/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-2rhm-pq9f-wfvc

Published

Last updated

https://images.chainguard.dev/security/CGA-2rhm-pq9f-wfvc
Package

apache-nifi-registry

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-55163
  • GHSA-prj3-ccx8-p6x4

Severity

7.5

High

CVSS CVSS_V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-55163

Updates

Status

Pending upstream fix

Impact

The fix for this CVE requires upgrading netty-codec-http2 to 4.2.4.Final. However, this dependency is bundled as part of the AWS extension JAR and cannot be independently updated through dependency management. Cherry-picking the upstream fix (commit ccd3c4e2c4fe7f78aa2c214b3f953540e63e7066) introduces 2.6.0-SNAPSHOT dependencies that break the build, as this version is not yet released and the SNAPSHOT artifacts are not available in Maven repositories. We need to wait for Apache NiFi 2.6.0 to be officially released before we can apply this security fix.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing