5.3
CVSS V3
Status
Impact
This CVE affects protobuf 3.20.3 used in kubeflow-pipelines metadata_writer component. The fix requires upgrading to protobuf 4.25.8+, which is a major version upgrade (3.x → 4.x) that upstream kubeflow-pipelines has not implemented yet. The upstream project still uses protobuf 3.20.3 in their main branch as of June 2025. We are waiting for upstream maintainers to implement this CVE fix to avoid breaking changes.
Status