cockroachdb

Patched
Databases & Caching from mirror.gcr.io/cockroachdb/cockroach
Pull Reference
ghcr.io/verity-org/cockroachdb/cockroach
docker pull ghcr.io/verity-org/cockroachdb/cockroach
Copa-Patched Image

Patched in-place from the upstream image using Copa . OS-level vulnerabilities are fixed without rebuilding \u2014 same layers, same behavior, fewer CVEs.

Signed SLSA L3 SBOM Rekor
Verify this artifact
Cosign signature
cosign verify \
  --certificate-identity-regexp "https://github.com/verity-org/verity/.github/workflows/" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  ghcr.io/verity-org/cockroachdb/cockroach:v25.4.6
Build provenance
gh attestation verify \
  oci://ghcr.io/verity-org/cockroachdb/cockroach:v25.4.6 \
  --owner verity-org

Vulnerability Scan

Found 101 vulnerabilit ies in the original image. 1 fixed by Copa. 100 remaining after patching.

1CRITICAL8HIGH45MEDIUM47LOW

Fix available — pending patch

These vulnerabilities have upstream fixes but could not be automatically patched.

IDPackageInstalledFixedSeverity
CVE-2025-68121stdlibv1.23.121.24.13, 1.25.7, 1.26.0-rc.3 CRITICAL
CVE-2025-58183stdlibv1.23.121.24.8, 1.25.2 HIGH
CVE-2025-61726stdlibv1.23.121.24.12, 1.25.6 HIGH
CVE-2025-61728stdlibv1.23.121.24.12, 1.25.6 HIGH
CVE-2025-61729stdlibv1.23.121.24.11, 1.25.5 HIGH
CVE-2026-25679stdlibv1.23.121.25.8, 1.26.1 HIGH
CVE-2025-47912stdlibv1.23.121.24.8, 1.25.2 MEDIUM
CVE-2025-58185stdlibv1.23.121.24.8, 1.25.2 MEDIUM
CVE-2025-58186stdlibv1.23.121.24.8, 1.25.2 MEDIUM
CVE-2025-58187stdlibv1.23.121.24.9, 1.25.3 MEDIUM
CVE-2025-58188stdlibv1.23.121.24.8, 1.25.2 MEDIUM
CVE-2025-58189stdlibv1.23.121.24.8, 1.25.2 MEDIUM
CVE-2025-61723stdlibv1.23.121.24.8, 1.25.2 MEDIUM
CVE-2025-61724stdlibv1.23.121.24.8, 1.25.2 MEDIUM
CVE-2025-61725stdlibv1.23.121.24.8, 1.25.2 MEDIUM
CVE-2025-61727stdlibv1.23.121.24.11, 1.25.5 MEDIUM
CVE-2025-61730stdlibv1.23.121.24.12, 1.25.6 MEDIUM
CVE-2026-27142stdlibv1.23.121.25.8, 1.26.1 MEDIUM
CVE-2026-27139stdlibv1.23.121.25.8, 1.26.1 LOW

Awaiting upstream fix

No fix is available yet for these vulnerabilities.

IDPackageInstalledFixedSeverity
CVE-2026-4424libarchive3.5.3-7.el9_7 HIGH
CVE-2026-27135libnghttp21.43.0-6.el9 HIGH
CVE-2025-5278coreutils-single8.32-39.el9 MEDIUM
CVE-2025-14017curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-1965curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3783curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3784curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3805curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2025-14087glib22.68.4-18.el9_7.1 MEDIUM
CVE-2025-14512glib22.68.4-18.el9_7.1 MEDIUM
CVE-2026-1484glib22.68.4-18.el9_7.1 MEDIUM
CVE-2026-1489glib22.68.4-18.el9_7.1 MEDIUM
CVE-2026-4437glibc2.34-231.el9_7.10 MEDIUM
CVE-2026-4437glibc-common2.34-231.el9_7.10 MEDIUM
CVE-2026-4437glibc-minimal-langpack2.34-231.el9_7.10 MEDIUM
CVE-2025-68972gnupg22.3.3-5.el9_7 MEDIUM
CVE-2023-30571libarchive3.5.3-7.el9_7 MEDIUM
CVE-2025-60753libarchive3.5.3-7.el9_7 MEDIUM
CVE-2026-4426libarchive3.5.3-7.el9_7 MEDIUM
CVE-2026-5121libarchive3.5.3-7.el9_7 MEDIUM
CVE-2025-14017libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-1965libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3783libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3784libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3805libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-0990libxml22.9.13-14.el9_7 MEDIUM
CVE-2026-1757libxml22.9.13-14.el9_7 MEDIUM
CVE-2026-22185openldap2.6.8-4.el9 MEDIUM
CVE-2026-2100p11-kit0.25.3-3.el9_5 MEDIUM
CVE-2026-2100p11-kit-trust0.25.3-3.el9_5 MEDIUM
CVE-2026-29111systemd-libs252-55.el9_7.7 MEDIUM
CVE-2026-4105systemd-libs252-55.el9_7.7 MEDIUM
CVE-2005-2541tar2:1.34-9.el9_7 MEDIUM
CVE-2025-64118tar2:1.34-9.el9_7 MEDIUM
CVE-2026-33056tar2:1.34-9.el9_7 MEDIUM
CVE-2024-11053curl-minimal7.76.1-35.el9_7.3 LOW
CVE-2024-7264curl-minimal7.76.1-35.el9_7.3 LOW
CVE-2024-9681curl-minimal7.76.1-35.el9_7.3 LOW
CVE-2023-4156gawk5.1.0-6.el9 LOW
CVE-2023-32636glib22.68.4-18.el9_7.1 LOW
CVE-2025-3360glib22.68.4-18.el9_7.1 LOW
CVE-2025-7039glib22.68.4-18.el9_7.1 LOW
CVE-2026-0988glib22.68.4-18.el9_7.1 LOW
CVE-2026-1485glib22.68.4-18.el9_7.1 LOW
CVE-2026-4438glibc2.34-231.el9_7.10 LOW
CVE-2026-4438glibc-common2.34-231.el9_7.10 LOW
CVE-2026-4438glibc-minimal-langpack2.34-231.el9_7.10 LOW
CVE-2022-3219gnupg22.3.3-5.el9_7 LOW
CVE-2025-30258gnupg22.3.3-5.el9_7 LOW
CVE-2026-24883gnupg22.3.3-5.el9_7 LOW
CVE-2025-1632libarchive3.5.3-7.el9_7 LOW
CVE-2025-5915libarchive3.5.3-7.el9_7 LOW
CVE-2025-5916libarchive3.5.3-7.el9_7 LOW
CVE-2025-5917libarchive3.5.3-7.el9_7 LOW
CVE-2025-5918libarchive3.5.3-7.el9_7 LOW
CVE-2024-11053libcurl-minimal7.76.1-35.el9_7.3 LOW
CVE-2024-7264libcurl-minimal7.76.1-35.el9_7.3 LOW
CVE-2024-9681libcurl-minimal7.76.1-35.el9_7.3 LOW
CVE-2022-27943libgcc11.5.0-11.el9 LOW
CVE-2022-27943libstdc++11.5.0-11.el9 LOW
CVE-2025-13151libtasn14.16.0-9.el9 LOW
CVE-2023-45322libxml22.9.13-14.el9_7 LOW
CVE-2024-34459libxml22.9.13-14.el9_7 LOW
CVE-2025-27113libxml22.9.13-14.el9_7 LOW
CVE-2025-6170libxml22.9.13-14.el9_7 LOW
CVE-2026-0989libxml22.9.13-14.el9_7 LOW
CVE-2026-0992libxml22.9.13-14.el9_7 LOW
CVE-2023-50495ncurses-base6.2-12.20210508.el9 LOW
CVE-2023-50495ncurses-libs6.2-12.20210508.el9 LOW
CVE-2026-2673openssl-fips-provider3.0.7-8.el9 LOW
CVE-2026-2673openssl-fips-provider-so3.0.7-8.el9 LOW
CVE-2024-13176openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2024-41996openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2025-9232openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2026-2673openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2022-41409pcre210.40-6.el9 LOW
CVE-2022-41409pcre2-syntax10.40-6.el9 LOW
CVE-2024-0232sqlite-libs3.34.1-9.el9_7 LOW
CVE-2025-70873sqlite-libs3.34.1-9.el9_7 LOW
CVE-2023-39804tar2:1.34-9.el9_7 LOW
CVE-2026-27171zlib1.2.11-40.el9 LOW
Source
Copa (in-place patch)
Platforms
linux/amd64, linux/arm64
Registry
ghcr.io/verity-org
Upstream
mirror.gcr.io/cockroachdb/cockroach