{"id":"CGA-mxp2-vmg9-xf22","modified":"2026-07-17T19:12:56.123601244Z","published":"2025-10-30T19:56:46Z","upstream":["CVE-2025-49140","GHSA-f26w-gh5m-qq77","GO-2025-3748"],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49140.json"},{"type":"ADVISORY","url":"https://github.com/pion/interceptor/security/advisories/GHSA-f26w-gh5m-qq77"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49140"},{"type":"REPORT","url":"https://github.com/pion/webrtc/issues/3148"},{"type":"FIX","url":"https://github.com/pion/interceptor/commit/fa5b35ea867389cec33a9c82fffbd459ca8958e5"},{"type":"FIX","url":"https://github.com/pion/interceptor/pull/338"}],"affected":[{"package":{"name":"ipfs-cluster-fips-compat","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/ipfs-cluster-fips-compat?arch=aarch64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.4-r2"}]}],"ecosystem_specific":{"components":[{"architecture":"aarch64","component_name":"github.com/pion/interceptor","component_version":"v0.1.37","component_type":"go-module","component_location":"/usr/bin/ipfs-cluster-ctl","component_purl":"pkg:golang/github.com/pion/interceptor@v0.1.37","latest_event_status":"fixed","latest_event_timestamp":"2025-06-11T08:14:38Z"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-mxp2-vmg9-xf22.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}