π [IBM OSPO Security Notification] β IBM/core-dump-handler
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.
SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β
they will never trigger warnings or archiving.
π‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β Advanced Security β Dependabot security updates β Enable.
π New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.
Attention: @No9
Dependabot Alerts
| Severity |
CVE/GHSA |
Package |
Affected |
Patched |
Deadline |
Fix PR |
| π high |
CVE-2026-41681 |
openssl |
>= 0.10.39, < 0.10.78 |
0.10.78 |
2026-10-22 |
β |
| π high |
CVE-2026-41898 |
openssl |
>= 0.9.24, < 0.10.78 |
0.10.78 |
2026-10-22 |
β |
| π high |
CVE-2026-41678 |
openssl |
>= 0.10.24, < 0.10.78 |
0.10.78 |
2026-10-22 |
β |
| π high |
CVE-2026-41676 |
openssl |
>= 0.9.27, < 0.10.78 |
0.10.78 |
2026-10-22 |
β |
| π high |
GHSA-82j2-j2ch-gfr8 |
rustls-webpki |
< 0.103.13 |
0.103.13 |
2026-10-22 |
β |
| π high |
CVE-2026-42327 |
openssl |
>= 0.9.7, < 0.10.79 |
0.10.79 |
2026-10-22 |
β |
| π‘ medium |
CVE-2024-12224 |
idna |
< 1.0.0 |
1.0.0 |
2026-12-21 |
β |
| π‘ medium |
CVE-2025-24898 |
openssl |
>= 0.10.0, < 0.10.70 |
0.10.70 |
2026-12-21 |
β |
| π‘ medium |
CVE-2025-4432 |
ring |
< 0.17.12 |
0.17.12 |
2026-12-21 |
β |
| π‘ medium |
GHSA-4fcv-w3qc-ppgg |
openssl |
>= 0.10.39, < 0.10.72 |
0.10.72 |
2026-12-21 |
β |
| π‘ medium |
CVE-2026-25541 |
bytes |
>= 1.2.1, < 1.11.1 |
1.11.1 |
2026-12-21 |
β |
| π‘ medium |
CVE-2026-25727 |
time |
>= 0.3.6, < 0.3.47 |
0.3.47 |
2026-12-21 |
β |
| π‘ medium |
CVE-2026-44662 |
openssl |
>= 0.10.0, < 0.10.79 |
0.10.79 |
2026-12-21 |
β |
| π‘ medium |
CVE-2026-45784 |
openssl |
>= 0.10.50, < 0.10.80 |
0.10.80 |
2026-12-21 |
β |
| π΅ low |
GHSA-g98v-hv3f-hcfr |
atty |
<= 0.2.14 |
β |
β |
β |
| π΅ low |
GHSA-rr8g-9fpq-6wmg |
tokio |
>= 1.39.0, < 1.43.1 |
1.43.1 |
β |
β |
| π΅ low |
GHSA-965h-392x-2mh5 |
rustls-webpki |
>= 0.101.0, < 0.103.12 |
0.103.12 |
β |
β |
| π΅ low |
GHSA-xgp8-3hg3-c2mh |
rustls-webpki |
>= 0.101.0, < 0.103.12 |
0.103.12 |
β |
β |
| π΅ low |
GHSA-cq8v-f236-94qc |
rand |
>= 0.7.0, < 0.8.6 |
0.8.6 |
β |
β |
| π΅ low |
CVE-2026-41677 |
openssl |
>= 0.9.0, < 0.10.78 |
0.10.78 |
β |
β |
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.
π [IBM OSPO Security Notification] β IBM/core-dump-handler
Attention: @No9
Dependabot Alerts
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.