Conversation
…VE-2026-75803) Signed-off-by: Jan Welker <jan@wlkr.ch>
|
Correction to my own PR: there is a fourth critical in this image that I missed, and this bump most likely does not fix it.
I could not confirm whether the fix reached the 3.3 branch:
If someone can check against the stable 3.3 tree, that would settle it. Two notes on how to weigh this: Reachability. The bug is in the FastCGI multiplexer. This chart's HAProxy proxies Redis over TCP and configures no FCGI backend, so the vulnerable path should not be reachable in the default configuration. Correction to my PR description. I listed socat CVE-2026-56123 among the three fixed. That is accurate as far as it goes, but relevancy analysis shows socat is not loaded at runtime in this image, whereas CVE-2026-55203 is in the binary that is. So the runtime-relevant effect of this PR is the two OpenSSL CVEs (four findings across libcrypto3 and libssl3), not three. The OpenSSL bump still stands on its own and I would still suggest merging it — I just did not want to leave the impression that it clears this image's critical findings. |
|
Adding a note on who this actually fixes, since it is not only direct users of this chart. This PR fixes the Argo CD chart. Argo CD 10.9.2 therefore ships That also means the fix does not reach them when this merges. It reaches them when this merges and a I have posted a values-level workaround on #423 for Argo CD users who need to move before then, and applied it in my own cluster (JanWelker/homelab#753) — but it only helps people who find the thread, so it does not substitute for this landing. Happy to rebase or split the README chunk out if that makes review easier. |
* fix(argocd): pin the redis-ha HAProxy image ahead of the chart The argo-cd chart vendors redis-ha 4.38.0 inside its release tarball, so the subchart's haproxy pin travels with it and no repository override can reach it. That pin is 3.3.10-alpine, which carries three critical CVEs: CVE-2026-63073 and CVE-2026-75803 in libcrypto3/libssl3, and CVE-2026-56123 in socat. Overriding the tag is enough. 3.3.14-alpine is the same HAProxy 3.3 line rebuilt on Alpine 3.24, whose APKINDEX carries the fixed packages, so this is a patch-level change to one image and nothing else in the chart moves. Upstream fix is DandyDeveloper/charts#424; this override comes out once the argo-cd chart vendors redis-ha 4.39.1 or later. * fix(argocd): let Renovate track the HAProxy tag override The override was invisible to Renovate. The helm-values manager only extracts an image block that carries a repository key alongside the tag: hasKey('repository', data) && (hasKey('tag', data) || hasKey('version', data)) This block sets only the tag, since the repository comes from the argo-cd chart's own values, so the manager skipped it and the pin would have gone stale exactly the way the upstream pins do. Annotating it hands the tag to the custom manager that already tracks inline image versions elsewhere in payload/. Restating the repository here would also work, but would pin argo-helm's registry choice as a side effect. versioning=docker keeps the -alpine suffix from being read as a semver prerelease.
What this PR does / why we need it:
Updates the HAProxy image from
3.3.10-alpineto3.3.14-alpine, which clears three critical CVEs:3.3.14-alpinewas rebuilt 2026-09-18 on Alpine 3.24; the package versions above are from the Alpine v3.24 APKINDEX. Same HAProxy 3.3 line, same Alpine base family — patch-level change only.This follows the same shape as #405, which bumped this pin for CVE-2025-15467.
Which issue this PR fixes
Special notes for your reviewer:
README.mdline 262 documentedhaproxy.image.tagas3.0.8-alpine— helm-docs was not re-run after #405, so the row was two bumps behind. This PR updates it to matchvalues.yaml. I checked the other generated tag rows (image.tag,configmapTest.image.tag,exporter.tag) and they are all in sync, so no other README churn is included.charts/redis-ha/ci/haproxy-enabled-values.yamlexists, soct installexercises this change on kind.As noted in #423, this repository has no Renovate or Dependabot configuration, which is why these pins drift into CVE reports. Happy to send a config PR separately if that is something you would want.
Prepared with the help of Claude Code; package versions verified against the Alpine v3.24 APKINDEX, and reviewed before raising.
Checklist
[Place an '[x]' (no spaces) in all applicable fields. Please remove unrelated fields.]
[stable/mychartname])