/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-4mx5-8jmv-wf2q

Published

Last updated

https://images.chainguard.dev/security/CGA-4mx5-8jmv-wf2q
Package

local-static-provisioner

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-5187
  • GHSA-4x4m-3c2p-qppc

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-5187

Updates

Status

Pending upstream fix

Impact

CVE-2025-5187 is fixed in version 1.31.12 onwards. However, upstream have explicitly pinned to 1.29.14 - 1.30 onwards includes incompatible API changes, so upstream will need to update the codebase to be able to use the newer versions

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing