DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-j7pc-mw92-593p

Package

wash

Component

rustls-webpki

Latest update

Pending upstream fix

Aliases

Severity

7.5

High

CVSS V3

Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://github.com/advisories/GHSA-82j2-j2ch-gfr8

Updates

Status

Pending upstream fix

Impact

rustls-webpki 0.101.7 is pulled into wash 0.39.0 via two upstream wasmcloud provider crates: wasmcloud-provider-blobstore-s3 0.12.0 → aws-smithy-runtime 1.7.8 → hyper-rustls 0.24.2 → rustls 0.21.12, and wasmcloud-provider-http-server 0.26.0 → axum-server 0.6.0 → rustls 0.21.12. GHSA-82j2-j2ch-gfr8 is only patched in rustls-webpki >= 0.103.13 (no 0.101.x or 0.102.x backport exists). Cannot fix until the wasmcloud-provider-* crates upstream bump their rustls/aws-smithy/axum-server dependency chain.

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.