5.3
CVSS V3
Status
Impact
quic-go 0.56.0 removed the logging and metrics packages which kubo depends upon, meaning builds against the fixed version (0.57.1) fail. To remediate this vulnerability, kubo upstream will need to adapt their code to the new quic-go API and cut a release.
Status
Impact
Govulncheck found vulnerable symbols in Go binaries at the following locations: in kubo-0.39.0-r1.apk, at usr/bin/ipfs, usr/bin/ipfs.
Status