Expected Behavior
No more CVEs found
Actual Behavior
There are some CVEs found from the latest Temporal image:
temporalio/ui:2.43.2
Steps to Reproduce the Problem
Pull the latest image temporalio/ui:2.43.2 from Dockerhub
Scan the image with any vulnerability scanner
| CVE |
SEVERITY |
CVSS |
PACKAGE |
VERSION |
FIX IN |
| CVE-2025-22870, CWE-918 |
HIGH |
8.8 |
golang.org/x/net/http/httpproxy |
v0.34.0 |
0.36.0 |