DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-pxfc-wpwr-xfc8

Package

falcoctl-fips-0.4

Component

oras.land/oras-go/v2

Latest update

Pending upstream fix

Aliases

Severity

Unknown
Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://github.com/advisories/GHSA-vh4v-2xq2-g5cg

Updates

Status

Pending upstream fix

Impact

falcoctl 0.4.0 depends on oras-go/v2 at the pre-release v2.0.0-rc.3. The fix for this vulnerability is available in oras-go/v2 v2.6.1, but adopting it requires source-level changes to falcoctl because the stabilized v2 API differs from the rc.3 API used by falcoctl's OCI push and pull code (the file.New, oras.TagN, and oras.Pack signatures changed). As a result, the package does not build with a direct dependency bump. Upstream falcoctl has adopted oras-go/v2 v2.6.1 on a later release line, but the change has not been released for the 0.4.x series. Remediation is pending an upstream falcoctl 0.4.x release that incorporates the updated oras-go/v2 dependency.

Reference: oras-go/v2 v2.6.1 release https://github.com/oras-project/oras-go/releases/tag/v2.6.1

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.