DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CGA-36rj-px8c-hmv2

Published

Last updated

https://images.chainguard.dev/security/CGA-36rj-px8c-hmv2
Package

dbgate-fips

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-65945
  • GHSA-869p-cjfg-cm3x

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-65945

Updates

Status

Pending upstream fix

Impact

This vulnerability affects jws @ 3.2.2, a transitive dependency brought in via jsonwebtoken @ 8.5.1 in packages/api. The fix requires upgrading jsonwebtoken from 8.5.1 to 9.0.3+, which upgrades jws from 3.2.2 to 4.0.1 (fixed version). Upstream dbgate maintainers have an open PR (#443) from December 2022 to upgrade jsonwebtoken to 9.0.0, but it remains unmerged. Additionally, many automated dependabot PRs attempting the same upgrade are also unmerged. We are deferring to upstream to merge the jsonwebtoken upgrade rather than applying it independently, as the 2+ year delay suggests potential compatibility concerns or testing requirements we cannot fully evaluate. Reference: https://github.com/dbgate/dbgate/pull/443


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing