Skip to main content
Testkube 2.7.0 is out! An improved resource management architecture and a new GitOps Agent, AI improvements, and more. Read More

testkube-tw-toolkit-2.7.1_linux_arm64

digestsha256:fa602d36ad64ba3e4039d2b03296c9c07af5853cac3800b96e3fb65e3a8b50b1
vulnerabilitiescritical: 1 high: 6 medium: 19 low: 7
platformlinux/arm64
size48 MB
packages206
critical: 1 high: 3 medium: 6 low: 0 libssl3 3.3.5-r0 (apk)

pkg:apk/alpine/libssl3@3.3.5-r0?arch=aarch64&distro=alpine-3.20.8&upstream=openssl

# tw-toolkit.Dockerfile (24:24)
FROM ${ALPINE_IMAGE}

critical : CVE--2025--15467

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score1.010%
EPSS Percentile77th percentile
Description

high : CVE--2025--69421

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.065%
EPSS Percentile20th percentile
Description

high : CVE--2025--69420

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.199%
EPSS Percentile42nd percentile
Description

high : CVE--2025--69419

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.061%
EPSS Percentile19th percentile
Description

medium : CVE--2025--66199

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.064%
EPSS Percentile20th percentile
Description

medium : CVE--2025--15468

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.052%
EPSS Percentile16th percentile
Description

medium : CVE--2026--22795

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.017%
EPSS Percentile4th percentile
Description

medium : CVE--2026--22796

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.077%
EPSS Percentile23rd percentile
Description

medium : CVE--2025--68160

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.016%
EPSS Percentile4th percentile
Description

medium : CVE--2025--69418

Affected range<3.3.6-r0
Fixed version3.3.6-r0
EPSS Score0.005%
EPSS Percentile0th percentile
Description
critical: 0 high: 1 medium: 9 low: 1 libcurl 8.14.1-r2 (apk)

pkg:apk/alpine/libcurl@8.14.1-r2?arch=aarch64&distro=alpine-3.20.8&upstream=curl

# tw-toolkit.Dockerfile (25:25)
RUN apk --no-cache add ca-certificates libssl3 git openssh-client

high : CVE--2026--3805

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.018%
EPSS Percentile4th percentile
Description

medium : CVE--2026--3784

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.016%
EPSS Percentile4th percentile
Description

medium : CVE--2026--1965

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.036%
EPSS Percentile10th percentile
Description

medium : CVE--2025--14017

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.007%
EPSS Percentile1st percentile
Description

medium : CVE--2025--13034

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.008%
EPSS Percentile1st percentile
Description

medium : CVE--2026--3783

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.016%
EPSS Percentile4th percentile
Description

medium : CVE--2025--15079

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.030%
EPSS Percentile8th percentile
Description

medium : CVE--2025--14819

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.039%
EPSS Percentile12th percentile
Description

medium : CVE--2025--14524

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.030%
EPSS Percentile8th percentile
Description

medium : CVE--2025--10966

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.018%
EPSS Percentile4th percentile
Description

low : CVE--2025--15224

Affected range<=8.14.1-r2
Fixed versionNot Fixed
EPSS Score0.072%
EPSS Percentile22nd percentile
Description
critical: 0 high: 1 medium: 1 low: 0 c-ares 1.33.1-r0 (apk)

pkg:apk/alpine/c-ares@1.33.1-r0?arch=aarch64&distro=alpine-3.20.8

# tw-toolkit.Dockerfile (25:25)
RUN apk --no-cache add ca-certificates libssl3 git openssh-client

high : CVE--2025--31498

Affected range<=1.33.1-r0
Fixed versionNot Fixed
EPSS Score0.618%
EPSS Percentile70th percentile
Description

medium : CVE--2025--62408

Affected range<=1.33.1-r0
Fixed versionNot Fixed
EPSS Score0.019%
EPSS Percentile5th percentile
Description
critical: 0 high: 1 medium: 0 low: 0 github.com/docker/cli 27.1.1+incompatible (golang)

pkg:golang/github.com/docker/cli@27.1.1%2Bincompatible

# tw-toolkit.Dockerfile (28:28)
COPY --from=build /app/testworkflow-init /init

high 7.0: CVE--2025--15558 Uncontrolled Search Path Element

Affected range
>=19.03.0
<29.2.0
Fixed version29.2.0
CVSS Score7
CVSS VectorCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score0.011%
EPSS Percentile1st percentile
Description

This issue affects Docker CLI through 29.1.5

Impact

Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are executed when a victim user opens Docker Desktop or invokes Docker CLI plugin features, and allow privilege-escalation if the docker CLI is executed as a privileged user.

This issue affects Docker CLI through v29.1.5 (fixed in v29.2.0). It impacts Windows binaries acting as a CLI plugin manager via the github.com/docker/cli/cli-plugins/manager package, which is consumed by downstream projects such as Docker Compose.

Docker Compose became affected starting in v2.31.0, when it incorporated the relevant CLI plugin manager code (see https://github.com/docker/compose/pull/12300), and is fixed in v5.1.0.

This issue does not impact non-Windows binaries or projects that do not use the plugin manager code.

Patches

Fixed version starts with 29.2.0

This issue was fixed in https://github.com/docker/cli/commit/13759330b1f7e7cb0d67047ea42c5482548ba7fa (https://github.com/docker/cli/pull/6713), which removed %PROGRAMDATA%\Docker\cli-plugins from the list of paths used for plugin-discovery on Windows.

Workarounds

None

Resources

Credits

Nitesh Surana (niteshsurana.com) of Trend Research of TrendAI

critical: 0 high: 0 medium: 1 low: 2 openssh-keygen 9.7_p1-r5 (apk)

pkg:apk/alpine/openssh-keygen@9.7_p1-r5?arch=aarch64&distro=alpine-3.20.8&upstream=openssh

# tw-toolkit.Dockerfile (25:25)
RUN apk --no-cache add ca-certificates libssl3 git openssh-client

medium : CVE--2025--32728

Affected range<=9.7_p1-r5
Fixed versionNot Fixed
EPSS Score0.274%
EPSS Percentile50th percentile
Description

low : CVE--2025--61985

Affected range<=9.7_p1-r5
Fixed versionNot Fixed
EPSS Score0.008%
EPSS Percentile1st percentile
Description

low : CVE--2025--61984

Affected range<=9.7_p1-r5
Fixed versionNot Fixed
EPSS Score0.005%
EPSS Percentile0th percentile
Description
critical: 0 high: 0 medium: 1 low: 2 ssl_client 1.36.1-r30 (apk)

pkg:apk/alpine/ssl_client@1.36.1-r30?arch=aarch64&distro=alpine-3.20.8&upstream=busybox

# tw-toolkit.Dockerfile (24:24)
FROM ${ALPINE_IMAGE}

medium : CVE--2025--60876

Affected range<=1.36.1-r30
Fixed versionNot Fixed
EPSS Score0.052%
EPSS Percentile16th percentile
Description

low : CVE--2025--46394

Affected range<1.36.1-r31
Fixed version1.36.1-r31
EPSS Score0.083%
EPSS Percentile24th percentile
Description

low : CVE--2024--58251

Affected range<1.36.1-r31
Fixed version1.36.1-r31
EPSS Score0.077%
EPSS Percentile23rd percentile
Description
critical: 0 high: 0 medium: 1 low: 1 libexpat 2.7.3-r0 (apk)

pkg:apk/alpine/libexpat@2.7.3-r0?arch=aarch64&distro=alpine-3.20.8&upstream=expat

# tw-toolkit.Dockerfile (25:25)
RUN apk --no-cache add ca-certificates libssl3 git openssh-client

medium : CVE--2026--25210

Affected range<2.7.4-r0
Fixed version2.7.4-r0
EPSS Score0.006%
EPSS Percentile0th percentile
Description

low : CVE--2026--24515

Affected range<2.7.4-r0
Fixed version2.7.4-r0
EPSS Score0.005%
EPSS Percentile0th percentile
Description
critical: 0 high: 0 medium: 0 low: 1 zlib 1.3.1-r1 (apk)

pkg:apk/alpine/zlib@1.3.1-r1?arch=aarch64&distro=alpine-3.20.8

# tw-toolkit.Dockerfile (24:24)
FROM ${ALPINE_IMAGE}

low : CVE--2026--27171

Affected range<=1.3.1-r1
Fixed versionNot Fixed
EPSS Score0.006%
EPSS Percentile0th percentile
Description