/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-cjj6-92vg-m522

Published

Last updated

https://images.chainguard.dev/security/CGA-cjj6-92vg-m522
Package

terraform

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-8959
  • GHSA-wjrx-6529-hcj3

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-8959

Updates

Status

Pending upstream fix

Impact

The vulnerability could not be remediated by upgrading go-getter because the newer version introduces an incompatibility with Terraform’s snapshotFS implementation. Specifically, the updated afero.Fs interface requires a Chown method that snapshotFS does not provide, causing compilation failures. Upstream must update the dependency tree and adapt snapshotFS (or related code) to the new afero API. Once upstream resolves this, we can upgrade go-getter and properly remediate the vulnerability.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing