Skip to content

CVE-2025-22869 and CVE-2025-27144 vulnerabilities in slsa-verifier v2.7.0 #846

@mukhan-axon

Description

@mukhan-axon

Description

We identified two security vulnerabilities in slsa-verifier version 2.7.0 through our internal Snyk scans. These CVEs are linked to dependencies used by the project:

These issues may expose systems using slsa-verifier to cryptographic weaknesses or other security risks, particularly in environments with automated supply chain verification or signature validation.

Please confirm:

  • Whether slsa-verifier v2.7.0 includes the vulnerable versions of these libraries.
  • If an upgrade path or mitigation is available.
  • Whether a patched release is planned or already available.

Steps to reproduce:

  1. Download and scan the slsa-verifier v2.7.0 binary using snyk test or an equivalent vulnerability scanner.

  2. Observe the following CVEs:

Expected behavior:

All dependencies used by slsa-verifier should be free of known vulnerabilities, particularly in a security-critical toolchain component.

Version

v2.7.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions