/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-mc58-mxcf-6c3r

Published

Last updated

https://images.chainguard.dev/security/CGA-mc58-mxcf-6c3r
Package

celeborn-0.5

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-55163
  • GHSA-prj3-ccx8-p6x4

Severity

7.5

High

CVSS CVSS_V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-55163

Updates

Status

Pending upstream fix

Impact

The identified vulnerability originates from the netty-codec-http2 dependency, which can be remediated by upgrading to version 4.1.124.Final. However, direct upgrades introduce cascading dependency resolution issues that cause build failures. Upstream must properly realign and update the dependency tree to ensure compatibility. Once this is addressed at the upstream level, we can safely apply the upgrade and remediate the vulnerability.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing