DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CGA-xx8w-2jx9-rh53

Published

Last updated

https://images.chainguard.dev/security/CGA-xx8w-2jx9-rh53
Package

k3s-1.33

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-64702
  • GHSA-g754-hx8w-x2g6

Severity

5.3

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-64702

Updates

Status

Pending upstream fix

Impact

The dependency github.com/k3s-io/k3s/pkg/spegel, which is a fork of the upstream Spegel module, transitively pulls in a vulnerable version of github.com/quic-go/quic-go. Attempting to upgrade github.com/quic-go/quic-go directly results in build failures. Remediation will require an upstream update to the Spegel fork.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing