<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cve on CuraDevOps</title><link>https://curadevops.metacog.co.kr/tags/cve/</link><description>Recent content in Cve on CuraDevOps</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 24 Aug 2026 12:43:44 +0000</lastBuildDate><atom:link href="https://curadevops.metacog.co.kr/tags/cve/index.xml" rel="self" type="application/rss+xml"/><item><title>Grafana 13.1.4 patches CVE-2026-17183</title><link>https://curadevops.metacog.co.kr/insights/2026-08-24-13-1-4/</link><pubDate>Mon, 24 Aug 2026 12:43:44 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-24-13-1-4/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Grafana is a common observability stack component; CVE-2026-17183 is not KEV-listed and carries EPSS 0.00, so no active exploitation signal, but schedule an upgrade to 13.1.4 this sprint as standard patch hygiene.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-17183 — CISA KEV: not listed, EPSS 0.00&lt;/li>
&lt;/ul></description></item><item><title>Docker Engine (Moby) v25.0.17 patches three container CVEs</title><link>https://curadevops.metacog.co.kr/insights/2026-08-17-v25-0-17/</link><pubDate>Mon, 17 Aug 2026 12:38:40 +0000</pubDate><guid>https://curadevops.metacog.co.kr/insights/2026-08-17-v25-0-17/</guid><description>&lt;ul>
&lt;li>&lt;strong>Platform/SRE — Plan:&lt;/strong> Three symlink/mount CVEs in the Docker engine (none KEV-listed, EPSS 0.00) warrant scheduling a patch to Moby 25.0.17 this sprint; also note that containerd 1.7 — vendored in this release — reaches EOL 2026-09-01, so any org running containerd 1.7 directly must plan a runtime upgrade within 15 days.&lt;/li>
&lt;li>&lt;strong>CI/CD — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> containerd 1.7 reaches EOL in 15d (2026-09-01) · major release (25.0) · CVE-2024-40635 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-41567 — CISA KEV: not listed, EPSS 0.00 · CVE-2026-41568 — CISA KEV: not listed, EPSS 0.00&lt;/li>
&lt;/ul></description></item></channel></rss>