ytt icon indicating copy to clipboard operation
ytt copied to clipboard

Multiple CVEs reported by Trivy scan tool for v0.52.1

Open Kisan-hpe opened this issue 2 months ago • 3 comments

The listed CVEs for v0.52.0 includes HIGH. @devanshuVmware Can you check and let us know when the new version with CVE fixes will be available? Our CI pipeline is currently blocked because of these issues. Vulnerabilities Summary

/usr/local/bin/ytt (gobinary)

Total: 10 (UNKNOWN: 0, LOW: 0, MEDIUM: 6, HIGH: 4, CRITICAL: 0)

Library Vulnerability Severity Status Installed Version Fixed Version Title
stdlib CVE-2025-58183 HIGH fixed 1.24.6 1.24.8, 1.25.2 golang: archive/tar: Unbounded allocation when parsing GNU sparse map
stdlib CVE-2025-58186 HIGH fixed 1.24.6 1.24.8, 1.25.2 Despite HTTP headers having a default limit of 1MB, the number of headers can cause memory issues
stdlib CVE-2025-58187 HIGH fixed 1.24.6 1.24.9, 1.25.3 Due to the design of the name constraint checking algorithm, invalid certificates may be accepted
stdlib CVE-2025-58188 HIGH fixed 1.24.6 1.24.8, 1.25.2 Validating certificate chains containing DSA public keys can cause unexpected behavior
stdlib CVE-2025-47912 MEDIUM fixed 1.24.6 1.24.8, 1.25.2 net/url: Insufficient validation of bracketed IPv6 hostnames
stdlib CVE-2025-58185 MEDIUM fixed 1.24.6 1.24.8, 1.25.2 encoding/asn1: Parsing DER payload can cause memory exhaustion
stdlib CVE-2025-58189 MEDIUM fixed 1.24.6 1.24.8, 1.25.2 crypto/tls: ALPN negotiation error may contain attacker-controlled information
stdlib CVE-2025-61723 MEDIUM fixed 1.24.6 1.24.8, 1.25.2 encoding/pem: Quadratic complexity when parsing some invalid inputs
stdlib CVE-2025-61724 MEDIUM fixed 1.24.6 1.24.8, 1.25.2 net/textproto: Excessive CPU consumption in Reader.ReadResponse
stdlib CVE-2025-61725 MEDIUM fixed 1.24.6 1.24.8, 1.25.2 net/mail: Excessive CPU consumption in ParseAddress

Kisan-hpe avatar Nov 12 '25 11:11 Kisan-hpe

@devanshuVmware Any updates on this issue?

Kisan-hpe avatar Nov 19 '25 05:11 Kisan-hpe

@devanshuVmware Any updates on this issue?

Hi @Kisan-hpe we bumped golang to 1.24.9 which fixes above listed CVEs https://github.com/carvel-dev/ytt/pull/968

Will create a release soon with the CVE fixes

devanshuVmware avatar Nov 19 '25 06:11 devanshuVmware

Hi, What is the status on this issue? Tks

perrigp-pen avatar Dec 08 '25 09:12 perrigp-pen

Hi @devanshuVmware Any updates on fixing this? we are blocked on this as most of these CVEs crossed SLA.

Kisan-hpe avatar Dec 15 '25 11:12 Kisan-hpe

Hi @devanshuVmware Any updates on fixing this? we are blocked on this as most of these CVEs crossed SLA.

@Kisan-hpe new version v0.52.2 has been released with the CVE fixes

devanshuVmware avatar Dec 16 '25 11:12 devanshuVmware