-
Notifications
You must be signed in to change notification settings - Fork 212
Open
Labels
bugSomething isn't workingSomething isn't workingtriageNew issues or PRs to be acknowledged by maintainersNew issues or PRs to be acknowledged by maintainers
Description
What happened in your environment?
stdlib v1.25.0, that oras depends on, is affected by multiple CVEs. Here's a partial list.
- Go (Go) Security Update for stdlib (GO-2025-3955)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-47910 - Go (Go) Security Update for stdlib (GO-2025-4009)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61723 - Go (Go) Security Update for stdlib (GO-2025-4006)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61725 - Go (Go) Security Update for stdlib (GO-2025-4013)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-58188 - ...
Please bump the version of go to >= 1.25.2
What did you expect to happen?
No CVEs detected.
How can we reproduce it?
See links above for the details on vulnerabilities.
What is the version of your ORAS CLI?
v1.3.0
What is your OS environment?
Azure Linux 3
Are you willing to submit PRs to fix it?
- Yes, I am willing to fix it.
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't workingtriageNew issues or PRs to be acknowledged by maintainersNew issues or PRs to be acknowledged by maintainers