cg
Chainguard
7.5
CVSS V3
Status
Impact
We tried remediating this CVE by using a newer, fixed version of the go module, however the vulnerable version still gets pulled by transitive dependencies at build time. The different upstreams, for the main package and the transitive dependencies, should update and release fixed versions before we can consider this CVE fixed.
Status