VYPR

apk package

chainguard/commercial-kyverno-cleanup-controller-1.15

pkg:apk/chainguard/commercial-kyverno-cleanup-controller-1.15

Vulnerabilities (3)

  • CVE-2026-39395MedApr 7, 2026
    affected < 1.15.2-r0fixed 1.15.2-r0

    Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and det

  • CVE-2026-24122LowFeb 19, 2026
    affected < 1.15.2-r0fixed 1.15.2-r0

    Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be considered valid during verification even if the provided timestamp would mean the issui

  • CVE-2025-69725MedFeb 19, 2026
    affected < 1.15.2-r0fixed 1.15.2-r0

    An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.