CVE-2025-66418 - Unbounded number of links in the decompression chain#4928
Merged
Jooho merged 3 commits intokserve:masterfrom Jan 7, 2026
Merged
CVE-2025-66418 - Unbounded number of links in the decompression chain#4928Jooho merged 3 commits intokserve:masterfrom
Jooho merged 3 commits intokserve:masterfrom
Conversation
chore: Fix GHSA-gm62-xv2j-4w53 Signed-off-by: Spolti <[email protected]>
Contributor
Author
|
/rerun-all |
sivanantha321
approved these changes
Jan 6, 2026
spolti
added a commit
to spolti/kserve
that referenced
this pull request
Jan 29, 2026
Commits in this batch: 35755fc ci: PR style check (kserve#4499) 30d1b75 AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb (kserve#4939) 53004e7 (jooho/upstream_master) feat: add automatic modelFormat annotation for InferenceServices (kserve#4953) 7d10530 Bump Gateway API Inference Extension (GIE) to v1.2.0 (kserve#4886) b43d60c Separate LocalModelCache webhook from KServe controller. (kserve#4941) 58fa35d Fix CVE-2025-68156: Update expr-lang/expr to v1.17.7 (kserve#4934) 7a7c5aa refactor: deduplicate test configs with helper functions (kserve#4952) 6f95f1a Fix: use correct image tag in LLMISvc E2E workflow (kserve#4948) f1f7bed Fix: LLMInferenceService reconciliation for Gateway refs in baseRefs (kserve#4944) a70985a CVE-2025-66418 - Unbounded number of links in the decompression chain (kserve#4928) 11aad94 chore: bump github.com/kedacore/keda/v2 from 2.16.1 to 2.17.3 (kserve#4927) b253a50 Fix: opentelemetry helm installation script (kserve#4932) 4041412 refactor: replace bash script with Python and improve generate-version (kserve#4935) 2e987ef Add precommit check to sync golangci Go version with go.mod (kserve#4930) f44cb66 fix: make deploy-dev for development env (kserve#4881) f15f6ac Address several CVEs (kserve#4912) 54faf3b ci: add retry request for e2e tests to reduce transient failures (kserve#4795) 6b7bc43 chore: Add .gitattributes to mark vendored and generated code (kserve#4904) 29a6a2b ci: split KServe and Storage publish workflow into separate jobs (kserve#4801) 299706d Improved CA Bundle Management For LLM Inference Services (kserve#4803)
10 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
chore: Fix GHSA-gm62-xv2j-4w53
What this PR does / why we need it:
Which issue(s) this PR fixes (optional, in
fixes #<issue number>(, fixes #<issue_number>, ...)format, will close the issue(s) when PR gets merged):Fixes #
Type of changes
Please delete options that are not relevant.
Feature/Issue validation/testing:
Please describe the tests that you ran to verify your changes and relevant result summary. Provide instructions so it can be reproduced.
Please also list any relevant details for your test configuration.
Test A
Test B
Logs
Special notes for your reviewer:
Checklist:
Release note:
Re-running failed tests
/rerun-all- rerun all failed workflows./rerun-workflow <workflow name>- rerun a specific failed workflow. Only one workflow name can be specified. Multiple /rerun-workflow commands are allowed per comment.