DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CGA-9jg2-hxq7-3f86

Published

Last updated

https://images.chainguard.dev/security/CGA-9jg2-hxq7-3f86
Package

k3s

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-67499
  • GHSA-jv3w-x3r3-g6rm

Severity

6.6

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-67499

Updates

Status

Pending upstream fix

Impact

Upstream currently relies on a fork of github.com/containernetworking/plugins (https://github.com/rancher/plugins), as referenced in the k3s build script (https://github.com/k3s-io/k3s/blob/8dac81b2a24e78ce4cf951c7788ea6a8d4a59aa7/scripts/build#L165). This fork has fallen behind the main repository. To remediate the vulnerability, upstream must first update the fork to version 1.9.0 or later and then update the corresponding dependency in k3s.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing