Thanks to visit codestin.com
Credit goes to github.com

Skip to content

CVE-2025-66418 - Unbounded number of links in the decompression chain#4928

Merged
Jooho merged 3 commits intokserve:masterfrom
spolti:CVE-2025-66418
Jan 7, 2026
Merged

CVE-2025-66418 - Unbounded number of links in the decompression chain#4928
Jooho merged 3 commits intokserve:masterfrom
spolti:CVE-2025-66418

Conversation

@spolti
Copy link
Contributor

@spolti spolti commented Jan 5, 2026

chore: Fix GHSA-gm62-xv2j-4w53

What this PR does / why we need it:

Which issue(s) this PR fixes (optional, in fixes #<issue number>(, fixes #<issue_number>, ...) format, will close the issue(s) when PR gets merged):
Fixes #

Type of changes
Please delete options that are not relevant.

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • This change requires a documentation update

Feature/Issue validation/testing:

Please describe the tests that you ran to verify your changes and relevant result summary. Provide instructions so it can be reproduced.
Please also list any relevant details for your test configuration.

  • Test A

  • Test B

  • Logs

Special notes for your reviewer:

  1. Please confirm that if this PR changes any image versions, then that's the sole change this PR makes.

Checklist:

  • Have you added unit/e2e tests that prove your fix is effective or that this feature works?
  • Has code been commented, particularly in hard-to-understand areas?
  • Have you made corresponding changes to the documentation?

Release note:


Re-running failed tests

  • /rerun-all - rerun all failed workflows.
  • /rerun-workflow <workflow name> - rerun a specific failed workflow. Only one workflow name can be specified. Multiple /rerun-workflow commands are allowed per comment.

@spolti spolti requested review from Jooho and sivanantha321 January 5, 2026 21:36
@spolti
Copy link
Contributor Author

spolti commented Jan 5, 2026

/rerun-all

@Jooho Jooho enabled auto-merge (squash) January 7, 2026 20:31
@Jooho Jooho merged commit a70985a into kserve:master Jan 7, 2026
19 checks passed
@spolti spolti deleted the CVE-2025-66418 branch January 7, 2026 23:03
spolti added a commit to spolti/kserve that referenced this pull request Jan 29, 2026
Commits in this batch:
35755fc ci: PR style check (kserve#4499)
30d1b75 AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb (kserve#4939)
53004e7 (jooho/upstream_master) feat: add automatic modelFormat annotation for InferenceServices (kserve#4953)
7d10530 Bump Gateway API Inference Extension (GIE) to v1.2.0 (kserve#4886)
b43d60c Separate LocalModelCache webhook from KServe controller. (kserve#4941)
58fa35d Fix CVE-2025-68156: Update expr-lang/expr to v1.17.7 (kserve#4934)
7a7c5aa refactor: deduplicate test configs with helper functions (kserve#4952)
6f95f1a Fix: use correct image tag in LLMISvc E2E workflow (kserve#4948)
f1f7bed Fix: LLMInferenceService reconciliation for Gateway refs in baseRefs (kserve#4944)
a70985a CVE-2025-66418 - Unbounded number of links in the decompression chain (kserve#4928)
11aad94 chore: bump github.com/kedacore/keda/v2 from 2.16.1 to 2.17.3 (kserve#4927)
b253a50 Fix: opentelemetry helm installation script (kserve#4932)
4041412 refactor: replace bash script with Python and improve generate-version (kserve#4935)
2e987ef Add precommit check to sync golangci Go version with go.mod (kserve#4930)
f44cb66 fix: make deploy-dev for development env (kserve#4881)
f15f6ac Address several CVEs (kserve#4912)
54faf3b ci: add retry request for e2e tests to reduce transient failures (kserve#4795)
6b7bc43 chore: Add .gitattributes to mark vendored and generated code (kserve#4904)
29a6a2b ci: split KServe and Storage  publish workflow into separate jobs (kserve#4801)
299706d Improved CA Bundle Management For LLM Inference Services (kserve#4803)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants