Skip to content

Rebuild Request: python:3.10-alpine — CVE-2026-23949 & CVE-2026-24049 (HIGH/CRITICAL) #1112

@tpickle-py

Description

@tpickle-py

Rebuild Request: python:3.10-alpineCVE-2026-23949 & CVE-2026-24049 (HIGH/CRITICAL)

Summary

The current python:3.10-alpine image ships with outdated versions of jaraco.context and wheel that contain known, fixed vulnerabilities. A rebuild is needed to pick up the patched versions.

Both CVEs have fixed versions available and this should be resolved by a simple image rebuild.


Affected Image

python:3.10-alpine


Vulnerabilities

Library CVE Severity Installed Version Fixed Version Description
jaraco.context CVE-2026-23949 HIGH 5.3.0 6.1.0 Path traversal via malicious tar archives
wheel CVE-2026-24049 HIGH 0.45.1 0.46.2 Privilege escalation or arbitrary code execution via malicious wheel file

References:


Impact

These vulnerabilities are being flagged as Critical by JFrog Xray, blocking our CI/CD pipeline builds. The fixes are already available upstream — this requires only an image rebuild to pull in the updated package versions.


Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions