VYPR

apk package

chainguard/apache-polaris-fips

pkg:apk/chainguard/apache-polaris-fips

Vulnerabilities (3)

  • CVE-2026-59949MedAug 18, 2026
    affected < 1.7.0-r3fixed 1.7.0-r3

    yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFact

  • CVE-2026-59903MedAug 17, 2026
    affected < 1.7.0-r3fixed 1.7.0-r3

    Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN

  • CVE-2026-64607MedJul 31, 2026
    affected < 1.7.0-r1fixed 1.7.0-r1

    HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient bas