forked from bitly/oauth2_proxy
-
Notifications
You must be signed in to change notification settings - Fork 152
Open
Description
Hi,
Our security scanner finds the following vulnerabilities in our oauth-proxy container image.
Is it possible for you to upgrade the dependencies to the fixed versions?
Thank you!
| Vulnerability | Severity | CVSS3 | Package | Current Version | Fixed in version |
|---|---|---|---|---|---|
| CVE-2025-61729 | Low | N/A | crypto/x509 | 1.25.3 | 1.24.11, 1.25.5 |
| CVE-2025-61727 | Low | N/A | crypto/x509 | 1.25.3 | 1.24.11, 1.25.5 |
The same CVEs were addressed in grafana by upgrading go-lang from 1.25.3 to 1.25.5 (grafana/grafana#114749).
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels