Skip to content

Request to patch dependencies to fix CVE-2026-42504 #838

@maffo-iscteiul

Description

@maffo-iscteiul

Hi,

Our security scanner has identified the following vulnerability in the Docker image prom/pushgateway:v1.11.3 (also referenced as prometheus/pushgateway:v1.11.3):

Could you please upgrade the image to a version that includes the fixed dependency?

Thank you!

Vulnerability Report

Vulnerabilities Found

Library Vulnerability Severity Status Installed Version Fixed Version Title
stdlib CVE-2026-42504 HIGH fixed v1.26.3 1.25.11, 1.26.4 Decoding a maliciously-crafted MIME header containing many invalid encoded words

Details:
https://avd.aquasec.com/nvd/cve-2026-42504


Summary:

  • Library: stdlib
  • Severity: High
  • Status: Fixed
  • Installed Version: v1.26.3
  • Recommended Version: 1.26.4

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions