Repository navigation
🚨 Security: Critical or high vulnerabilities in ida-pro-mcp container #986
Description
Activity
github-actions commented
on Sep 21, 2026 on Sep 21, 2026 – with GitHub ActionsContributorAuthorMore actionsUpdated Scan Results
🚨 Security Scan Alert
A periodic security scan found fixable critical or high severity vulnerabilities in the container image. Findings at this level also block publishing in the build workflow.
- Image:
ghcr.io/stacklok/dockyard/uvx/ida-pro-mcp:1.4.0 - Critical vulnerabilities: 0
- High vulnerabilities: 1
Details
See the Security tab for full details.
High Vulnerabilities
- GHSA-8xx6-hgc6-gc2m in
httpx2@2.10.0: HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
Automated security scan from periodic-security-scan workflow
- Image:
github-actions commented
on Sep 28, 2026 on Sep 28, 2026 – with GitHub ActionsContributorAuthorMore actionsUpdated Scan Results
🚨 Security Scan Alert
A periodic security scan found fixable critical or high severity vulnerabilities in the container image. Findings at this level also block publishing in the build workflow.
- Image:
ghcr.io/stacklok/dockyard/uvx/ida-pro-mcp:1.4.0 - Critical vulnerabilities: 0
- High vulnerabilities: 1
Details
See the Security tab for full details.
High Vulnerabilities
- GHSA-8xx6-hgc6-gc2m in
httpx2@2.10.0: HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
Automated security scan from periodic-security-scan workflow
- Image:
github-actions commented
on Oct 5, 2026 on Oct 5, 2026 – with GitHub ActionsContributorAuthorMore actionsUpdated Scan Results
🚨 Security Scan Alert
A periodic security scan found fixable critical or high severity vulnerabilities in the container image. Findings at this level also block publishing in the build workflow.
- Image:
ghcr.io/stacklok/dockyard/uvx/ida-pro-mcp:1.4.0 - Critical vulnerabilities: 1
- High vulnerabilities: 6
Details
See the Security tab for full details.
Critical Vulnerabilities
- GHSA-ffc3-869f-jxw9 in
pyjwt@2.13.0: PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
High Vulnerabilities
- GHSA-8xx6-hgc6-gc2m in
httpx2@2.10.0: HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification) - GHSA-r6x4-923q-g947 in
pyjwt@2.13.0: PyJWT BOM Bypass - GHSA-w2cx-738m-mc7w in
pyjwt@2.13.0: PyJWT accepts public JWK containers as HMAC secrets - GHSA-9j54-fg26-wv3r in
pyjwt@2.13.0: PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation - GHSA-p4g4-x82p-q773 in
pyjwt@2.13.0: PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
... and 1 more. See Security tab for complete list.
Automated security scan from periodic-security-scan workflow
- Image:
🚨 Security Scan Alert
A periodic security scan found fixable critical or high severity vulnerabilities in the container image. Findings at this level also block publishing in the build workflow.
ghcr.io/stacklok/dockyard/uvx/ida-pro-mcp:1.4.0Details
See the Security tab for full details.
High Vulnerabilities
httpx2@2.10.0: HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)Automated security scan from periodic-security-scan workflow