VYPR

apk package

chainguard/codex

pkg:apk/chainguard/codex

Vulnerabilities (4)

  • CVE-2026-48504MedJul 17, 2026
    affected < 0fixed 0

    OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause unn

  • CVE-2026-40034HigMay 26, 2026
    affected < 0.149.0-r0fixed 0.149.0-r0

    gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .g

  • CVE-2026-44471HigMay 13, 2026
    affected < 0.149.0-r0fixed 0.149.0-r0

    gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide, permit writing an attacker-controlled symlink into any existing directory the user has write access to. During checkout, all symli

  • CVE-2026-25537HigFeb 4, 2026
    affected < 0.149.0-r0fixed 0.149.0-r0

    jsonwebtoken is a JWT lib in rust. Prior to version 10.3.0, there is a Type Confusion vulnerability in jsonwebtoken, specifically, in its claim validation logic. When a standard claim (such as nbf or exp) is provided with an incorrect JSON type (Like a String instead of a Number)