Skip to content

UID2-8033: preventive bump pcre2 in nginx:alpine images (CVE-2026-103111) - #230

Closed
swibi-ttd wants to merge 1 commit into
mainfrom
swi-UID2-8033-pcre2-alpine
Closed

swibi-ttd wants to merge 1 commit into
mainfrom
swi-UID2-8033-pcre2-alpine

Conversation

@swibi-ttd

Copy link
Copy Markdown
Contributor

Upgrades pcre2 10.48 → 10.49 in the six nginx:alpine images (apk add --no-cache --upgrade), since the latest nginx:alpine still ships 10.48.

  • CVE-2026-103111 (HIGH, pcre2): Required attack preconditions are absent in this configuration.

The assessment is recorded on the ticket in the title.

🤖 Generated with Claude Code

)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@swibi-ttd

Copy link
Copy Markdown
Contributor Author

Replaced by a .trivyignore suppression: the apk upgrade was not a simple pin bump.

@swibi-ttd swibi-ttd closed this Oct 6, 2026
@swibi-ttd
swibi-ttd deleted the swi-UID2-8033-pcre2-alpine branch October 6, 2026 04:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant