apk package
chainguard/apicurio-registry-fips
pkg:apk/chainguard/apicurio-registry-fips
Vulnerabilities (13)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-55851 | — | < 3.3.0-r8 | 3.3.0-r8 | Jul 23, 2026 | Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs prot | ||
| CVE-2026-56746 | — | < 3.3.0-r8 | 3.3.0-r8 | Jul 23, 2026 | Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortC | ||
| CVE-2026-55833 | — | < 3.3.0-r8 | 3.3.0-r8 | Jul 21, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the | ||
| CVE-2026-55831 | — | < 3.3.0-r8 | 3.3.0-r8 | Jul 21, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting | ||
| CVE-2026-59889 | — | < 3.3.0-r8 | 3.3.0-r8 | Jul 16, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and call | ||
| CVE-2026-59921 | mod | 5.7 | < 3.3.0-r8 | 3.3.0-r8 | Jul 9, 2026 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder | |
| CVE-2026-59919 | mod | 5.5 | < 3.3.0-r8 | 3.3.0-r8 | Jul 9, 2026 | io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy | |
| CVE-2026-59900 | mod | 6.5 | < 3.3.0-r8 | 3.3.0-r8 | Jul 9, 2026 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 | |
| CVE-2026-59899 | imp | 7.5 | < 3.3.0-r8 | 3.3.0-r8 | Jul 9, 2026 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) | |
| CVE-2026-54515 | med | — | < 3.3.0-r6 | 3.3.0-r6 | Jun 23, 2026 | ## Summary In `BeanDeserializerBase.createContextual()`, per-property `@JsonIgnoreProperties` exclusions are applied by `_handleByNameInclusion()`, producing a `contextual` deserializer whose `BeanPropertyMap` has the ignored properties removed. The subsequent per-property case-i | |
| CVE-2026-42583 | Hig | 7.5 | < 3.3.0-r3 | 3.3.0-r3 | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload | |
| CVE-2026-42579 | Hig | 7.5 | < 3.3.0-r1 | 3.3.0-r1 | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS respon | |
| CVE-2026-6860 | Med | 5.3 | < 3.3.0-r4 | 3.3.0-r4 | May 6, 2026 | A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com where xyz is a valid name can be used. |
- CVE-2026-55851Jul 23, 2026affected < 3.3.0-r8fixed 3.3.0-r8
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs prot
- CVE-2026-56746Jul 23, 2026affected < 3.3.0-r8fixed 3.3.0-r8
Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortC
- CVE-2026-55833Jul 21, 2026affected < 3.3.0-r8fixed 3.3.0-r8
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the
- CVE-2026-55831Jul 21, 2026affected < 3.3.0-r8fixed 3.3.0-r8
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting
- CVE-2026-59889Jul 16, 2026affected < 3.3.0-r8fixed 3.3.0-r8
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and call
- affected < 3.3.0-r8fixed 3.3.0-r8
io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
- affected < 3.3.0-r8fixed 3.3.0-r8
io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy
- affected < 3.3.0-r8fixed 3.3.0-r8
io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
- affected < 3.3.0-r8fixed 3.3.0-r8
io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)
- affected < 3.3.0-r6fixed 3.3.0-r6
## Summary In `BeanDeserializerBase.createContextual()`, per-property `@JsonIgnoreProperties` exclusions are applied by `_handleByNameInclusion()`, producing a `contextual` deserializer whose `BeanPropertyMap` has the ignored properties removed. The subsequent per-property case-i
- affected < 3.3.0-r3fixed 3.3.0-r3
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload
- affected < 3.3.0-r1fixed 3.3.0-r1
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS respon
- affected < 3.3.0-r4fixed 3.3.0-r4
A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com where xyz is a valid name can be used.