Package
kube-controller-manager-fips-1.32-default-compat
Component
k8s.io/kubernetes
Latest update
6.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
CVE-2025-1767 does not affect the Kubernetes client or the core Kubernetes platform. This vulnerability is specifically related to the deprecated gitRepo volume feature, which is no longer maintained and will not receive security updates. Importantly, the issue lies in the git-repo volume provisioner, not the Kubernetes client itself.
Status
Impact
The k8s.io CVE affecting this package is currently in the triage stage upstream, PR on the issue can be found here: https://github.com/kubernetes/kubernetes/issues/130786
Status