/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-w9jf-v97x-p8vf

Published

Last updated

https://images.chainguard.dev/security/CGA-w9jf-v97x-p8vf
Package

kubernetes-dns-node-cache

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-5187
  • GHSA-4x4m-3c2p-qppc

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-5187

Updates

Status

Pending upstream fix

Impact

This CVE is resolved in k8s.io/kubernetes/ v1.31.12 onwards. However, the upstream maintainers have used a replace directive in go.mod to explicitly pin to v1.30.12 as a result of an attempted upgrade causing issues. The upstream maintainers will need to resolve those issues before this dependency can be upgraded

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing