—
GO-2025-3511
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries in github.com/deislabs/ratify
Quick fix
GO-2025-3511 — github.com/deislabs/ratify: upgrade to the fixed version with the command below.
go get github.com/deislabs/ratify@v1.2.3Details
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries in github.com/deislabs/ratify
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/deislabs/ratify
Introduced in:
0Fixed in: 1.2.3Fix
go get github.com/deislabs/ratify@v1.2.3Go/github.com/ratify-project/ratify
Introduced in:
1.3.0Fixed in: 1.3.2Fix
go get github.com/ratify-project/ratify@v1.3.2References
- https://github.com/ratify-project/ratify/security/advisories/GHSA-44f7-5fj5-h4px[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2025-27403[ADVISORY]
- https://github.com/ratify-project/ratify/commit/0ec0c08490e3d672ae64b1a220c90d5484f1c93f[FIX]
- https://github.com/ratify-project/ratify/commit/84c7c48fa76bb9a1c9583635d1e90bc25b1a546c[FIX]