DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-vp75-xwqg-6wfg

Package

eks-distro-kube-proxy-1.32

Component

github.com/google/cel-go

Latest update

Fix not planned

Aliases

Severity

Unknown
Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://github.com/advisories/GHSA-gcjh-h69q-9w9g

Updates

Status

Fix not planned

Impact

The kube-apiserver, kube-controller-manager, kube-proxy and kube-scheduler binaries are built from the Kubernetes 1.32 source tree, which pins github.com/google/cel-go v0.22.0. GHSA-gcjh-h69q-9w9g is fixed only in cel-go v0.29.0, whose ext.TwoVarComprehensions API is compatible only with Kubernetes >= 1.33 apiserver; forcing v0.29.0 onto the 1.32 build fails to compile, and cel-go v0.22.0 is intrinsic to the 1.32 codebase. Kubernetes 1.32 is upstream end-of-life and the cel-go fix has not been backported to the 1.32 series, so no fix will be provided for this stream. Remediation requires upgrading to a newer Kubernetes minor (>= 1.33). This mirrors the fix-not-planned disposition already recorded on the canonical kubernetes-1.32 / kube-apiserver-1.32 packages.

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.