carvel-dev / carvel-dev/ytt

HIGH CVE reported by Trivy scan tool for v0.53.2

Open
#981 1 comment 0 reactions 0 assignees View on GitHub
bug carvel accepted
Dominant language
Go
Stars
1.9k
Forks
167
PR merge metrics
No merged PRs in 30d

Description

The listed CVE for v0.53.2 includes HIGH.
@devanshuVmware Can you check and let us know when the new version with CVE fixes will be available? Our CI pipeline is currently blocked because of this High issues.
Vulnerabilities Summary

/usr/local/bin/ytt (gobinary)

**Summary:**
Total: **3** (HIGH: 1, MEDIUM: 1, LOW: 1)

---

### Details

| Library | CVE ID | Severity | Status | Installed Version | Fixed Version | Description |
|--------|----------------|----------|--------|-------------------|--------------------|------------|
| stdlib | CVE-2026-25679 | HIGH | Fixed | v1.25.7 | 1.25.8, 1.26.1 | net/url: Incorrect parsing of IPv6 host literals |
| stdlib | CVE-2026-27142 | MEDIUM | Fixed | v1.25.7 | - | html/template: URLs in meta content attributes not escaped |
| stdlib | CVE-2026-27139 | LOW | Fixed | v1.25.7 | - | os: FileInfo can escape from a Root |

---

Contributor guide

Open the contributing guide

Research direction

The report concerns /usr/local/bin/ytt in v0.53.2 and lists three Go standard-library CVEs, including one high-severity issue. Start by checking how the v0.53.2 binary is built and released, then verify the Go version and Trivy results. Done means a released ytt version no longer reports the listed vulnerabilities.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
cli, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.