/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-8xrc-697j-x68f

Published

Last updated

https://images.chainguard.dev/security/CGA-8xrc-697j-x68f
Package

grafana-pyroscope-1.13

RepositoryWolfi
Latest Update
Fixed
Fixed Version

1.13.5-r2

Aliases
  • CVE-2025-54576
  • GHSA-7rh7-c77v-6434

Severity

9.1

Critical

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-54576

Updates

Status

Fixed

Fixed version

1.13.5-r2

Status

Pending upstream fix

Impact

The oauth2-proxy is a transient dependency and any attempts to bump result in build failure. We will have to wait for upstream to work on bumping their dependency tree. There is currently an issue open upstream to try to bump this dependency but it is still a work in progress: https://github.com/grafana/pyroscope/pull/4335

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing