VYPR

apk package

chainguard/crossplane-provider-aws-appflow-fips

pkg:apk/chainguard/crossplane-provider-aws-appflow-fips

Vulnerabilities (42)

  • CVE-2026-5160MedApr 15, 2026
    affected < 2.6.0-r8fixed 2.6.0-r8

    Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before reso

  • CVE-2026-29181HigApr 7, 2026
    affected < 2.5.0-r1fixed 2.5.0-r1

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many bagg

Page 3 of 3