/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-847r-2v6v-qpvq

Published

Last updated

https://images.chainguard.dev/security/CGA-847r-2v6v-qpvq
Package

vault-fips-1.20

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2025-12044
  • GHSA-vp5w-xcfc-73wf

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-12044

Updates

Status

Fix not planned

Impact

vault-fips-1.20 is EOL (https://endoflife.date/hashicorp-vault) and the fix commits for remediating this CVE don't apply cleanly to the 1.20 tag.

Status

Fix not planned

Impact

This package is no longer supported upstream and has reached its end of life. A dependency upgrade to fix this vulnerability failed when building this package.

Status

Under investigation


Safe Source for Open Source™
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing