VYPR

apk package

chainguard/crossplane-function-environment-configs-fips

pkg:apk/chainguard/crossplane-function-environment-configs-fips

Vulnerabilities (63)

  • CVE-2025-58183MedOct 29, 2025
    affected < 0.4.0-r4fixed 0.4.0-r4

    tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When r

  • CVE-2025-47912MedOct 29, 2025
    affected < 0.4.0-r4fixed 0.4.0-r4

    The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresse

  • CVE-2025-22868HigFeb 26, 2025
    affected < 0.4.0-r1fixed 0.4.0-r1

    An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

Page 4 of 4