/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-c739-mjf2-g6c3

Published

Last updated

https://images.chainguard.dev/security/CGA-c739-mjf2-g6c3
Package

kubeflow-pipelines

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-4565
  • GHSA-8qvm-5x2c-j2w7

Severity

5.3

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-4565

Updates

Status

Pending upstream fix

Impact

This CVE affects protobuf 3.20.3 used in kubeflow-pipelines metadata_writer component. The fix requires upgrading to protobuf 4.25.8+, which is a major version upgrade (3.x → 4.x) that upstream kubeflow-pipelines has not implemented yet. The upstream project still uses protobuf 3.20.3 in their main branch as of June 2025. We are waiting for upstream maintainers to implement this CVE fix to avoid breaking changes.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing