VYPR

apk package

chainguard/amazon-eks-ami-fips

pkg:apk/chainguard/amazon-eks-ami-fips

Vulnerabilities (44)

  • CVE-2026-29181HigApr 7, 2026
    affected < 20260318-r3fixed 20260318-r3

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many bagg

  • CVE-2025-68121CriFeb 5, 2026
    affected < 20260129-r1fixed 20260129-r1

    During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and

  • CVE-2025-61732HigFeb 5, 2026
    affected < 20260129-r1fixed 20260129-r1

    A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

  • CVE-2025-58187HigOct 29, 2025
    affected < 20251023-r0fixed 20251023-r0

    Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.

Page 3 of 3