Package
calico-node-3.29
Component
k8s.io/kubernetes
Latest update
6.7
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerability cannot be remediated at this time because upgrading the dependency is not possible without breaking the build. The affected component still relies on deprecated Kubernetes APIs, and the current code is incompatible with k8s.io v1.31. Upstream needs to properly refactor and align the implementation with the v1.31 API surface. Once upstream completes this alignment, we can upgrade the dependency chain and remediate the CVE.
Status