CLEANSTART-2026-FB77791

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-FB77791.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-FB77791
Upstream
Published
2026-09-18T10:17:37Z
Modified
2026-09-18T11:46:26Z
Summary
Security fix for CVE-2026-40890 applied in: gotenberg 8.30.1-r0, kube-metrics-adapter 0.2.9-r0, temporal 1.5.1-r0, temporal-ui-server-fips 2.48.2-r0
Details

CVE-2026-40890 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.

References

Affected packages

CleanStart / gotenberg

Package

Name
gotenberg

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.30.1-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-FB77791.json"

CleanStart / kube-metrics-adapter

Package

Name
kube-metrics-adapter

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.2.9-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-FB77791.json"

CleanStart / temporal

Package

Name
temporal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.1-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-FB77791.json"

CleanStart / temporal-ui-server-fips

Package

Name
temporal-ui-server-fips

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.48.2-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-FB77791.json"