VEX44's approved disposition and actual internal-hub scanner consumption are independently verified.
Human merge c5d9faa preserved reviewed ff6655e; index-check35438359126 passed. Independent post-merge review downloaded the actual internal hub, matched the approved tree, and verified StringPrep consumption for the published Quay agent tag, index and both architecture digests. Grype consumes it as fixed; unpatched/source-only controls remain active. All six controlled Trivy tests pass, with native StringPrep detection still outside that claim. All32 other statements/dispositions are unchanged; Python CVE-2026-82049 remains active.
PR44 is removed from the human-review queue. Rancher migration/parity remains unverified and tracked through existing vexhub#34 / cve-reporter#29 and the established agent Python VEX audit plan. Current gh and fallback credentials cannot resolve rancher/image-scanning; this is a visibility limitation, not proof of absence. No duplicate migration issue or new scan wave. GO and Agent511 holds remain unchanged; this is not whole-image clearance or ticket closure.
Two reviewed not_affected statements for stackstate-k8s-agent no longer apply,
so the gating chart scan still reports findings they were written to cover.
Reproducing the gate exactly (image-pipeline passes --by-cve) against
quay.io/stackstate/stackstate-k8s-agent:ff38da51, digest
sha256:4ebe6280d7c28e07ab1447e1497fbe855ee1229e9ef38b3e9945145cb0367616:
grype --by-cve --vex pkg/oci/stackstate-k8s-agent/scan.openvex.json \
--vex pkg/golang/github.com/containerd/containerd/scan.openvex.json \
quay.io/stackstate/stackstate-k8s-agent:ff38da51
→ active 10, ignored 3
CVE-2025-15367 and CVE-2026-4360 are among the active findings despite both
carrying reviewed not_affected statements.
Cause: the subcomponent is pinned to a superseded interpreter
Those statements pin subcomponents to pkg:generic/python@3.13.13 (and
@3.13.14 on CVE-2025-15367). The image now reports
pkg:generic/python@3.13.15, and Grype requires the subcomponent to match, so the
statements no longer apply.
Isolated with a single-variable test under the same --by-cve invocation:
appending pkg:generic/python@3.13.15 to CVE-2025-15367's subcomponents and
changing nothing else moves it to ignoredMatches, while CVE-2026-4360 — left
pinned at 3.13.13 as a control — stays active.
The general hazard is that any routine patch bump of an embedded runtime silently
voids every statement written against the previous version, with no error anywhere.
What this needs
Extending these statements to 3.13.15 widens a reachability claim to an
interpreter revision nobody has reviewed, so it needs security review rather than a
mechanical bump. The reviewed premises are about the agent's own code paths (for
CVE-2026-4360, that the sole shipped tar-extraction path excludes hardlinks
before calling tarfile.extract()), so the question for review is whether those
premises still hold on the current default branch — not whether the interpreter
changed.
Four further Python findings on the image have no statement and no exception at
all: CVE-2026-15806, CVE-2026-17084, CVE-2026-19672 and CVE-2026-15310.
None has an upstream fix. Together with the two above, these six are what the chart
gate will still report on the agent once the chart picks up the merged OpenSSL fix.
The interim deferral for CVE-2025-15367 and CVE-2026-4360 lives in the agent
repo with a 2026-09-04 review date, and StackVista/stackstate-agent#501 makes
that date fail closed. Note that a repo-local exception does not affect the
chart gate — the chart scan does not read consumer exception trees — so VEX is the
only artifact that can clear these from the gate.
Correction to the original report
This issue previously claimed that all 23 agent statements were inert, that the
containerd statements were missing the GO- advisory IDs Grype reports, and that
OSV contradicted their rationale. All three were wrong:
- The containerd statements do apply.
image-pipeline runs Grype with
--by-cve, which maps GO- IDs onto their CVE aliases, so the CVE-named
statements match. CVE-2026-50195, CVE-2026-53489 and CVE-2026-53492 are the
three suppressed findings in the run above. The original "0 ignored" measurement
came from omitting --by-cve, which is not how the pipeline runs.
- Their rationale is supported. The upstream advisory
(GHSA-33vj-92qq-66hc and siblings) lists only
github.com/containerd/containerd/v2 in the 2.1, 2.2 and 2.3 lines, with no v1
range — matching the statements, which assert the agent's v1.7.33 is out of
scope. The contradicting v1 entry appears only in the Go vulnerability database,
whose record is marked review_status: UNREVIEWED and carries introduced: 0
with no fixed version and empty ecosystem_specific — the signature of an
uncurated import rather than a curated finding.
- No alias change is needed for our gates. Adding the
GO- IDs to
vulnerability.aliases would still be worthwhile for consumers that do not pass
--by-cve, but it is hygiene, not a fix.
CONTRIBUTING.md guidance has been corrected accordingly in
#35, which also handles all four krb5 findings on this image.
Related coordination ticket: https://github.com/StackVista/cve-reporter/issues/29
VEX44's approved disposition and actual internal-hub scanner consumption are independently verified.
Human merge c5d9faa preserved reviewed ff6655e; index-check35438359126 passed. Independent post-merge review downloaded the actual internal hub, matched the approved tree, and verified StringPrep consumption for the published Quay agent tag, index and both architecture digests. Grype consumes it as fixed; unpatched/source-only controls remain active. All six controlled Trivy tests pass, with native StringPrep detection still outside that claim. All32 other statements/dispositions are unchanged; Python CVE-2026-82049 remains active.
PR44 is removed from the human-review queue. Rancher migration/parity remains unverified and tracked through existing vexhub#34 / cve-reporter#29 and the established agent Python VEX audit plan. Current gh and fallback credentials cannot resolve rancher/image-scanning; this is a visibility limitation, not proof of absence. No duplicate migration issue or new scan wave. GO and Agent511 holds remain unchanged; this is not whole-image clearance or ticket closure.
Two reviewed
not_affectedstatements forstackstate-k8s-agentno longer apply,so the gating chart scan still reports findings they were written to cover.
Reproducing the gate exactly (
image-pipelinepasses--by-cve) againstquay.io/stackstate/stackstate-k8s-agent:ff38da51, digestsha256:4ebe6280d7c28e07ab1447e1497fbe855ee1229e9ef38b3e9945145cb0367616:CVE-2025-15367andCVE-2026-4360are among the active findings despite bothcarrying reviewed
not_affectedstatements.Cause: the subcomponent is pinned to a superseded interpreter
Those statements pin
subcomponentstopkg:generic/python@3.13.13(and@3.13.14onCVE-2025-15367). The image now reportspkg:generic/python@3.13.15, and Grype requires the subcomponent to match, so thestatements no longer apply.
Isolated with a single-variable test under the same
--by-cveinvocation:appending
pkg:generic/python@3.13.15toCVE-2025-15367's subcomponents andchanging nothing else moves it to
ignoredMatches, whileCVE-2026-4360— leftpinned at
3.13.13as a control — stays active.The general hazard is that any routine patch bump of an embedded runtime silently
voids every statement written against the previous version, with no error anywhere.
What this needs
Extending these statements to
3.13.15widens a reachability claim to aninterpreter revision nobody has reviewed, so it needs security review rather than a
mechanical bump. The reviewed premises are about the agent's own code paths (for
CVE-2026-4360, that the sole shipped tar-extraction path excludes hardlinksbefore calling
tarfile.extract()), so the question for review is whether thosepremises still hold on the current default branch — not whether the interpreter
changed.
Four further Python findings on the image have no statement and no exception at
all:
CVE-2026-15806,CVE-2026-17084,CVE-2026-19672andCVE-2026-15310.None has an upstream fix. Together with the two above, these six are what the chart
gate will still report on the agent once the chart picks up the merged OpenSSL fix.
The interim deferral for
CVE-2025-15367andCVE-2026-4360lives in the agentrepo with a
2026-09-04review date, and StackVista/stackstate-agent#501 makesthat date fail closed. Note that a repo-local exception does not affect the
chart gate — the chart scan does not read consumer exception trees — so VEX is the
only artifact that can clear these from the gate.
Correction to the original report
This issue previously claimed that all 23 agent statements were inert, that the
containerd statements were missing the
GO-advisory IDs Grype reports, and thatOSV contradicted their rationale. All three were wrong:
image-pipelineruns Grype with--by-cve, which mapsGO-IDs onto their CVE aliases, so the CVE-namedstatements match.
CVE-2026-50195,CVE-2026-53489andCVE-2026-53492are thethree suppressed findings in the run above. The original "0 ignored" measurement
came from omitting
--by-cve, which is not how the pipeline runs.(
GHSA-33vj-92qq-66hcand siblings) lists onlygithub.com/containerd/containerd/v2in the 2.1, 2.2 and 2.3 lines, with no v1range — matching the statements, which assert the agent's v1.7.33 is out of
scope. The contradicting v1 entry appears only in the Go vulnerability database,
whose record is marked
review_status: UNREVIEWEDand carriesintroduced: 0with no fixed version and empty
ecosystem_specific— the signature of anuncurated import rather than a curated finding.
GO-IDs tovulnerability.aliaseswould still be worthwhile for consumers that do not pass--by-cve, but it is hygiene, not a fix.CONTRIBUTING.mdguidance has been corrected accordingly in#35, which also handles all four krb5 findings on this image.
Related coordination ticket: https://github.com/StackVista/cve-reporter/issues/29