{"schema_version":"1.7.3","id":"GO-2025-3527","published":"2025-03-18T18:14:48Z","modified":"2026-02-04T02:54:48.132901Z","aliases":["CVE-2025-0495","GHSA-m4gq-fm9h-8q75"],"related":["CGA-jqqg-39q6-6jp8"],"summary":"buildx allows a possible credential leakage to telemetry endpoint in github.com/docker/buildx","details":"buildx allows a possible credential leakage to telemetry endpoint in github.com/docker/buildx","affected":[{"package":{"name":"github.com/docker/buildx","ecosystem":"Go","purl":"pkg:golang/github.com/docker/buildx"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.21.3"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-3527.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/docker/buildx/security/advisories/GHSA-m4gq-fm9h-8q75"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-0495"},{"type":"FIX","url":"https://github.com/docker/buildx/commit/18ccba072076ddbfb0aeedd6746d7719b0729b58"}],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2025-3527"}}