Skip to content

Security vulnerabilities detected in NetApp Trident container images (CVE-2025-61727, CVE-2025-61729) #1105

@nikhiljoseph2905

Description

@nikhiljoseph2905

Description

Container security scanning has identified vulnerabilities in NetApp Trident–related container images used in our Kubernetes environment.

Affected images include:

docker.io/netapp/trident

docker.io/netapp/trident-autosupport

registry.k8s.io/sig-storage/csi-provisioner

registry.k8s.io/sig-storage/csi-resizer

registry.k8s.io/sig-storage/csi-node-driver-registrar
registry.k8s.io/sig-storage/csi-attacher
registry.k8s.io/sig-storage/csi-snapshotter

Detected vulnerabilities:

CVE-2025-61727 (Medium)

CVE-2025-61729 (High – Go crypto/x509)

These vulnerabilities appear to be related to the Go toolchain version used to build the images.

Request

Please advise:

Whether patched images are available

The Trident / CSI component versions that remediate these CVEs

Any recommended mitigation or upgrade path

These findings are blocking our CI/CD security gates.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions