The latest packer binary (installed via apt.releases.hashicorp.com) contains
two Critical CVEs identified by Trivy:
| CVE |
Severity |
Component |
Installed |
Fixed in |
| CVE-2025-68121 |
Critical |
stdlib (Go) |
1.24.12 |
1.24.13, 1.25.7, 1.26.0-rc.3 |
| CVE-2026-33186 |
Critical |
google.golang.org/grpc |
v1.59.0 |
1.79.3 |
Could you please:
- recompile packer with Go ≥ 1.24.13 or ≥ 1.25.7
- bump
google.golang.org/grpc to ≥ 1.79.3
The latest packer binary (installed via
apt.releases.hashicorp.com) containstwo Critical CVEs identified by Trivy:
Could you please:
google.golang.org/grpcto ≥ 1.79.3