CuraDevOps

tag: Cve · 2 items

2026-08-24 · Releases: grafana · source ↗ #grafana#cve#observability
  • Platform/SRE — Plan: Grafana is a common observability stack component; CVE-2026-17183 is not KEV-listed and carries EPSS 0.00, so no active exploitation signal, but schedule an upgrade to 13.1.4 this sprint as standard patch hygiene.
  • CI/CD — Skip
  • Leader — Skip
  • Signals: CVE-2026-17183 — CISA KEV: not listed, EPSS 0.00
2026-08-17 · Releases: moby · source ↗ #moby#container-security#cve
  • Platform/SRE — Plan: Three symlink/mount CVEs in the Docker engine (none KEV-listed, EPSS 0.00) warrant scheduling a patch to Moby 25.0.17 this sprint; also note that containerd 1.7 — vendored in this release — reaches EOL 2026-09-01, so any org running containerd 1.7 directly must plan a runtime upgrade within 15 days.
  • CI/CD — Skip
  • Leader — Skip
  • Signals: containerd 1.7 reaches EOL in 15d (2026-09-01) · major release (25.0) · CVE-2024-40635 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-41567 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-41568 — CISA KEV: not listed, EPSS 0.00