From 15d7dcae265b6d17c702216c4cbf42100287bf75 Mon Sep 17 00:00:00 2001 From: santidev21 Date: Thu, 1 Oct 2026 16:00:52 -0500 Subject: [PATCH] fix(docker): patch the base-OS pcre2 CVE in the nginx images CVE-2026-103111 (HIGH, pcre2 out-of-bounds write) is present in nginx:1.31-alpine and fails the required Docker Build & Trivy Scan gate. The published nginx image still ships pcre2 10.48-r0 and the cached apk upgrade layer skips the fix, so require pcre2>=10.49-r0 explicitly in both nginx-based images (frontend and proxy). Generic apk upgrade is kept for the rest of the base OS. --- docker/frontend/Dockerfile | 7 +++++-- docker/proxy/Dockerfile | 4 +++- 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/docker/frontend/Dockerfile b/docker/frontend/Dockerfile index 17de59b..18c1fbe 100644 --- a/docker/frontend/Dockerfile +++ b/docker/frontend/Dockerfile @@ -22,8 +22,11 @@ RUN npm run build -- --configuration production # Stage 2: Serve static files with Nginx Alpine FROM nginx:1.31-alpine AS final -# Install wget and upgrade Alpine packages to patch base OS vulnerabilities -RUN apk add --no-cache wget && apk upgrade --no-cache +# Install wget and upgrade Alpine packages to patch base OS vulnerabilities. +# pcre2 is listed explicitly because CVE-2026-103111 (fixed in 10.49-r0) is not +# yet in the published nginx image, and a cached `apk upgrade` layer would keep +# serving the vulnerable package. +RUN apk add --no-cache wget 'pcre2>=10.49-r0' && apk upgrade --no-cache # Copy custom Nginx configuration COPY docker/frontend/nginx.conf /etc/nginx/conf.d/default.conf diff --git a/docker/proxy/Dockerfile b/docker/proxy/Dockerfile index b8f8d99..9a8ac8a 100644 --- a/docker/proxy/Dockerfile +++ b/docker/proxy/Dockerfile @@ -5,7 +5,9 @@ FROM nginx:1.31-alpine # Install openssl for self-signed certificate generation in local/test mode. # gettext provides envsubst for rendering the nginx template at runtime. -RUN apk add --no-cache openssl gettext && apk upgrade --no-cache +# pcre2 is listed explicitly because CVE-2026-103111 (fixed in 10.49-r0) is not +# yet in the published nginx image. +RUN apk add --no-cache openssl gettext 'pcre2>=10.49-r0' && apk upgrade --no-cache # Create non-root-friendly directories and set ownership. # Nginx alpine image provides nginx user (UID 101) / group (GID 101).