Vulnerability Report: GO-2026-4924
- CVE-2025-68153, GHSA-245v-p8fj-vwm2
- Affects: github.com/juju/juju
- Published: Apr 06, 2026
Juju has a resource poisoning vulnerability in github.com/juju/juju. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/juju/juju from v2.9 before v2.9.56, from v3.6 before v3.6.19.
For detailed information about this vulnerability, visit https://github.com/juju/juju/security/advisories/GHSA-245v-p8fj-vwm2.
Affected Packages
-
PathVersionsSymbols
Aliases
References
- https://github.com/juju/juju/security/advisories/GHSA-245v-p8fj-vwm2
- https://github.com/juju/juju/commit/26ff93c903d55b0712c6fb3f6b254710edb971d4
- https://vuln.go.dev/ID/GO-2026-4924.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.