DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CGA-c4gh-3fq4-f7qr

Published

Last updated

https://images.chainguard.dev/security/CGA-c4gh-3fq4-f7qr
Package

ipfs-cluster-fips

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-64702
  • GHSA-g754-hx8w-x2g6

Severity

5.3

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-64702

Updates

Status

Pending upstream fix

Impact

Updating github.com/quic-go/quic-go to v0.57.0 in ipfs-cluster v1.1.4 is blocked by dependency conflicts. The current go-libp2p v0.38.2 requires quic-go v0.48.1 and uses deprecated packages (logging, metrics) removed in v0.57.x. While go-libp2p v0.46.0 supports v0.57.1, ipfs-cluster v1.1.4 is incompatible. Await upstream ipfs-cluster release updating go-libp2p for compatibility.

Status

Affected

Impact

Govulncheck found vulnerable symbols in Go binaries at the following locations: in ipfs-cluster-fips-1.1.4-r7.apk, at usr/bin/ipfs-cluster-ctl, usr/bin/ipfs-cluster-ctl, usr/bin/ipfs-cluster-follow, usr/bin/ipfs-cluster-follow, usr/bin/ipfs-cluster-service, usr/bin/ipfs-cluster-service.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing