/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-x45f-2frp-28pj

Published

Last updated

https://images.chainguard.dev/security/CGA-x45f-2frp-28pj
Package

keda-fips-2.16

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2025-30204
  • GHSA-mh63-6h87-95cp

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-30204

Updates

Status

Fix not planned

Impact

This vulnerability found in jwt 3.2.2 requires upgrading to a newer major version, jwt 4.x or 5.x. The Keda project has removed its dependency on jwt 3.x starting with version 2.17. Since Keda 2.16.x is now end of life and no longer receives upstream updates, it is recommended to upgrade to Keda 2.17.x or later.

Status

Affected

Impact

Govulncheck found vulnerable symbols in Go binaries at the following locations: in keda-fips-2.16-2.16.1-r11.apk, at usr/bin/keda, usr/bin/keda; in keda-fips-2.16-metrics-apiserver-2.16.1-r11.apk, at usr/bin/keda-adapter, usr/bin/keda-adapter.

Status

Under investigation


Safe Source for Open Source™
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing