Skip to content

FedRAMP remediation, July cycle (images due 2026-07-03) #16879

Description

@mohamedasni

Ship a patched build of h2oai-opensource-k8sminimal:v3.46.0.11-2 with the 0 critical and 1 high findings below resolved. Due 2026-07-03.

Where this comes from

  • Release scan: MC-26.06.0 FedRAMP scan summary.
  • Manifest: MC-26.06.0-fedramp.yaml. These are the images MC-26.06.0 ships to govcloud/FedRAMP this month; the fixes below are needed for the next release, built on top of these versions.
  • The scans were taken from umbrella chart v4.3.0-rc4, the version this manifest is built from. The umbrella chart version the next release will target is still being set by the umbrella team, so it is not assumed here.
  • Image(s) in scope for h2oai/h2o-3: h2oai-opensource-k8sminimal:v3.46.0.11-2.

What needs fixing

The findings below are the critical and high CVEs in the image(s) above as of 2026-06-17, for the exact versions pinned in the manifest. Fix them in the build that goes into the next release.

Caution

1 critical/high findings, due 2026-07-03. Each row is one (CVE, package, version) to remediate; the same finding across several images is shown once with all images listed.

CVE Severity Package Installed Fixed Published Image(s)
CVE-2026-45447 HIGH libcrypto3 3.6.2-r5 3.6.3-r0 2026-06-09 h2oai-opensource-k8sminimal:v3.46.0.11-2

How to close

When a build carrying the fixes lands in the next release, comment with the fixed image version and close this issue. If a finding does not apply to how MC runs the image, comment with the reason so it can be recorded as an accepted risk (POA&M) in the umbrella issue.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions