DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CGA-r7p5-p42g-h7rf

Published

Last updated

https://images.chainguard.dev/security/CGA-r7p5-p42g-h7rf
Package

trivy-fips

Repository

Chainguard

Latest Update
Not affected
Aliases
  • CVE-2025-66564
  • GHSA-4qg8-fj49-pxjh

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-66564

Updates

Status

Not affected

Justification

Vulnerable code not in execute path

Impact

The vulnerable code comes from an indirect dependency and is not in the code execution path. This is raised by upstream, who concluded they are unaffected here, and was confirmed independently.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing