Skip to content

UID2-7279: suppress CVE-2026-45447 (libcrypto3); extend CVE-2026-42577 expiry#2602

Merged
cYKatherine merged 1 commit into
mainfrom
kchen-UID2-7279-libcrypto3-suppress
Jun 11, 2026
Merged

UID2-7279: suppress CVE-2026-45447 (libcrypto3); extend CVE-2026-42577 expiry#2602
cYKatherine merged 1 commit into
mainfrom
kchen-UID2-7279-libcrypto3-suppress

Conversation

@cYKatherine

Copy link
Copy Markdown
Contributor

Summary

  • CVE-2026-45447 suppression (UID2-7279): add libcrypto3 to .trivyignore with exp:2026-07-11. libcrypto3 is present in the Alpine base image but the JVM uses JSSE for TLS — not the native C library. No JNI or OpenSSL calls in source.
  • CVE-2026-42577 expiry extended: 2026-06-082026-09-11 (3 months; no 4.1.x fix available, vert.x 5 migration pending per UID2-7035).

Jira

Test plan

…expiry

- .trivyignore: add CVE-2026-45447 (libcrypto3 Alpine OS lib, not used by JVM/JSSE)
  with exp:2026-07-11
- .trivyignore: extend CVE-2026-42577 expiry to 2026-09-11 (no 4.1.x fix yet)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@cYKatherine cYKatherine merged commit 0ccfdaa into main Jun 11, 2026
9 checks passed
@cYKatherine cYKatherine deleted the kchen-UID2-7279-libcrypto3-suppress branch June 11, 2026 06:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants