VYPR

apk package

chainguard/crossplane-provider-aws-sesv2-fips

pkg:apk/chainguard/crossplane-provider-aws-sesv2-fips

Vulnerabilities (43)

  • CVE-2026-33814HigMay 7, 2026
    affected < 2.5.0-r0fixed 2.5.0-r0

    When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

  • CVE-2026-33811HigMay 7, 2026
    affected < 2.5.0-r0fixed 2.5.0-r0

    When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

  • CVE-2026-5160MedApr 15, 2026
    affected < 2.6.0-r5fixed 2.6.0-r5

    Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before reso

Page 3 of 3