/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-x4vv-4qx8-xm22

Published

Last updated

https://images.chainguard.dev/security/CGA-x4vv-4qx8-xm22
Package

kuma-2.7

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-53547
  • GHSA-557j-xg8c-q2mm

Severity

8.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-53547

Updates

Status

Pending upstream fix

Impact

The helm.sh/helm/v3 dependency at version 3.14.3 contains a vulnerability that is fixed in v3.18.4. It wasn't possible to bump the dependency without a proper fix from upstream. Resolution from upstream requires code changes and several dependencies alignments. Once this is done, we will patch and remediate the CVE for this package.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing