/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-jpv5-vvg9-c274

Published

Last updated

https://images.chainguard.dev/security/CGA-jpv5-vvg9-c274
Package

bind

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2025-40776
  • GHSA-2hm8-9847-q7gc

Severity

8.6

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-40776

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

CVE-2025-40776 affects only BIND Subscription Edition (-S) versions including 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1. The Wolfi bind package version 9.20.11-r1 is the open-source edition and is not affected by this vulnerability which specifically targets the commercial Subscription Edition with ECS (EDNS Client Subnet) configuration.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing