Skip to content

CVE-2025-52881 is being reported by Wiz on the latest AMI #4878

Description

@surajmali14

Image I'm using: : bottlerocket-aws-k8s-1.33-x86_64-v1.62.1-ea1afdd6

What I expected to happen: : CVE-2025-52881 should not be present in the latest AMI version, as it has already been addressed in the corresponding release.

What actually happened: I found that CVE-2025-52881 has already been fixed in Bottlerocket AMI v1.50.0. Since we are already using the latest Bottlerocket AMI version, it is unexpected that Wiz is still reporting this vulnerability.

According to the Bottlerocket release notes, the fix is included in v1.50.0:
https://github.com/bottlerocket-os/bottlerocket/releases/tag/v1.50.0

Could you please help verify whether this is a false positive, or if there is an updated vulnerability database or additional remediation required?

How to reproduce the problem: : Images for reference

Image Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    status/needs-triagePending triage or re-evaluationtype/bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions