From 4238485aa19b1604987b09aebb4951146d6e6f97 Mon Sep 17 00:00:00 2001 From: sean wibisono Date: Tue, 11 Aug 2026 09:17:11 +1000 Subject: [PATCH] UID2-7656: suppress CVE-2026-56408 in .trivyignore (exp 2026-11-11) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit unknown package is present but not reachable from this service — see UID2-7656 for the impact assessment. Reachability alone determines suppress-vs-fix. --- .trivyignore | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.trivyignore b/.trivyignore index c0e23648..62610d3a 100644 --- a/.trivyignore +++ b/.trivyignore @@ -39,7 +39,13 @@ CVE-2026-2100 exp:2026-09-01 # See: UID2-7456 CVE-2026-56131 exp:2026-08-09 CVE-2026-56407 exp:2026-08-09 -CVE-2026-56408 exp:2026-08-09 +# CVE-2026-56408 — libexpat (Alpine base image, transitive via eclipse-temurin:21-jre- +# alpine-3.23) (HIGH). +# Not exploitable here: Dockerfile FROM eclipse-temurin:21-jre-alpine-3.23; libexpat not apk- +# added, only libpng/libcrypto3/libssl3/gnutls. Pure-Java Vert.x jar; no expat/JNI/loadLibrary +# refs in any *.java. XML (logback.xml/conf) parsed by JVM JAXP, not native libexpat. +# See: UID2-7656 +CVE-2026-56408 exp:2026-11-11 # jackson-core async parser maxNumberLength bypass (GHSA-r7wm-3cxj-wff9) - incomplete fix for # GHSA-72hv-8253-57qq. Not exploitable: services only use the synchronous ObjectMapper API, not