VYPR

apk package

chainguard/apache-jena-fuseki

pkg:apk/chainguard/apache-jena-fuseki

Vulnerabilities (9)

  • CVE-2026-10050CriAug 4, 2026
    affected < 6.1.0-r4fixed 6.1.0-r4

    In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If t

  • CVE-2026-8384MedJul 14, 2026
    affected < 6.2.0-r1fixed 6.2.0-r1

    In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as it will not serve the secret.t

  • CVE-2026-6790MedJul 14, 2026
    affected < 6.2.0-r2fixed 6.2.0-r2

    In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present). This was not enforced in earlier HTTP RFC (for example, in RFC 2616), but it is in the latest R

  • CVE-2026-10051HigJul 14, 2026
    affected < 6.2.0-r2fixed 6.2.0-r2

    In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the trailers of the first request. Subsequent request that do have trai

  • CVE-2026-49268CriJun 17, 2026
    affected < 6.1.0-r3fixed 6.1.0-r3

    A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attack

  • CVE-2026-2332HigApr 14, 2026
    affected < 6.0.0-r5fixed 6.0.0-r5

    In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty term

  • CVE-2026-34480HigApr 10, 2026
    affected < 6.0.0-r5fixed 6.0.0-r5

    Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whene

  • CVE-2026-1605HigMar 5, 2026
    affected < 6.0.0-r3fixed 6.0.0-r3

    In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This happens because the JDK Inflater is allocated

  • CVE-2026-23901LowFeb 10, 2026
    affected < 6.0.0-r2fixed 6.0.0-r2

    Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7. Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue. Prior to Shiro 2.0.7, code paths for non-existent vs. existing users are