Security Advisories
This page lists Common Vulnerabilities and Exposures (CVEs) addressed in each Kloudfuse release, together with any HIGH or CRITICAL CVEs that remain unresolved pending upstream fixes. All Kloudfuse service images are scanned with Trivy and AWS Inspector after each release. For the raw scan reports, see the GCS security reports bucket.
For release-by-release feature and fix details, see also Release Notes.
About This Page
Rows are sorted CRITICAL → HIGH → MEDIUM → LOW within each table. CVE IDs link to the National Vulnerability Database, the Red Hat Security Advisory, or a GitHub Security Advisory. The Fixed In column shows what change (toolchain bump, dependency upgrade, base OS refresh) resolved the CVE. The Status column in the outstanding table explains why a fix is not yet available.
Release 4.3.0
Fixed CVEs (28 total — 4 Critical, 24 High)
| CVE | Severity | CVSS | Affected Component | Fixed In | Remediation |
|---|---|---|---|---|---|
CRITICAL |
9.2 |
|
snowflake-connector-python 4.7.3 |
Resolved by upgrading the pinned |
|
CRITICAL |
9.1 |
|
Datadog Agent 7.82.3 |
Envoy Gateway vulnerability resolved by upgrading the bundled Datadog Agent release, which carries envoyproxy/gateway forward from v1.7.1 to v1.7.4. |
|
CRITICAL |
9.1 |
|
netty 4.1.137.Final / 4.1.138.Final |
Heap overflow in netty’s DNS-over-HTTPS response parsing, resolved by upgrading the pinned netty version across the affected services. |
|
CRITICAL |
9.0 |
|
next 16.3.4 |
Unauthenticated remote code execution in the Next.js Image Optimization API, resolved by upgrading |
|
HIGH |
7.5 |
Go stdlib (all FIPS service images) |
Go 1.26.7 FIPS toolchain |
Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7 across all affected service images. |
|
HIGH |
8.2 |
Go stdlib (all FIPS service images) |
Go 1.26.7 FIPS toolchain |
Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7. |
|
HIGH |
7.5 |
Go stdlib (all FIPS service images) |
Go 1.26.7 FIPS toolchain |
Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7. |
|
HIGH |
7.5 |
Go stdlib (all FIPS service images) |
Go 1.26.7 FIPS toolchain |
Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7. |
|
HIGH |
8.1 |
Go stdlib (all FIPS service images) |
Go 1.26.7 FIPS toolchain |
Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7. |
|
HIGH |
7.5 |
Go stdlib (all FIPS service images) |
Go 1.26.7 FIPS toolchain |
Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7. |
|
HIGH |
7.5 |
Go stdlib (all FIPS service images) |
Go 1.26.7 FIPS toolchain |
Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7. |
|
HIGH |
7.5 |
Go stdlib (all FIPS service images) |
Go 1.26.7 FIPS toolchain |
Go standard library vulnerability resolved by upgrading the FIPS Go toolchain to Go 1.26.7. |
|
HIGH |
7.0 |
|
sharp 0.35.0 |
Arbitrary code execution vulnerability in the sharp image-processing library. Resolved by forcing the transitive dependency to version 0.35.0 or later. |
|
HIGH |
7.4 |
|
Datadog Agent 7.82.3 |
Envoy Gateway vulnerability resolved by upgrading the bundled Datadog Agent release, which carries envoyproxy/gateway forward from v1.7.1 to v1.7.4. |
|
HIGH |
7.5 |
|
Datadog Agent 7.82.3 |
Resolved by upgrading the bundled Datadog Agent release, which carries golang.org/x/net forward from v0.55.0 to v0.57.0. |
|
HIGH |
7.5 |
|
Datadog Agent 7.82.3 |
Resolved by upgrading the bundled Datadog Agent release, which carries golang.org/x/text forward from v0.37.0 to v0.40.0. |
|
HIGH |
8.8 |
|
Datadog Agent 7.82.3 |
Resolved by upgrading the bundled Datadog Agent release, which carries grpc forward from v1.81.1 to v1.82.1. |
|
HIGH |
8.7 |
|
grpc v1.83.2 |
A subsequent grpc HIGH CVE re-pinned directly to v1.83.2, since the Datadog Agent’s own vendored grpc release had not yet caught up. |
|
HIGH |
— |
|
grpc v1.83.2 |
Denial-of-service in grpc-go xDS servers, resolved by the same v1.83.2 re-pin as CVE-2026-84304. |
|
HIGH |
8.8 |
|
Datadog Agent 7.82.3 |
Resolved by upgrading the bundled Datadog Agent release, which migrated off the vulnerable v1 containerd module entirely in favor of containerd/containerd/v2. |
|
HIGH |
7.5 / 8.8 |
|
golang.org/x/mod 0.40.0 |
The Datadog Agent 7.82.3 release did not fully carry this dependency forward, so it was patched directly to version 0.40.0. |
|
HIGH |
7.5 |
|
jline 3.30.14 |
Resolved by upgrading the pinned |
|
HIGH |
7.5 |
|
httpcore5 5.4.3 |
Denial of service via oversized HTTP/2 HPACK header blocks, resolved by bumping the pinned |
|
HIGH |
7.5 |
|
httpcore5 5.4.3 |
Resolved by the same |
|
HIGH |
7.5 |
|
netty 4.1.137.Final |
Resolved by the same pinned netty version bump that addressed the httpcore5 and jline CVEs above. |
|
HIGH |
8.2 |
|
mysql2 3.22.0 |
Auth-plugin downgrade in |
|
HIGH |
7.5 |
|
nodemailer 9.1.1 |
Quadratic-time denial of service in nodemailer’s address parser, resolved by upgrading the pinned dependency. |
|
HIGH |
7.5 |
|
RHEL 9.8 errata base image refresh |
Resolved by refreshing the |
Outstanding CVEs (High / Critical)
| CVE | Severity | Affected Component | Status & Rationale |
|---|---|---|---|
CRITICAL |
|
Blocked by an upstream Grafana dependency pin that has not yet been updated. |
|
CRITICAL |
|
Deferred pending a full Grafana version upgrade, rather than patching individual transitive dependencies piecemeal. |
|
HIGH |
|
Same upstream Grafana dependency pin as above. |
|
HIGH |
|
Same upstream Grafana dependency pin as above. |
|
HIGH |
|
Same Grafana version-upgrade deferral as above. This CVE is already fixed for datadog-agent — see the Fixed CVEs table. |
|
HIGH |
|
Same as above. |
|
HIGH |
|
Same Grafana version-upgrade deferral as above. This CVE is already fixed for datadog-agent and the FIPS service images — see the Fixed CVEs table. |
|
HIGH |
|
Same Grafana version-upgrade deferral as above. This CVE is already fixed for datadog-agent — see the Fixed CVEs table. |
|
HIGH |
|
Same Grafana version-upgrade deferral as above. |
|
HIGH |
|
Tracks the same upstream dependency chain as the prometheus CVEs below. |
|
HIGH |
|
Tracks the same upstream dependency chain as the prometheus CVEs below. |
|
HIGH |
|
Requires a coordinated dependency upgrade with compatibility validation before it can be applied. |
|
HIGH |
|
Same as above. |
|
HIGH |
|
Fix requires a major-version upgrade (3.x to 4.x); deliberately not attempted this cycle. |
|
HIGH |
|
No fixed version has been published as a consumable Go module — the fix corresponds to a Docker product release, not a Go module tag currently available upstream. |
|
HIGH |
|
Same as above. |
|
HIGH |
|
Same as above. |
|
HIGH |
|
|
|
HIGH |
|
Same separate Amazon Linux 2023 base image as above. |
|
HIGH |
|
Same separate Amazon Linux 2023 base image as above. |
|
HIGH |
|
Not yet published by Red Hat for the RHEL 9.8 stream. |
|
HIGH |
|
Not yet published by Red Hat for the RHEL 9.8 stream. |
|
HIGH |
|
Not yet published by Red Hat for the RHEL 9.8 stream. |
|
HIGH |
|
Not yet published by Red Hat for the RHEL 9.8 stream. |
|
HIGH |
|
Not yet published by Red Hat for the RHEL 9.8 stream. |