DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-j8m4-vq7v-pr2f

Package

dotstatsuite-supercore

Component

stream-json

Latest update

Pending upstream fix

Aliases

Severity

6.2

Medium

CVSS V3

Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://nvd.nist.gov/vuln/detail/CVE-2026-71429

Updates

Status

Pending upstream fix

Impact

The fix is only available in stream-json 3.5.0 and later, which is an ESM-only release with a restructured module layout and a changed API. This package's only consumer of stream-json is the minio client, which requires stream-json/jsonl/Parser.js and calls its static make() method; neither exists in 3.x, so forcing the newer version makes the minio client fail to load. minio has not yet migrated to stream-json 3.x (its dependency update PR minio/minio-js#1497 fails on this same module-not-found error), and no fixed release exists on the 1.x line. This will be remediated when minio ships a release compatible with stream-json 3.5.0 or later.

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.