/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-j6h3-wrvc-rhcc

Published

Last updated

https://images.chainguard.dev/security/CGA-j6h3-wrvc-rhcc
Package

grafana-pyroscope-1.12

Repository

Chainguard

Latest Update
Fixed
Fixed Version

1.12.2-r3

Aliases
  • CVE-2025-54576
  • GHSA-7rh7-c77v-6434

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-54576

Updates

Status

Fixed

Fixed version

1.12.2-r3

Status

Pending upstream fix

Impact

The oauth2-proxy is a transient dependency and any attempts to bump result in build failure. We will have to wait for upstream to work on bumping their dependency tree. There is currently an issue open upstream to try to bump this dependency but it is still a work in progress: https://github.com/grafana/pyroscope/pull/4335

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing