/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-8758-m7p7-vf5r

Published

Last updated

https://images.chainguard.dev/security/CGA-8758-m7p7-vf5r
Package

airflow-3

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-53643
  • GHSA-9548-qrrj-x5pj

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-53643

Updates

Status

Pending upstream fix

Impact

The vulnerability in aiohttp is introduced via a transitive dependency from the ray package (v2.47.1, latest). Remediation is pending upstream updates from ray and a subsequent airflow release that includes the updated ray version. In the interim, we have proactively updated aiohttp to v3.12.14 wherever feasible.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing