kuma-2.8
Chainguard
Status
Impact
Kuma v2.7.16 depends on Helm v3.14.3, and upgrading to Helm v3.18.5 (which fixes the vulnerability) causes build failures due to API incompatibilities and updates to Kubernetes modules that introduce breaking changes. These issues stem from changes in function signatures and require upstream refactoring in Kuma to ensure compatibility, making it not feasible to fix the CVE in the current version without upstream changes.
Status