5.3
CVSS V3
Status
Impact
The dependency github.com/k3s-io/k3s/pkg/spegel, which is a fork of the upstream Spegel module, transitively pulls in a vulnerable version of github.com/quic-go/quic-go. Attempting to upgrade github.com/quic-go/quic-go directly results in build failures. Remediation will require an upstream update to the Spegel fork.
Status