Package
kibana-9.3
Component
piscina
Latest update
Fixed version
9.3.8-r0
8.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
9.3.8-r0Status
Impact
The vulnerable piscina worker-pool dependency is a direct dependency pinned to the 3.x release line, which received no security backport for this issue. The fix is only available in piscina 4.9.3 and later — a major version upgrade that upstream has not adopted in any released version, with adoption currently blocked by API incompatibilities. This will resolve once upstream ships a release built against a fixed piscina version.
Status