Skip to content

Request to patch dependencies to fix CVE-2026-42504 #838

Description

@maffo-iscteiul

Hi,

Our security scanner has identified the following vulnerability in the Docker image prom/pushgateway:v1.11.3 (also referenced as prometheus/pushgateway:v1.11.3):

Could you please upgrade the image to a version that includes the fixed dependency?

Thank you!

Vulnerability Report

Vulnerabilities Found

Library Vulnerability Severity Status Installed Version Fixed Version Title
stdlib CVE-2026-42504 HIGH fixed v1.26.3 1.25.11, 1.26.4 Decoding a maliciously-crafted MIME header containing many invalid encoded words

Details:
https://avd.aquasec.com/nvd/cve-2026-42504


Summary:

  • Library: stdlib
  • Severity: High
  • Status: Fixed
  • Installed Version: v1.26.3
  • Recommended Version: 1.26.4

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions