GoogleCloudPlatform / GoogleCloudPlatform/k8s-stackdriver

cm-sd-adapter image vulnerable to CVE-2026-27143

Open
#1,172 0 comments 0 reactions 1 assignee Claimed by @juli4n View on GitHub
Dominant language
Go
Stars
409
Forks
236
Avg merge
2h 34m
Merged PRs (30d)
9

Description

The vulnerability scanner for Google Artifact Registry reports that the cm-sd-adapter image `gcr.io/gke-release/custom-metrics-stackdriver-adapter:v0.16.5-gke.0` contains the vulnerability documented in CVE-2026-27143 based on the standard library in GO 1.26.1. The scanner rates the severity of this CVE as Critical.

The vulnerability is fixed in GO 1.26.2

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.