VDB

GO-2025-3981

GO-2025-3981 PUBLISHED

Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning in github.com/gardener/gardener-extension-provider-aws

Affected Products

VendorProductVersions
github.comgardener/gardener-extension-provider-aws0, 0
github.comgardener/gardener-extension-provider-openstack0, 0
github.comgardener/gardener-extension-provider-gcp0, 0
github.comgardener/gardener-extension-provider-azure0, 0

Timeline

  • Oct 23, 2025 CVE Published
  • Mar 3, 2026 CVE Updated
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›