/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-c739-mjf2-g6c3

Published

Last updated

https://images.chainguard.dev/security/CGA-c739-mjf2-g6c3
Package

kubeflow-pipelines

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-4565
  • GHSA-8qvm-5x2c-j2w7

Severity

5.3

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-4565

Updates

Status

Pending upstream fix

Impact

This CVE affects protobuf 3.20.3 used in kubeflow-pipelines metadata_writer component. The fix requires upgrading to protobuf 4.25.8+, which is a major version upgrade (3.x → 4.x) that upstream kubeflow-pipelines has not implemented yet. The upstream project still uses protobuf 3.20.3 in their main branch as of June 2025. We are waiting for upstream maintainers to implement this CVE fix to avoid breaking changes.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing