/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-r6jp-fj5x-gf48

Published

Last updated

https://images.chainguard.dev/security/CGA-r6jp-fj5x-gf48
Package

kubernetes-dns-node-cache-fips

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-5187
  • GHSA-4x4m-3c2p-qppc

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-5187

Updates

Status

Pending upstream fix

Impact

This CVE is resolved in k8s.io/kubernetes/ v1.31.12 onwards. However, the upstream maintainers have used a replace directive in go.mod to explicitly pin to v1.30.12 as a result of an attempted upgrade causing issues. The upstream maintainers will need to resolve those issues before this dependency can be upgraded

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing