gitlab-runner-17.9
Chainguard
8.1
CVSS V3
Status
Justification
Impact
The GHSA-gh5c-3h97-2f3q vulnerability was incorrectly marked as affecting versions earlier than 26.0.0. The issue was actually addressed in version 25.0.4 and later. The GHSA entry has been updated to reflect the correct version: GHSA-gh5c-3h97-2f3q.
Status
Status
Impact
gitlab-runner-17.9.1 uses Docker 25.0.6, as seen here: https://gitlab.com/gitlab-org/gitlab-runner/-/blob/v17.9.1/go.mod?ref_type=tags#L31 The fixed version to remediate this CVE is 26.0.0; however, breaking changes between these major versions require upstream maintainers to implement compatibility.