/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-q8xj-545x-4rwh

Published

Last updated

https://images.chainguard.dev/security/CGA-q8xj-545x-4rwh
Package

zipkin

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-55163
  • GHSA-prj3-ccx8-p6x4

Severity

7.5

High

CVSS CVSS_V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-55163

Updates

Status

Pending upstream fix

Impact

Upgrading netty-codec-http2 to 4.1.124.Final to fix this CVE causes build failures due to missing netty-codec-http dependency. The compilation fails with "package io.netty.handler.codec.http does not exist" in the zipkin-storage-elasticsearch module. While netty-codec is present, the specific netty-codec-http package required for HTTP handling is not included in the dependencies. Upstream needs to properly configure the Netty dependencies to include both netty-codec-http2 and netty-codec-http with compatible versions before this security fix can be applied.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing