Repository navigation
ci: stamp the version in the scan image and record that CVE-2026-33503 does not apply - #16
Merged
Merged
Conversation
…tement CVE-2026-33503 (GHSA-hgx2-28f8-6g2r) is an SQL injection through a forged page token of the ListCourierMessages Admin API. Its cause is the encrypted-token pagination package (ory/x keysetpagination_v2): that package builds the WHERE and ORDER BY clauses from the column names inside the token. Upstream moved the courier list to that package in 9931ea5 (first release v25.4.0) and added the column check in e006333 (first release v26.2.0). This fork is v1.3.0 with ory/x v0.0.660, and keysetpagination_v2 does not exist there. The courier list takes its column names from the server (WithColumn and the model columns) and binds the token values as query parameters. The advisory does not apply. The test sends two forged tokens to the endpoint: one with an unknown column name and one with an unbalanced quote in a column value. Each must return 200 with the recipient filter in effect. The test passed on the first run, because no defect exists. A temporary mutation of ListMessages proved that it can fail: with the token column names in the statement, the column name case returned 500 (no such column), and with the token values in the statement, the column value case returned 500 (syntax error). Claude-Session: https://claude.ai/code/session_01LbDrkZWVmFoiWnumt6MpWU
The CI scan could not see a CVE in the Kratos module itself. Trivy takes the version of the main module from the config.Version linker flag, because .dockerignore excludes .git. publish-image.yml passes VERSION, but the docker make target did not. So the published image v1.3.0-gn-v11 shows CVE-2026-33503 (HIGH), and the scan run on the same tag showed 0 findings for usr/bin/kratos. Scan gate changes: - Makefile: the docker target passes VERSION from `git describe --tags --always`. - cve-scan.yaml: the checkout uses fetch-depth 0. With a shallow checkout the version is a bare commit hash, and Trivy does not match a bare hash. - .trivyignore: adds CVE-2026-33503. The fork is not affected: the flaw is in ory/x keysetpagination_v2 (Kratos v25.4.0 and later), and ory/x v0.0.660 does not have that package. The test in courier/handler_test.go pins it. Remove the entry when the fork moves to an upstream version that has keysetpagination_v2. Local Trivy scans of a `make docker` image, with the options of cve-scan.yaml: - no stamp: 0 findings, exit 0 - stamp, no ignore entry: CVE-2026-33503, exit 42 - stamp and ignore entry: 0 findings, exit 0 - a bare commit hash as the version: 0 findings, exit 0 Claude-Session: https://claude.ai/code/session_01LbDrkZWVmFoiWnumt6MpWU
…e zone The "column name" case built its created_at bound from the clock in UTC. SQLite compares created_at as text, and pop stores it with the local offset of the machine. At UTC+2 or farther east each stored row sorted after the bound, so the list was empty and the test failed with 0 items in place of 2. The bound is now the fixed far-future value that Message.DefaultPageToken also uses, and the value of the unknown column is a constant, because only its name has an effect. Before: TZ=Europe/Berlin failed 2 of 4 subtests. After: 4 of 4 pass with TZ set to Europe/Berlin, Asia/Shanghai, UTC, America/Los_Angeles and Pacific/Kiritimati. Claude-Session: https://claude.ai/code/session_01LbDrkZWVmFoiWnumt6MpWU
Author
|
Ship summary: https://claude.ai/artifact/Bg48AoLDsQMcC7Z9P8sGLN |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The CI image scan now sees the Kratos module: the
dockertarget of theMakefilepassesVERSIONfromgit describe,cve-scan.yamlchecks out the full history, and.trivyignoregetsCVE-2026-33503with its reason.Trivy flags the published
v1.3.0-gn-v11image forCVE-2026-33503, but the fork is not affected: the flaw is inkeysetpagination_v2ofory/x(Kratos v25.4.0 and later), andory/xv0.0.660 does not have that package.Tested with a new forged page token case in
courier/handler_test.go(it fails under a mutation that puts token content into the statement) and with local Trivy scans of amake dockerimage: no stamp gives 0 findings, the stamp gives the CVE and exit 42, the stamp plus the ignore entry gives exit 0.https://claude.ai/code/session_01LbDrkZWVmFoiWnumt6MpWU