Skip to content

CVE-2025-22869 and CVE-2025-27144 vulnerabilities in slsa-verifier v2.7.0 #846

@mukhan-axon

Description

@mukhan-axon

Description

We identified two security vulnerabilities in slsa-verifier version 2.7.0 through our internal Snyk scans. These CVEs are linked to dependencies used by the project:

These issues may expose systems using slsa-verifier to cryptographic weaknesses or other security risks, particularly in environments with automated supply chain verification or signature validation.

Please confirm:

  • Whether slsa-verifier v2.7.0 includes the vulnerable versions of these libraries.
  • If an upgrade path or mitigation is available.
  • Whether a patched release is planned or already available.

Steps to reproduce:

  1. Download and scan the slsa-verifier v2.7.0 binary using snyk test or an equivalent vulnerability scanner.

  2. Observe the following CVEs:

Expected behavior:

All dependencies used by slsa-verifier should be free of known vulnerabilities, particularly in a security-critical toolchain component.

Version

v2.7.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions