/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-795w-j5w8-fmg3

Published

Last updated

https://images.chainguard.dev/security/CGA-795w-j5w8-fmg3
Package

grafana-agent-operator

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-4673
  • GHSA-62jj-gr2r-5c34

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-4673

Updates

Status

Pending upstream fix

Impact

Currently grafana-agent-operator is dependent on golang 1.22. There is work upstream to bump the golang version to 1.24, and we are pending for upstream to cut a version with the new golang version in order to fix this CVE. More information can be found here: https://github.com/grafana/agent/commit/1d3100817f6c84454ee9155c7bdfe6008dd15ef8

Status

Affected

Impact

Govulncheck found vulnerable symbols in Go binaries at the following locations: in grafana-agent-operator-0.44.2-r37.apk, at usr/bin/grafana-agent-operator, usr/bin/grafana-agent-operator.

Status

Under investigation


Safe Source for Open Source™
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing