Skip to content

Security: packer compiled with dependancy containing critical CVEs#13678

Description

@securepii-dev

Community Note

  • Please vote on this issue by adding a 馃憤 reaction to the original issue to help the community and maintainers prioritize this request
  • Please do not leave "+1" or other comments that do not add relevant new information or questions, they generate extra noise for issue followers and do not help prioritize the request
  • If you are interested in working on this issue or have submitted a pull request, please leave a comment

The latest packer binary (installed from https://releases.hashicorp.com/packer/xxxxx/packer_xxxxx_linux_amd64.zip) contains two Critical CVEs identified by AWS Inspector:

CVE Severity
CVE-2026-50195 Critical
CVE-2026-53492 Critical

They are both related to github.com/containerd/containerd/v2 and are fixed in versions 2.3.2, 2.2.5 and 2.1.9

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions