Skip to content

ACK Detected Controllers CVEs #2428

@ack-bot

Description

@ack-bot
CVE ID Type Severity Installed Version Fixed Version Affected Controllers Title
CVE-2025-22871 gobinary MEDIUM 1.24.1 1.23.8, 1.24.2 [apigatewayv2 ecs mq opensearchservice networkfirewall pipes prometheusservice ram ses wafv2 ec2 elasticache acmpca cloudwatchlogs cognitoidentityprovider memorydb organizations route53 applicationautoscaling athena kms recyclebin s3control sfn ecr ecrpublic emrcontainers route53resolver secretsmanager sqs ssm cloudtrail kafka kinesis keyspaces s3 sagemaker sns documentdb cloudfront cloudwatch codeartifact acm efs elbv2 eventbridge iam lambda] net/http: Request smuggling due to acceptance of invalid chunked data in net/http
CVE-2025-22870 gobinary MEDIUM v0.33.0 0.36.0 [acmpca memorydb organizations efs] golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net
CVE-2025-22866 gobinary MEDIUM 1.23.5 1.22.12, 1.23.6, 1.24.0-rc.3 [memorydb] crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/cveCategorizes issue or PR as related to CVE.prow/auto-genPRs related to prow auto generation automation

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions