DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CGA-h7j9-83x5-fqr5

Published

Last updated

https://images.chainguard.dev/security/CGA-h7j9-83x5-fqr5
Package

kyverno-fips-1.16

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-66506
  • GHSA-f83f-xpx7-ffpw

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-66506

Updates

Status

Pending upstream fix

Impact

Updating Fulcio v1.8.3 requires sigstore/sigstore v1.10.0, which removed the cryptoutils.ValidatePubKey function that cosign v2.4.1 depends on. Migrating to cosign v3 would fix that incompatibility, but it's a major version upgrade that requires k8s.io v0.34.x—and upgrading to that version would break compatibility with k8s.io/api/networking/v1alpha1, which we depend on. Updating fulcio would force a cascade of breaking changes across the dependency chain. Upstream need substantial refactoring and API compatibility updates to make this work.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing