Skip to content

Vulnerablities in node-cache version 1.26.5 #720

@K-Cuttler

Description

@K-Cuttler

A few vulnerabilities are present in the mentioned version, information is below:

           PACKAGE             TYPE   VERSION   SUGGESTED FIX  CRITICAL  HIGH  MEDIUM  LOW  NEGLIGIBLE  EXPLOIT  
  github.com/coredns/coredns  golang  v1.12.2      v1.12.4        0       1      0      0       0          0     
  k8s.io/kubernetes           golang  v1.30.12    v1.31.12        0       0      3      0       0          0 

Coredns is associated with: CVE-2025-58063 and Kubernetes with CVE-2025-5187. A fix in HEAD is available for the Kubernetes version but not the coredns version. Coredns has releases an upstream version: v1.12.4 that fixes the vulnerability.

Metadata

Metadata

Assignees

No one assigned

    Labels

    lifecycle/rottenDenotes an issue or PR that has aged beyond stale and will be auto-closed.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions