Skip to content

Issue with CVE-2025-22874 related to crypto/x509 go package used in nginx prometheus exporter #1109

@sainikhil-1903

Description

@sainikhil-1903

Describe the bug
Issue with CVE-2025-22874 related to crypto/x509 go package used in nginx prometheus exporter.
Link to the CVE :
https://access.redhat.com/security/cve/cve-2025-22874
https://pkg.go.dev/vuln/GO-2025-3749

Expected behavior
Currently Go lang version used in 1.4.2 version is 1.24.2, CVE is fixed once Go lang version is upgraded to more than 1.24.4

Your environment

  • Version of the Prometheus exporter - 1.4.2
  • Using NGINX and NGINX Plus - both

Additional context
Add any other context about the problem here. Any log files you want to share.

Metadata

Metadata

Assignees

No one assigned

    Labels

    communityIssues or PRs opened by an external contributor

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions