5.5
CVSS V3
Status
Justification
Impact
JuiceFS only uses etcd client libraries (go.etcd.io/etcd/client/v3) for connecting to external etcd clusters. This vulnerability affects etcd server components, which are not present in JuiceFS. Static analysis confirms no etcd server symbols exist in the binary, and govulncheck produces no findings. This CVE does not apply to JuiceFS client-only usage.
Status
Impact
This package must be removed from upstream dependencies. Upstream already consumes the fixed version, and trying to bump the vulnerable version will cause build failures due to duplication.
Status