Skip to content

The unleash-proxy:latest Docker image contains vulnerable OpenSSL packages affected by CVE-2025-15467 (Critical severity). #219

@jakeybrown92

Description

@jakeybrown92

Describe the bug

Current versions

  • libcrypto3: 3.5.4-r0 (vulnerable)
  • libssl3: 3.5.4-r0 (vulnerable)

Required versions

  • libcrypto3: 3.5.5-r0+
  • libssl3: 3.5.5-r0+

Fix

Rebuild the Docker image to pull updated Alpine packages. The Dockerfile already has apk upgrade, just needs a fresh build.

CVE Details

https://www.cve.org/CVERecord?id=CVE-2025-15467

Steps to reproduce the bug

No response

Expected behavior

No response

Logs, error output, etc.

Screenshots

No response

Additional context

No response

Unleash version

No response

Subscription type

None

Hosting type

None

SDK information (language and version)

No response

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

Status

Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions