We found base image Vulnerabilities on temporalio/ui:2.49.1 image. Due to this we are unable deploy to our self hosted environment. Can someone look into this and rebuild the image?
CVE: CVE-2026-3805
Maybe your process is a bit too strict? This vulnerability is a use after free in curl when doing two calls to the same host using SMB. Exploitability in the case of temporal UI container is very unlikely.
I believe these vulnerabilities are propagating down from the base image that temporal UI is using. Once you rebuild your image with updated base image, it should go away.
More High Vulnerabilities started showing up on this image. This time it’s from net package from Go language. Could you please let me know when we are going release the latest version?