/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-hg69-mpw7-67wf

Published

Last updated

https://images.chainguard.dev/security/CGA-hg69-mpw7-67wf
Package

jitsucom-bulker

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-58187
  • GHSA-frhw-mqj2-wxw2

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-58187

Updates

Status

Pending upstream fix

Impact

The build using the remediated Go version is failing due to missing symbols. Upstream will need to migrate to a supported version of github.com/marcboeker/go-duckdb/mapping to resolve these issues and allow the build to succeed.

Status

Affected

Impact

Govulncheck found vulnerable symbols in Go binaries at the following locations: in jitsucom-bulker-bulker-2.11.0-r3.apk, at usr/bin/bulker, usr/bin/bulker; in jitsucom-bulker-ingest-2.11.0-r3.apk, at usr/bin/ingest, usr/bin/ingest; in jitsucom-bulker-ingmgr-2.11.0-r3.apk, at usr/bin/ingmgr, usr/bin/ingmgr; in jitsucom-bulker-sidecar-2.11.0-r3.apk, at usr/bin/sidecar, usr/bin/sidecar; in jitsucom-bulker-syncctl-2.11.0-r3.apk, at usr/bin/syncctl, usr/bin/syncctl.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing