From 79296baabc52f4144c440d5e0d9cc496682b9da0 Mon Sep 17 00:00:00 2001 From: Alexsander Hamir Date: Tue, 10 Feb 2026 12:37:15 -0800 Subject: [PATCH] fix: address security scan failures (Node, orjson, diff) - Pin Node to 24.13.0 (nodejs-24-24.13.0-r0) in Dockerfile and Dockerfile.database to fix Node CVEs (CVE-2025-55130, etc.) - Upgrade orjson to 3.11.7 in requirements.txt (CVE-2025-67221) - Add npm override for diff>=8.0.3 in litellm-dashboard (GHSA-73rr-hh4g-fpgx) - Remove Node CVEs from .grype.yaml and security_scans.sh allowlist; keep Python 3.13 / zlib ignores (no fix in Wolfi yet) --- Dockerfile | 4 ++-- ci_cd/.grype.yaml | 17 +++++++++++++++++ ci_cd/security_scans.sh | 6 ------ docker/Dockerfile.database | 2 +- requirements.txt | 2 +- ui/litellm-dashboard/package.json | 1 + 6 files changed, 22 insertions(+), 10 deletions(-) diff --git a/Dockerfile b/Dockerfile index 5e93a0c627e..d460a1d0a2c 100644 --- a/Dockerfile +++ b/Dockerfile @@ -47,8 +47,8 @@ FROM $LITELLM_RUNTIME_IMAGE AS runtime # Ensure runtime stage runs as root USER root -# Install runtime dependencies (libsndfile needed for audio processing on ARM64) -RUN apk add --no-cache bash openssl tzdata nodejs npm python3 py3-pip libsndfile && \ +# Install runtime dependencies (libsndfile for ARM64; nodejs-24-24.13.0-r0 for Node CVEs) +RUN apk add --no-cache bash openssl tzdata nodejs-24-24.13.0-r0 npm python3 py3-pip libsndfile && \ npm install -g npm@latest tar@7.5.7 glob@11.1.0 @isaacs/brace-expansion@5.0.1 && \ # SECURITY FIX: npm bundles tar, glob, and brace-expansion at multiple nested # levels inside its dependency tree. `npm install -g ` only creates a diff --git a/ci_cd/.grype.yaml b/ci_cd/.grype.yaml index 642e2dd9d03..921bb4f5a26 100644 --- a/ci_cd/.grype.yaml +++ b/ci_cd/.grype.yaml @@ -1,3 +1,20 @@ ignore: - vulnerability: CVE-2026-22184 reason: no fixed zlib package is available yet in the Wolfi repositories, so this is ignored temporarily until an upstream release exists + # Wolfi base image: Python 3.13 has no fixed apk build yet (Node 24.13 fixed via Dockerfile pin) + - vulnerability: CVE-2026-0865 + reason: Python 3.13 in Wolfi base; no fixed apk build yet + - vulnerability: CVE-2025-15282 + reason: Python 3.13 in Wolfi base; no fixed apk build yet + - vulnerability: CVE-2026-0672 + reason: Python 3.13 in Wolfi base; no fixed apk build yet + - vulnerability: CVE-2025-15366 + reason: Python 3.13 in Wolfi base; no fixed apk build yet + - vulnerability: CVE-2025-15367 + reason: Python 3.13 in Wolfi base; no fixed apk build yet + - vulnerability: CVE-2025-11468 + reason: Python 3.13 in Wolfi base; no fixed apk build yet + - vulnerability: CVE-2025-12781 + reason: Python 3.13 in Wolfi base; no fixed apk build yet + - vulnerability: CVE-2026-1299 + reason: Python 3.13 in Wolfi base; no fixed apk build yet diff --git a/ci_cd/security_scans.sh b/ci_cd/security_scans.sh index 3ffa13c444f..505946057f8 100755 --- a/ci_cd/security_scans.sh +++ b/ci_cd/security_scans.sh @@ -140,12 +140,6 @@ run_grype_scans() { "GHSA-34x7-hfp2-rc4v" # node-tar hardlink path traversal - not applicable, tar CLI not exposed in application code "GHSA-r6q2-hw4h-h46w" # node-tar not used by application runtime, Linux-only container, not affect by macOS APFS-specific exploit "GHSA-8rrh-rw8j-w5fx" # wheel is from chainguard and will be handled by then TODO: Remove this after Chainguard updates the wheel - "CVE-2025-59465" # We do not use Node in application runtime, only used for building Admin UI - "CVE-2025-55131" # We do not use Node in application runtime, only used for building Admin UI - "CVE-2025-59466" # We do not use Node in application runtime, only used for building Admin UI - "CVE-2025-55130" # We do not use Node in application runtime, only used for building Admin UI - "CVE-2025-59467" # We do not use Node in application runtime, only used for building Admin UI - "CVE-2026-21637" # We do not use Node in application runtime, only used for building Admin UI "CVE-2025-15281" # No fix available yet "CVE-2026-0865" # No fix available yet "CVE-2025-15282" # No fix available yet diff --git a/docker/Dockerfile.database b/docker/Dockerfile.database index a6fcd98ab6d..74fbaf8d684 100644 --- a/docker/Dockerfile.database +++ b/docker/Dockerfile.database @@ -49,7 +49,7 @@ FROM $LITELLM_RUNTIME_IMAGE AS runtime USER root # Install runtime dependencies -RUN apk add --no-cache bash openssl tzdata nodejs npm python3 py3-pip libsndfile && \ +RUN apk add --no-cache bash openssl tzdata nodejs-24-24.13.0-r0 npm python3 py3-pip libsndfile && \ npm install -g npm@latest tar@7.5.7 glob@11.1.0 @isaacs/brace-expansion@5.0.1 && \ GLOBAL="$(npm root -g)" && \ find "$GLOBAL/npm" -type d -name "tar" -path "*/node_modules/tar" | while read d; do \ diff --git a/requirements.txt b/requirements.txt index f680de120c5..29405cdc420 100644 --- a/requirements.txt +++ b/requirements.txt @@ -32,7 +32,7 @@ async_generator==1.10.0 # for async ollama calls langfuse==2.59.7 # for langfuse self-hosted logging prometheus_client==0.20.0 # for /metrics endpoint on proxy ddtrace==2.19.0 # for advanced DD tracing / profiling -orjson==3.11.2 # fast /embedding responses +orjson==3.11.7 # fast /embedding responses polars==1.31.0 # for data processing apscheduler==3.10.4 # for resetting budget in background fastapi-sso==0.19.0 # admin UI, SSO diff --git a/ui/litellm-dashboard/package.json b/ui/litellm-dashboard/package.json index 76ac97f008c..42b90d27333 100644 --- a/ui/litellm-dashboard/package.json +++ b/ui/litellm-dashboard/package.json @@ -79,6 +79,7 @@ "vitest": "^3.2.4" }, "overrides": { + "diff": ">=8.0.3", "prismjs": ">=1.30.0", "webpack-dev-server": ">=5.2.1", "mermaid": ">=11.10.0",