-
Notifications
You must be signed in to change notification settings - Fork 722
Expand file tree
/
Copy path.govulncheck.yaml
More file actions
84 lines (77 loc) · 4.13 KB
/
Copy path.govulncheck.yaml
File metadata and controls
84 lines (77 loc) · 4.13 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
# Ignore list for the govulncheck CI job.
#
# Every entry needs a `reason` so the rationale lives in git history.
# The optional `expires` field forces periodic re-evaluation: once that
# date passes, CI starts failing on the entry again until it's renewed
# or removed. See tools/govulncheck/ for the wrapper that consumes this.
ignore:
- id: GO-2026-4887
reason: |
Moby AuthZ plugin bypass (CVE-2026-34040). The legacy
github.com/docker/docker module now enters the build through
prometheus.exporter.mongodb (github.com/percona/percona-backup-mongodb
imports github.com/docker/docker/api/types), not cadvisor. The
vulnerability is server-side (a Docker daemon handling API requests
through an AuthZ plugin) — Alloy never runs as a Docker daemon. The fix
exists only in github.com/moby/moby/v2; the legacy github.com/docker/docker
path will never be patched. Revisit once percona-backup-mongodb drops
legacy github.com/docker/docker.
expires: 2027-01-01
- id: GO-2026-4883
reason: |
Moby off-by-one in plugin privilege validation (CVE-2026-33997).
Vulnerable code path is `docker plugin install` on a Docker daemon
— Alloy never processes plugin installs. Same upstream-fix story
as GO-2026-4887 (only fixed in github.com/moby/moby/v2).
expires: 2027-01-01
- id: GO-2026-5746
reason: |
Docker PUT /containers/{id}/archive runs a container binary on the
host (CVE-2026-41567, RCE). Daemon-side handler. github.com/docker/docker
now enters the build only through prometheus.exporter.mongodb
(github.com/percona/percona-backup-mongodb imports
github.com/docker/docker/api/types); Alloy never runs dockerd or serves
that handler, so it is unreachable. No fix in github.com/docker/docker
(only github.com/moby/moby/v2). Revisit once percona-backup-mongodb drops
legacy github.com/docker/docker.
expires: 2027-01-01
- id: GO-2026-5668
reason: |
Race in docker cp lets a container create arbitrary empty host files
via symlink swap (CVE-2026-41568). Daemon-side docker cp path. The only
importer of github.com/docker/docker is now prometheus.exporter.mongodb
(via github.com/percona/percona-backup-mongodb); Alloy never runs dockerd
or docker cp. No fix in github.com/docker/docker (only
github.com/moby/moby/v2). Revisit once percona-backup-mongodb drops legacy
github.com/docker/docker.
expires: 2027-01-01
- id: GO-2026-5617
reason: |
Race in docker cp redirects a bind mount to an arbitrary host path
(CVE-2026-42306). Daemon-side docker cp path, unreachable: Alloy pulls
github.com/docker/docker only through prometheus.exporter.mongodb (via
github.com/percona/percona-backup-mongodb) and never runs dockerd or
docker cp. No fix in github.com/docker/docker (only
github.com/moby/moby/v2). Revisit once percona-backup-mongodb drops legacy
github.com/docker/docker.
expires: 2027-01-01
- id: GO-2026-5662
reason: |
Stored XSS via metric names and label values in the Prometheus web UI
tooltips and metrics explorer (CVE-2026-40179). Alloy embeds Prometheus
as a library for scrape/TSDB/remote-write and never serves that web UI,
so the vulnerable rendering path is unreachable. govulncheck flags it
only because the advisory has no symbol-level data and matches generic
tsdb/remote-write symbols Alloy does call. No fix on the prometheus
v3.12 line; revisit when a v3.12.x backport lands or we move to v3.13.
expires: 2027-01-01
- id: GO-2026-5115
reason: |
Loki path traversal, a CVE-2021-36156 bypass (CVE-2026-21726), fixed
upstream in v3.6.4. github.com/grafana/loki/v3 is pinned to a commit
on Loki's #k324 branch that is chronologically after the fix and does
contain it, but the pin's pseudo-version base (v3.0.0) still sorts
below v3.6.4 under normal semver comparison, so govulncheck flags it
as a false positive. Revisit once Loki cuts a release with the new
dskit NewProvider signature and the pin can move to a real tag.
expires: 2027-01-01