A | N/A | ||
| GHSA-vvjj-xcjg-gr5g | Twistlock CVE | Medium | nodemailer-7.0.11 | N/A | N/A | ||
| GHSA-vvjj-xcjg-gr5g | Anchore CVE | Medium | nodemailer-7.0.11 | N/A | N/A | ||
| GHSA-vpq2-c234-7xj6 | Anchore CVE | Low | @tootallnate/once-2.0.0 | N/A | N/A | ||
| GHSA-v34v-rq6j-cj6p | Anchore CVE | Medium | langsmith-0.3.87 | N/A | N/A | ||
| GHSA-rr7j-v2q5-chgv | Twistlock CVE | Medium | langsmith-0.3.87 | N/A | N/A | ||
| GHSA-rr7j-v2q5-chgv | Anchore CVE | Medium | langsmith-0.3.87 | N/A | N/A | ||
| GHSA-rp42-5vxx-qpwr | Twistlock CVE | High | basic-ftp-5.2.0 | N/A | N/A | ||
| GHSA-r5fr-rjxr-66jc | Anchore CVE | High | lodash-4.17.23 | N/A | N/A | ||
| GHSA-r4q5-vmmm-2653 | Twistlock CVE | Medium | follow-redirects-1.15.11 | N/A | N/A | ||
| GHSA-r4q5-vmmm-2653 | Anchore CVE | Medium | follow-redirects-1.15.11 | N/A | N/A | ||
| GHSA-mphv-75cg-56wg | Anchore CVE | Medium | @langchain/community-0.3.45 | N/A | N/A | ||
| GHSA-jg4p-7fhp-p32p | Anchore CVE | High | @hapi/content-6.0.0 | N/A | N/A | ||
| GHSA-gf3v-fwqg-4vh7 | Anchore CVE | Medium | @langchain/community-0.3.45 | N/A | N/A | ||
| GHSA-fw9q-39r9-c252 | Anchore CVE | Medium | langsmith-0.3.87 | N/A | N/A | ||
| GHSA-f23m-r3pf-42rh | Anchore CVE | Medium | lodash-4.17.23 | N/A | N/A | ||
| GHSA-c7w3-x93f-qmm8 | Anchore CVE | Low | nodemailer-7.0.11 | N/A | N/A | ||
| GHSA-c7w3-x93f-qmm8 | Twistlock CVE | Low | nodemailer-7.0.11 | N/A | N/A | ||
| GHSA-c2c7-rcm5-vvqj | Anchore CVE | High | picomatch-2.3.1 | N/A | N/A | ||
| GHSA-48c2-rrv3-qjmp | Anchore CVE | Medium | yaml-2.8.1 | N/A | N/A | ||
| GHSA-48c2-rrv3-qjmp | Anchore CVE | Medium | yaml-2.3.4 | N/A | N/A | ||
| GHSA-48c2-rrv3-qjmp | Anchore CVE | Medium | yaml-2.3.4 | N/A | N/A | ||
| GHSA-48c2-rrv3-qjmp | Anchore CVE | Medium | yaml-2.3.4 | N/A | N/A | ||
| GHSA-48c2-rrv3-qjmp | Anchore CVE | Medium | yaml-1.10.2 | N/A | N/A | ||
| GHSA-3v7f-55p6-f55p | Anchore CVE | Medium | picomatch-2.3.1 | N/A | N/A | ||
| GHSA-39q2-94rc-95cp | Twistlock CVE | Medium | dompurify-3.3.2 | N/A | N/A | ||
| GHSA-39q2-94rc-95cp | Anchore CVE | Medium | dompurify-3.3.2 | N/A | N/A | ||
| GHSA-2w6w-674q-4c4q | Anchore CVE | Critical | handlebars-4.7.8 | N/A | N/A |
More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=elastic/kibana/kibana&tag=8.19.13&branch=master
Tasks
Contributor:
-
Apply the StatusReview label to this issue for a
merge request reviewand wait for feedback
OR
- Provide justifications for findings in the VAT (docs)
-
Apply the StatusVerification label to this issue for a
VAT justifications reviewand wait for feedback
Iron Bank:
- Review findings and justifications
Note: If the above process is rejected for any reason, the
RevieworVerificationlabel will be removed and the issue will be sent back toTo-Do. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add theRevieworVerificationlabel.
Questions?
Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.
Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.