/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-p42h-78rh-746q

Published

Last updated

https://images.chainguard.dev/security/CGA-p42h-78rh-746q
Package

wso2is

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-48795
  • GHSA-36wv-v2qp-v4g4

Severity

5.6

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-48795

Updates

Status

Pending upstream fix

Impact

The vulnerability in cxf-core (< 3.5.11) originates from a transitive dependency introduced via carbon-deployment (https://github.com/wso2/carbon-deployment). Although a fix is available in version 3.5.11 and above, enforcing this upgrade at the product root level was unsuccessful. Upstream must update the dependency to resolve the issue, after which we can proceed with remediation.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing