/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-g686-m3gr-g2wq

Published

Last updated

https://images.chainguard.dev/security/CGA-g686-m3gr-g2wq
Package

airflow-2

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-53643
  • GHSA-9548-qrrj-x5pj

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-53643

Updates

Status

Pending upstream fix

Impact

The vulnerability in aiohttp is introduced via a transitive dependency from the ray package (v2.47.1, latest). Remediation is pending upstream updates from ray and a subsequent airflow release that includes the updated ray version. In the interim, we have proactively updated aiohttp to v3.12.14 wherever feasible.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing