UNCLASSIFIED - NO CUI

chore(findings): elastic/kibana/kibana

Summary

elastic/kibana/kibana has 49 new findings discovered during continuous monitoring.

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=elastic/kibana/kibana&tag=8.19.13&branch=master

EPSS (Exploit Prediction Scoring System) provides an estimate of the likelihood that a vulnerability will be exploited in the wild.

KEV (Known Exploited Vulnerabilities) indicates whether a vulnerability is actively being exploited according to CISA.

id source severity package impact workaround epss_score kev
CVE-2026-35213 Twistlock CVE High @hapi/content-6.0.0 0.00359 false
CVE-2026-33937 Twistlock CVE Low handlebars-4.7.8 0.00155 false
CVE-2026-33532 Twistlock CVE Low yaml-1.10.2 0.00053 false
CVE-2026-33532 Twistlock CVE Low yaml-2.8.1 0.00053 false
CVE-2026-33532 Twistlock CVE Low yaml-2.3.4 0.00053 false
CVE-2026-40190 Twistlock CVE Medium langsmith-0.3.87 0.00052 false
CVE-2026-33672 Twistlock CVE Low picomatch-2.3.1 0.00052 false
CVE-2026-41242 Twistlock CVE Critical protobufjs-7.5.4 0.00050 false
CVE-2026-41242 Twistlock CVE Critical protobufjs-8.0.0 0.00050 false
CVE-2026-27795 Twistlock CVE Medium @langchain/community-0.3.45 0.00042 false
CVE-2026-21717 Anchore CVE Medium node-22.22.0 0.00035 false
CVE-2026-21713 Anchore CVE Medium node-22.22.0 0.00027 false
CVE-2026-33671 Twistlock CVE Low picomatch-2.3.1 0.00018 false
CVE-2026-34757 Anchore CVE Medium libpng-2:1.6.37-12.el9_7.2 0.00016 false
CVE-2026-34757 Twistlock CVE Medium libpng-2:1.6.37-12.el9_7.2 0.00016 false
CVE-2026-21714 Anchore CVE Medium node-22.22.0 0.00016 false
CVE-2026-3449 Twistlock CVE Low @tootallnate/once-2.0.0 0.00015 false
CVE-2026-25528 Twistlock CVE Medium langsmith-0.3.87 0.00014 false
CVE-2026-26019 Twistlock CVE Medium @langchain/community-0.3.45 0.00013 false
CVE-2026-21716 Anchore CVE Low node-22.22.0 0.00004 false
GHSA-xq3m-2v4x-88gg Anchore CVE Critical protobufjs-7.5.4 N/A N/A
GHSA-xq3m-2v4x-88gg Anchore CVE Critical protobufjs-8.0.0 N/A N/A
GHSA-vvjj-xcjg-gr5g Twistlock CVE Medium nodemailer-7.0.11 N/A N/A
GHSA-vvjj-xcjg-gr5g Anchore CVE Medium nodemailer-7.0.11 N/A N/A
GHSA-vpq2-c234-7xj6 Anchore CVE Low @tootallnate/once-2.0.0 N/A N/A
GHSA-v34v-rq6j-cj6p Anchore CVE Medium langsmith-0.3.87 N/A N/A
GHSA-rr7j-v2q5-chgv Twistlock CVE Medium langsmith-0.3.87 N/A N/A
GHSA-rr7j-v2q5-chgv Anchore CVE Medium langsmith-0.3.87 N/A N/A
GHSA-rp42-5vxx-qpwr Twistlock CVE High basic-ftp-5.2.0 N/A N/A
GHSA-r5fr-rjxr-66jc Anchore CVE High lodash-4.17.23 N/A N/A
GHSA-r4q5-vmmm-2653 Twistlock CVE Medium follow-redirects-1.15.11 N/A N/A
GHSA-r4q5-vmmm-2653 Anchore CVE Medium follow-redirects-1.15.11 N/A N/A
GHSA-mphv-75cg-56wg Anchore CVE Medium @langchain/community-0.3.45 N/A N/A
GHSA-jg4p-7fhp-p32p Anchore CVE High @hapi/content-6.0.0 N/A N/A
GHSA-gf3v-fwqg-4vh7 Anchore CVE Medium @langchain/community-0.3.45 N/A N/A
GHSA-fw9q-39r9-c252 Anchore CVE Medium langsmith-0.3.87 N/A N/A
GHSA-f23m-r3pf-42rh Anchore CVE Medium lodash-4.17.23 N/A N/A
GHSA-c7w3-x93f-qmm8 Anchore CVE Low nodemailer-7.0.11 N/A N/A
GHSA-c7w3-x93f-qmm8 Twistlock CVE Low nodemailer-7.0.11 N/A N/A
GHSA-c2c7-rcm5-vvqj Anchore CVE High picomatch-2.3.1 N/A N/A
GHSA-48c2-rrv3-qjmp Anchore CVE Medium yaml-2.8.1 N/A N/A
GHSA-48c2-rrv3-qjmp Anchore CVE Medium yaml-2.3.4 N/A N/A
GHSA-48c2-rrv3-qjmp Anchore CVE Medium yaml-2.3.4 N/A N/A
GHSA-48c2-rrv3-qjmp Anchore CVE Medium yaml-2.3.4 N/A N/A
GHSA-48c2-rrv3-qjmp Anchore CVE Medium yaml-1.10.2 N/A N/A
GHSA-3v7f-55p6-f55p Anchore CVE Medium picomatch-2.3.1 N/A N/A
GHSA-39q2-94rc-95cp Twistlock CVE Medium dompurify-3.3.2 N/A N/A
GHSA-39q2-94rc-95cp Anchore CVE Medium dompurify-3.3.2 N/A N/A
GHSA-2w6w-674q-4c4q Anchore CVE Critical handlebars-4.7.8 N/A N/A

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=elastic/kibana/kibana&tag=8.19.13&branch=master

Tasks

Contributor:

  • Apply the StatusReview label to this issue for a merge request review and wait for feedback

OR

  • Provide justifications for findings in the VAT (docs)
  • Apply the StatusVerification label to this issue for a VAT justifications review and wait for feedback

Iron Bank:

  • Review findings and justifications

Note: If the above process is rejected for any reason, the Review or Verification label will be removed and the issue will be sent back to To-Do. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Review or Verification label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by CHORE_TOKEN