Skip to content

Vulnerabilities Identified in VPA release 1.3.0 #8014

@san4ever

Description

@san4ever

Hi Team,
We identified for the latest VPA 1.3.0 release

registry.k8s.io/autoscaling/vpa-admission-controller
registry.k8s.io/autoscaling/vpa-updater
registry.k8s.io/autoscaling/vpa-recommender
These images got impacted with below list of vulnerabilities.

CVE-2025-22868
CVE-2025-22870
CVE-2025-22866

We would appreciate if you review and provide any timelines to release new version of VPA that remediates these vulnerabilities.

Regards
Sandeep

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions