Skip to content

Conversation

@wiz-betterup
Copy link

@wiz-betterup wiz-betterup bot commented Dec 9, 2025

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 103 findings detected in this project

Changes were made to the following file(s):

  • /balancer/go.mod
  • /cluster-autoscaler/go.mod
  • /vertical-pod-autoscaler/e2e/go.mod
  • /vertical-pod-autoscaler/go.mod

Vulnerabilities:

Component Findings Locations
github.com/docker/distribution
2.8.1+incompatible → 2.8.2-beta.1
Medium CVE-2023-2253 /cluster-autoscaler/go.mod
/vertical-pod-autoscaler/e2e/go.mod
github.com/golang-jwt/jwt/v4
4.4.2 → 4.5.2
High CVE-2025-30204
Low CVE-2024-51744
/cluster-autoscaler/go.mod
github.com/opencontainers/runc
1.1.4 → 1.2.8
High CVE-2025-52881
High CVE-2023-28642
High CVE-2024-21626
High CVE-2023-27561
High CVE-2025-31133
High CVE-2025-52565
Medium CVE-2023-25809
Low CVE-2024-45310
/cluster-autoscaler/go.mod
/vertical-pod-autoscaler/e2e/go.mod
github.com/opencontainers/selinux
1.10.0 → 1.13.0
High CVE-2025-52881 /cluster-autoscaler/go.mod
/vertical-pod-autoscaler/e2e/go.mod
github.com/sirupsen/logrus
1.8.1 → 1.8.3
High CVE-2025-65637 /vertical-pod-autoscaler/e2e/go.mod
github.com/sirupsen/logrus
1.9.0 → 1.9.1
High CVE-2025-65637 /cluster-autoscaler/go.mod
go.opentelemetry.io/contrib/instrumentat-
ion/github.com/emicklei/go-restful/otelr-
estful

0.35.0 → 0.44.0
High CVE-2023-45142 /cluster-autoscaler/go.mod
/vertical-pod-autoscaler/e2e/go.mod
go.opentelemetry.io/contrib/instrumentat-
ion/google.golang.org/grpc/otelgrpc

0.40.0 → 0.46.0
High CVE-2023-47108 /cluster-autoscaler/go.mod
go.opentelemetry.io/contrib/instrumentat-
ion/net/http/otelhttp

0.35.0 → 0.44.0
High CVE-2023-45142 /vertical-pod-autoscaler/e2e/go.mod
go.opentelemetry.io/contrib/instrumentat-
ion/net/http/otelhttp

0.40.0 → 0.44.0
High CVE-2023-45142 /cluster-autoscaler/go.mod
golang.org/x/crypto
0.1.0 → 0.45.0
Critical CVE-2024-45337
High CVE-2025-22869
Medium CVE-2023-48795
Medium CVE-2025-47914
Medium CVE-2025-58181
/vertical-pod-autoscaler/e2e/go.mod
golang.org/x/crypto
0.8.0 → 0.45.0
Critical CVE-2024-45337
High CVE-2025-22869
Medium CVE-2025-47914
Medium CVE-2025-58181
Medium CVE-2023-48795
/cluster-autoscaler/go.mod
golang.org/x/net
0.0.0-20220722155237-a158d28d115b → 0.38.0
High CVE-2023-45288
High CVE-2022-41723
High CVE-2022-27664
High CVE-2023-44487
High CVE-2023-39325
High CVE-2022-41721
Medium CVE-2025-22870
Medium CVE-2025-22872
Medium CVE-2023-3978
Medium CVE-2022-41717
/balancer/go.mod
golang.org/x/net
0.3.1-0.20221206200815-1e63c2f08a10 → 0.38.0
High CVE-2023-39325
High CVE-2023-45288
High CVE-2023-44487
High CVE-2022-41723
Medium CVE-2023-3978
Medium CVE-2025-22872
Medium CVE-2025-22870
Medium CVE-2022-41717
/vertical-pod-autoscaler/e2e/go.mod
golang.org/x/net
0.8.0 → 0.38.0
High CVE-2023-45288
High CVE-2023-44487
High CVE-2023-39325
Medium CVE-2025-22872
Medium CVE-2023-3978
Medium CVE-2025-22870
/vertical-pod-autoscaler/go.mod
golang.org/x/net
0.9.0 → 0.38.0
High CVE-2023-45288
High CVE-2023-39325
High CVE-2023-44487
Medium CVE-2025-22870
Medium CVE-2025-22872
Medium CVE-2023-3978
/cluster-autoscaler/go.mod
golang.org/x/oauth2
0.0.0-20211104180415-d3ed0bb246c8 → 0.27.0
High CVE-2025-22868 /balancer/go.mod
golang.org/x/oauth2
0.0.0-20220223155221-ee480838109b → 0.27.0
High CVE-2025-22868 /vertical-pod-autoscaler/e2e/go.mod
/vertical-pod-autoscaler/go.mod
golang.org/x/oauth2
0.7.0 → 0.27.0
High CVE-2025-22868 /cluster-autoscaler/go.mod
golang.org/x/text
0.3.7 → 0.3.8
High CVE-2022-32149 /balancer/go.mod
google.golang.org/grpc
1.49.0 → 1.56.3
High GHSA-m425-mq94-257g /vertical-pod-autoscaler/e2e/go.mod
google.golang.org/grpc
1.54.0 → 1.56.3
High GHSA-m425-mq94-257g /cluster-autoscaler/go.mod
google.golang.org/protobuf
1.28.0 → 1.33.0
High CVE-2024-24786 /balancer/go.mod
google.golang.org/protobuf
1.28.1 → 1.33.0
High CVE-2024-24786 /vertical-pod-autoscaler/e2e/go.mod
/vertical-pod-autoscaler/go.mod
google.golang.org/protobuf
1.30.0 → 1.33.0
High CVE-2024-24786 /cluster-autoscaler/go.mod
k8s.io/kubernetes
1.26.1 → 1.31.12
High CVE-2024-10220
High CVE-2023-3955
High CVE-2023-3676
High CVE-2023-5528
High CVE-2024-0793
Medium CVE-2023-2728
Medium CVE-2025-5187
Medium CVE-2025-0426
Medium CVE-2023-2727
Medium CVE-2024-5321
Medium CVE-2023-2431
Low CVE-2024-3177
/vertical-pod-autoscaler/e2e/go.mod
k8s.io/kubernetes
1.27.0 → 1.31.12
High CVE-2023-5528
High CVE-2024-10220
High CVE-2023-3676
High CVE-2023-3955
Medium CVE-2023-2727
Medium CVE-2023-2728
Medium CVE-2024-5321
Medium CVE-2025-0426
Medium CVE-2025-5187
Medium CVE-2023-2431
Low CVE-2024-3177
/cluster-autoscaler/go.mod

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants