VYPR

apk package

chainguard/airbyte-platform-workload-api-server

pkg:apk/chainguard/airbyte-platform-workload-api-server

Vulnerabilities (5)

  • CVE-2026-59903MedAug 17, 2026
    affected < 2.0.0-r4fixed 2.0.0-r4

    Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN

  • CVE-2026-64607MedJul 31, 2026
    affected < 2.0.0-r7fixed 2.0.0-r7

    HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient bas

  • CVE-2026-55153HigJul 1, 2026
    affected < 2.0.0-r2fixed 2.0.0-r2

    mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its JNDI ObjectFactory implementation (com.mchange.v2.naming.JavaBeanObjectFactory) will construct objects of arbitrary classes and ini

  • CVE-2026-54428HigJul 1, 2026
    affected < 2.0.0-r3fixed 2.0.0-r3

    Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks

  • CVE-2026-54399HigJul 1, 2026
    affected < 2.0.0-r1fixed 2.0.0-r1

    Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of he