CLEANSTART-2026-VA40669

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-VA40669
Upstream
  • CVE-2026-56854
Published
2026-10-09T00:37:23Z
Modified
2026-10-09T01:00:20Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
Details

CVE-2026-56854 affects multiple packages. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. See references for individual vulnerability details.

References

Affected packages

CleanStart
trust-manager-fips

Package

Name
trust-manager-fips
Purl
pkg:apk/cleanstart/trust-manager-fips

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.23.0-r2

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"
weaviate-fips

Package

Name
weaviate-fips
Purl
pkg:apk/cleanstart/weaviate-fips

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.38.19-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"
weaviate-fips

Package

Name
weaviate-fips
Purl
pkg:apk/cleanstart/weaviate-fips

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.39.10-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"
prometheus-redis-exporter-fips

Package

Name
prometheus-redis-exporter-fips
Purl
pkg:apk/cleanstart/prometheus-redis-exporter-fips

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.91.1-r1

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"
ollama-fips

Package

Name
ollama-fips
Purl
pkg:apk/cleanstart/ollama-fips?arch=x86_64

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.40.0-r3

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"
ollama-fips

Package

Name
ollama-fips
Purl
pkg:apk/cleanstart/ollama-fips?arch=aarch64

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.40.0-r3

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"
syft

Package

Name
syft
Purl
pkg:apk/cleanstart/syft

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.52.0-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"
ollama-fips

Package

Name
ollama-fips
Purl
pkg:apk/cleanstart/ollama-fips?arch=x86_64

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.34.4-r4

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"
ollama-fips

Package

Name
ollama-fips
Purl
pkg:apk/cleanstart/ollama-fips?arch=aarch64

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.34.4-r4

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"
weaviate-fips

Package

Name
weaviate-fips
Purl
pkg:apk/cleanstart/weaviate-fips

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.39.9-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"
prometheus-elasticsearch-exporter

Package

Name
prometheus-elasticsearch-exporter
Purl
pkg:apk/cleanstart/prometheus-elasticsearch-exporter

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.11.0-r2

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"
flux-image-automation-controller

Package

Name
flux-image-automation-controller
Purl
pkg:apk/cleanstart/flux-image-automation-controller?arch=x86_64

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.5-r1

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"
flux-image-automation-controller

Package

Name
flux-image-automation-controller
Purl
pkg:apk/cleanstart/flux-image-automation-controller?arch=aarch64

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.5-r1

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"
node-problem-detector

Package

Name
node-problem-detector
Purl
pkg:apk/cleanstart/node-problem-detector

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.8.25-r1

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VA40669.json"