🔴 Critical — Tier C: Restricted Pending Review
Source: UK AI Open Code Risk & Resilience Governance — weekly scan 2026-07-24
SLA: 3 days (by 2026-07-27)
Finding
The ghcr.io/github/gh-aw-firewall/agent:0.27.41 container image uses Go go1.24.6, which is affected by a critical vulnerability:
| ID |
Severity |
Package |
Fixed In |
| GO-2026-4337 |
🔴 Critical |
stdlib go1.24.6 |
≥go1.24.13, 1.25.7, 1.26.0-rc.3 |
Additionally there are 18 high-severity stdlib advisories all fixed by upgrading to go1.24.12+ or go1.25.6+. Total: 365 CVEs in the image (1 critical, 43 fixable). Digest drift also detected.
Risk Scoring
| Dimension |
Score (1–5) |
Notes |
| Exposure amplification |
5 |
Critical stdlib CVE in production agent runtime |
| Patchability |
4 |
Go toolchain upgrade; straightforward |
| Detectability |
4 |
Grype detects; exploit may be subtle |
| Operational fragility |
4 |
Agent container is core agentic runtime |
| Ownership confidence |
4 |
pelikhan owns firewall versioning |
| Overall |
Tier C |
Restricted Pending Review |
Remediation Actions
- Upgrade Go runtime in firewall agent Dockerfile to
≥go1.24.13 (or go1.25.7+).
- Rebuild
ghcr.io/github/gh-aw-firewall/agent with updated Go toolchain.
- Re-pin
actions-lock.json / container pin entries to new image digest after validation.
- Update
DefaultFirewallVersion in gh-aw if a new firewall release is cut.
Exception Governance
- Threat hypothesis: Exploitation of GO-2026-4337 via malicious input to the agent runtime
- Operational weakness: No patch applied; image in active use
- Expiry date: 2026-07-27
- Mitigation plan: Upgrade Go runtime → rebuild → re-pin
Governance report: UK AI Open Code Risk & Resilience Governance — Weekly Report 2026-07-24
References: §30107107922 · Container scan issue #47737
Generated by UK AI Operational Resilience · sonnet46 · 66.3 AIC · ⌖ 8.85 AIC · ⊞ 5.3K · ◷
🔴 Critical — Tier C: Restricted Pending Review
Source: UK AI Open Code Risk & Resilience Governance — weekly scan 2026-07-24
SLA: 3 days (by 2026-07-27)
Finding
The
ghcr.io/github/gh-aw-firewall/agent:0.27.41container image uses Gogo1.24.6, which is affected by a critical vulnerability:stdlibgo1.24.6Additionally there are 18 high-severity stdlib advisories all fixed by upgrading to
go1.24.12+ orgo1.25.6+. Total: 365 CVEs in the image (1 critical, 43 fixable). Digest drift also detected.Risk Scoring
Remediation Actions
≥go1.24.13(orgo1.25.7+).ghcr.io/github/gh-aw-firewall/agentwith updated Go toolchain.actions-lock.json/ container pin entries to new image digest after validation.DefaultFirewallVersioningh-awif a new firewall release is cut.Exception Governance
Governance report: UK AI Open Code Risk & Resilience Governance — Weekly Report 2026-07-24
References: §30107107922 · Container scan issue #47737