DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CGA-j2cp-8wmf-x724

Published

Last updated

https://images.chainguard.dev/security/CGA-j2cp-8wmf-x724
Package

sonarqube

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-67735
  • GHSA-84h7-rjj3-6jx4

Severity

6.5

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-67735

Updates

Status

Pending upstream fix

Impact

netty-codec-http is a transitive dependency from elasticsearch, which does not have have the fixed version of netty-codec-http. Upstream elasticsearch maintainer will need to release a version with netty-codec-http v4.1.129.Final or later.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing