volsync-fips
Chainguard
5.3
CVSS V3
Status
Impact
Depedency github.com/syncthing/syncthing pulls in a vulnerable version of github.com/quic-go/quic-go. github.com/syncthing/syncthing v1.3.0 is incompatible with patched github.com/quic-go/quic-go v0.57.0 and bumping either dependency directly causes build failures. Upstream has an open PR to remediate this CVE: https://github.com/backube/volsync/pull/1858.
Status