What happened:
Security scanning of external‑snapshotter v8.2.0 container images (e.g., registry.k8s.io/sig-storage/snapshot-controller:v8.2.0 and registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0) reports multiple vulnerabilities in the Go standard library.
Impacted CVEs (as reported by scanners):
CVE‑2025‑61724
CVE‑2025‑61723
CVE‑2025‑58189
CVE‑2025‑58188
CVE‑2025‑58187
CVE‑2025‑47912
CVE‑2025‑58185
CVE‑2025‑61727
CVE‑2025‑61729
These are Go stdlib vulnerabilities, not issues in external‑snapshotter business logic. The fix is to rebuild binaries with a patched Go toolchain.
The Go security team states these issues are addressed in Go 1.24.8 (and 1.25.2).
What you expected to happen:
How to reproduce it:
Anything else we need to know?:
Environment:
- Driver version:
- Kubernetes version (use
kubectl version):
- OS (e.g. from /etc/os-release):
- Kernel (e.g.
uname -a):
- Install tools:
- Others:
What happened:
Security scanning of external‑snapshotter v8.2.0 container images (e.g., registry.k8s.io/sig-storage/snapshot-controller:v8.2.0 and registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0) reports multiple vulnerabilities in the Go standard library.
Impacted CVEs (as reported by scanners):
CVE‑2025‑61724
CVE‑2025‑61723
CVE‑2025‑58189
CVE‑2025‑58188
CVE‑2025‑58187
CVE‑2025‑47912
CVE‑2025‑58185
CVE‑2025‑61727
CVE‑2025‑61729
These are Go stdlib vulnerabilities, not issues in external‑snapshotter business logic. The fix is to rebuild binaries with a patched Go toolchain.
The Go security team states these issues are addressed in Go 1.24.8 (and 1.25.2).
What you expected to happen:
How to reproduce it:
Anything else we need to know?:
Environment:
kubectl version):uname -a):