/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-rjrp-m6fc-6jrg

Published

Last updated

https://images.chainguard.dev/security/CGA-rjrp-m6fc-6jrg
Package

local-static-provisioner-fips

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-5187
  • GHSA-4x4m-3c2p-qppc

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-5187

Updates

Status

Pending upstream fix

Impact

CVE-2025-5187 is fixed in version 1.31.12 onwards. However, upstream have explicitly pinned to 1.29.14 - 1.30 onwards includes incompatible API changes, so upstream will need to update the codebase to be able to use the newer versions

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing