DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CGA-5p76-wm5c-xxjq

Published

Last updated

https://images.chainguard.dev/security/CGA-5p76-wm5c-xxjq
Package

undock

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-66506
  • GHSA-f83f-xpx7-ffpw

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-66506

Updates

Status

Pending upstream fix

Impact

Remediating GHSA-f83f-xpx7-ffpw requires upgrading github.com/sigstore/fulcio to 1.8.3. This bump introduces incompatible dependency versions causing build failures. Upstream will need to carefully update dependencies and make required code changes to fix this issue.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing