DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CGA-w44m-vv7q-9c9p

Published

Last updated

https://images.chainguard.dev/security/CGA-w44m-vv7q-9c9p
Package

dbgate

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-65945
  • GHSA-869p-cjfg-cm3x

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-65945

Updates

Status

Pending upstream fix

Impact

This vulnerability affects jws @ 3.2.2, a transitive dependency brought in via jsonwebtoken @ 8.5.1 in packages/api. The fix requires upgrading jsonwebtoken from 8.5.1 to 9.0.3+, which upgrades jws from 3.2.2 to 4.0.1 (fixed version). Upstream dbgate maintainers have an open PR (#443) from December 2022 to upgrade jsonwebtoken to 9.0.0, but it remains unmerged. Additionally, many automated dependabot PRs attempting the same upgrade are also unmerged. We are deferring to upstream to merge the jsonwebtoken upgrade rather than applying it independently, as the 2+ year delay suggests potential compatibility concerns or testing requirements we cannot fully evaluate. Reference: https://github.com/dbgate/dbgate/pull/443

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing