{"@context":"https://openvex.dev/ns/v0.2.0","@id":"pkg:docker/operator@1.29.0","author":"security@datadoghq.com","author_role":"Vulnerability Management","last_updated":"2026-08-25T12:29:03.952910253Z","statements":[{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.772312Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.772311Z","products":[{"@id":"pkg:golang/stdlib@1.25.12"}],"status":"affected","timestamp":"2026-08-14T12:07:56.772311Z","vulnerability":{"name":"CVE-2026-39821"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.772416Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.772416Z","products":[{"@id":"pkg:golang/stdlib@1.25.12"}],"status":"affected","timestamp":"2026-08-14T12:07:56.772415Z","vulnerability":{"name":"CVE-2026-46600"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.772509Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.772509Z","products":[{"@id":"pkg:rpm/redhat/libgcc@14.3.1-4.4.el10?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=gcc-14.3.1-4.4.el10.src.rpm"},{"@id":"pkg:rpm/redhat/libgcc@14.3.1-4.4.el10?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=gcc-14.3.1-4.4.el10.src.rpm"}],"status":"affected","timestamp":"2026-08-14T12:07:56.772509Z","vulnerability":{"name":"CVE-2021-46195"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.772545Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.772545Z","products":[{"@id":"pkg:rpm/redhat/pam-libs@1.6.1-9.el10?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=pam-1.6.1-9.el10.src.rpm"},{"@id":"pkg:rpm/redhat/pam-libs@1.6.1-9.el10?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=pam-1.6.1-9.el10.src.rpm"}],"status":"affected","timestamp":"2026-08-14T12:07:56.772545Z","vulnerability":{"name":"CVE-2026-54411"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.772589Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.772589Z","products":[{"@id":"pkg:rpm/redhat/glibc@2.39-128.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-common@2.39-128.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-minimal-langpack@2.39-128.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc@2.39-128.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-common@2.39-128.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-minimal-langpack@2.39-128.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"}],"status":"affected","timestamp":"2026-08-14T12:07:56.772589Z","vulnerability":{"name":"CVE-2026-6791"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.772662Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.772662Z","products":[{"@id":"pkg:rpm/redhat/coreutils-single@9.5-8.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=coreutils-9.5-8.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/coreutils-single@9.5-8.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=coreutils-9.5-8.el10_2.src.rpm"}],"status":"affected","timestamp":"2026-08-14T12:07:56.772662Z","vulnerability":{"name":"CVE-2026-56391"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.772719Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.772719Z","products":[{"@id":"pkg:rpm/redhat/libattr@2.5.2-5.el10?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=attr-2.5.2-5.el10.src.rpm"},{"@id":"pkg:rpm/redhat/libattr@2.5.2-5.el10?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=attr-2.5.2-5.el10.src.rpm"}],"status":"affected","timestamp":"2026-08-14T12:07:56.772719Z","vulnerability":{"name":"CVE-2026-54371"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.772758Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.772758Z","products":[{"@id":"pkg:rpm/redhat/coreutils-single@9.5-8.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=coreutils-9.5-8.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/coreutils-single@9.5-8.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=coreutils-9.5-8.el10_2.src.rpm"}],"status":"affected","timestamp":"2026-08-14T12:07:56.772758Z","vulnerability":{"name":"CVE-2026-56392"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.772829Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.772829Z","products":[{"@id":"pkg:rpm/redhat/pam-libs@1.6.1-9.el10?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=pam-1.6.1-9.el10.src.rpm"},{"@id":"pkg:rpm/redhat/pam-libs@1.6.1-9.el10?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=pam-1.6.1-9.el10.src.rpm"}],"status":"affected","timestamp":"2026-08-14T12:07:56.772828Z","vulnerability":{"name":"CVE-2026-12610"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.77286Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.772859Z","products":[{"@id":"pkg:rpm/redhat/glibc@2.39-128.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-common@2.39-128.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-minimal-langpack@2.39-128.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc@2.39-128.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-common@2.39-128.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-minimal-langpack@2.39-128.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"}],"status":"affected","timestamp":"2026-08-14T12:07:56.772859Z","vulnerability":{"name":"CVE-2026-6368"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.772927Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.772927Z","products":[{"@id":"pkg:golang/github.com/google/cel-go@v0.26.0"}],"status":"under_investigation","timestamp":"2026-08-14T12:07:56.772926Z","vulnerability":{"name":"GHSA-gcjh-h69q-9w9g"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.772977Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.772977Z","products":[{"@id":"pkg:golang/golang.org/x/mod@v0.37.0"}],"status":"under_investigation","timestamp":"2026-08-14T12:07:56.772976Z","vulnerability":{"name":"CVE-2026-56864"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.773021Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.773021Z","products":[{"@id":"pkg:golang/golang.org/x/mod@v0.37.0"}],"status":"under_investigation","timestamp":"2026-08-14T12:07:56.773021Z","vulnerability":{"name":"CVE-2026-56865"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.773063Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.773063Z","products":[{"@id":"pkg:golang/stdlib@1.25.12"}],"status":"under_investigation","timestamp":"2026-08-14T12:07:56.773063Z","vulnerability":{"name":"CVE-2026-33818"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.773138Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.773138Z","products":[{"@id":"pkg:golang/stdlib@1.25.12"}],"status":"under_investigation","timestamp":"2026-08-14T12:07:56.773138Z","vulnerability":{"name":"CVE-2026-56853"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.773221Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.773221Z","products":[{"@id":"pkg:golang/stdlib@1.25.12"}],"status":"under_investigation","timestamp":"2026-08-14T12:07:56.773221Z","vulnerability":{"name":"CVE-2026-56858"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.773286Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.773285Z","products":[{"@id":"pkg:golang/stdlib@1.25.12"}],"status":"under_investigation","timestamp":"2026-08-14T12:07:56.773285Z","vulnerability":{"name":"CVE-2026-56859"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.773352Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.773352Z","products":[{"@id":"pkg:golang/stdlib@1.25.12"}],"status":"under_investigation","timestamp":"2026-08-14T12:07:56.773352Z","vulnerability":{"name":"CVE-2026-56860"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.773421Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.773421Z","products":[{"@id":"pkg:golang/stdlib@1.25.12"}],"status":"under_investigation","timestamp":"2026-08-14T12:07:56.773421Z","vulnerability":{"name":"CVE-2026-56862"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.773493Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.773493Z","products":[{"@id":"pkg:rpm/redhat/glibc@2.39-128.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc@2.39-128.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"}],"status":"under_investigation","timestamp":"2026-08-14T12:07:56.773493Z","vulnerability":{"name":"CVE-2026-4046"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.773538Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.773538Z","products":[{"@id":"pkg:rpm/redhat/glibc@2.39-128.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc@2.39-128.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-128.el10_2.src.rpm"}],"status":"under_investigation","timestamp":"2026-08-14T12:07:56.773538Z","vulnerability":{"name":"CVE-2025-15281"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.773569Z","impact_statement":"This vulnerability is not exploitable in our environment, as the affected function is not used by the application. The binary does not link against or invoke the vulnerable component (cap_set_file function).","justification":"vulnerable_code_not_present","last_updated":"2026-08-14T12:07:56.773569Z","products":[{"@id":"pkg:rpm/redhat/libcap@2.69-7.el10_2.1?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=libcap-2.69-7.el10_2.1.src.rpm"},{"@id":"pkg:rpm/redhat/libcap@2.69-7.el10_2.1?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=libcap-2.69-7.el10_2.1.src.rpm"}],"status":"not_affected","timestamp":"2026-08-14T12:07:56.773568Z","vulnerability":{"name":"CVE-2026-4878"}},{"action_statement":"","action_statement_timestamp":"2026-08-14T12:07:56.773605Z","impact_statement":"The vulnerable code path cannot exist in the image because the vulnerable file was never included in it, and the operator's Go source contains no reference to ncurses, terminfo, or any terminal-capability library","justification":"vulnerable_code_not_present","last_updated":"2026-08-14T12:07:56.773605Z","products":[{"@id":"pkg:rpm/redhat/ncurses-base@6.4-15.20240127.el10_1?arch=noarch\u0026distro=rhel-10.2\u0026upstream=ncurses-6.4-15.20240127.el10_1.src.rpm"}],"status":"not_affected","timestamp":"2026-08-14T12:07:56.773605Z","vulnerability":{"name":"CVE-2025-69720"}},{"action_statement":"","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.824904Z","products":[{"@id":"pkg:golang/golang.org/x/text@v0.37.0"}],"status":"fixed","timestamp":"2026-08-14T12:07:56.824904Z","vulnerability":{"name":"CVE-2026-56852"}},{"action_statement":"","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.824935Z","products":[{"@id":"pkg:rpm/redhat/glibc@2.39-126.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-common@2.39-126.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-minimal-langpack@2.39-126.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc@2.39-126.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-common@2.39-126.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-minimal-langpack@2.39-126.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"}],"status":"fixed","timestamp":"2026-08-14T12:07:56.824934Z","vulnerability":{"name":"CVE-2026-6238"}},{"action_statement":"","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.824941Z","products":[{"@id":"pkg:golang/stdlib@1.25.11"}],"status":"fixed","timestamp":"2026-08-14T12:07:56.824941Z","vulnerability":{"name":"CVE-2026-42505"}},{"action_statement":"","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.824945Z","products":[{"@id":"pkg:rpm/redhat/glibc@2.39-126.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-common@2.39-126.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-minimal-langpack@2.39-126.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc@2.39-126.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-common@2.39-126.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-minimal-langpack@2.39-126.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"}],"status":"fixed","timestamp":"2026-08-14T12:07:56.824944Z","vulnerability":{"name":"CVE-2026-5928"}},{"action_statement":"","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.824948Z","products":[{"@id":"pkg:golang/stdlib@1.25.11"}],"status":"fixed","timestamp":"2026-08-14T12:07:56.824948Z","vulnerability":{"name":"CVE-2026-39822"}},{"action_statement":"","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.824952Z","products":[{"@id":"pkg:rpm/redhat/glibc@2.39-126.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-common@2.39-126.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-minimal-langpack@2.39-126.el10_2?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc@2.39-126.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-common@2.39-126.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"},{"@id":"pkg:rpm/redhat/glibc-minimal-langpack@2.39-126.el10_2?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=glibc-2.39-126.el10_2.src.rpm"}],"status":"fixed","timestamp":"2026-08-14T12:07:56.824952Z","vulnerability":{"name":"CVE-2026-5435"}},{"action_statement":"","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.824961Z","products":[{"@id":"pkg:golang/go.opentelemetry.io/otel@v1.43.0"}],"status":"fixed","timestamp":"2026-08-14T12:07:56.824961Z","vulnerability":{"name":"CVE-2026-41178"}},{"action_statement":"","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.824972Z","products":[{"@id":"pkg:rpm/redhat/libacl@2.3.2-4.el10?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=acl-2.3.2-4.el10.src.rpm"},{"@id":"pkg:rpm/redhat/libacl@2.3.2-4.el10?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=acl-2.3.2-4.el10.src.rpm"}],"status":"fixed","timestamp":"2026-08-14T12:07:56.824971Z","vulnerability":{"name":"CVE-2026-54369"}},{"action_statement":"","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.824975Z","products":[{"@id":"pkg:rpm/redhat/libacl@2.3.2-4.el10?arch=x86_64\u0026distro=rhel-10.2\u0026upstream=acl-2.3.2-4.el10.src.rpm"},{"@id":"pkg:rpm/redhat/libacl@2.3.2-4.el10?arch=aarch64\u0026distro=rhel-10.2\u0026upstream=acl-2.3.2-4.el10.src.rpm"}],"status":"fixed","timestamp":"2026-08-14T12:07:56.824975Z","vulnerability":{"name":"CVE-2026-54370"}},{"action_statement":"","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-14T12:07:56.824978Z","products":[{"@id":"pkg:golang/google.golang.org/grpc@v1.79.3"}],"status":"fixed","timestamp":"2026-08-14T12:07:56.824978Z","vulnerability":{"name":"GHSA-hrxh-6v49-42gf"}}],"timestamp":"2026-08-05T12:12:00.857802472Z","tooling":"","version":15}