Junglewise Threat Intelligence

CVE-2025-58356: GO-2025-4076 - Constellation has insecure LUKS2 persistent storage partitions which may be opened and used in github.com/edgelesssys/constellation

CVE-2025-58356 · Severity: medium · CVSS 4 · Published 2025-10-30

Technologies: github.com/edgelesssys/constellation (Go), github.com/edgelesssys/constellation/v2 (Go). Vendors: Go.

Executive brief

Constellation has insecure LUKS2 persistent storage partitions which may be opened and used in github.com/edgelesssys/constellation

Affected products

  • Go github.com/edgelesssys/constellation
  • Go github.com/edgelesssys/constellation/v2

Related threats