Skip to content

CVE-2025-6965 - CRITICAL vulnerability found in [email protected] #407

@armandocollazo-tomtom

Description

@armandocollazo-tomtom

When running trivy against version 1.30.7, it outputs the following vulnerability.:

Library Vulnerability Severity Status Installed Version Fixed Version Title
sqlite-libs CVE-2025-6965 CRITICAL fixed 3.49.2-r0 3.49.2-r1 sqlite: Integer Truncation in SQLite
https://avd.aquasec.com/nvd/cve-2025-6965

Recommendation from the report:
Upgrade to version 3.50.2 or above

Steps to reproduce:

  1. Ensure Trivy is installed.
  2. Run the following command:
    trivy image --ignore-unfixed --exit-code 1 --severity CRITICAL quay.io/kiwigrid/k8s-sidecar:1.30.7

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions