VYPR

apk package

chainguard/commercial-kyverno-background-controller-1.13

pkg:apk/chainguard/commercial-kyverno-background-controller-1.13

Vulnerabilities (3)

  • CVE-2026-39395MedApr 7, 2026
    affected < 1.13.6-r0fixed 1.13.6-r0

    Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and det

  • CVE-2026-24122LowFeb 19, 2026
    affected < 1.13.6-r0fixed 1.13.6-r0

    Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be considered valid during verification even if the provided timestamp would mean the issui

  • CVE-2025-29778MedMar 24, 2025
    affected < 1.13.6-r0fixed 1.13.6-r0

    Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign with keyless mode. It allows the attacker to deploy kubernetes resources with the artif