VYPR

apk package

chainguard/crossplane-provider-aws-vpc

pkg:apk/chainguard/crossplane-provider-aws-vpc

Vulnerabilities (44)

  • CVE-2026-33811HigMay 7, 2026
    affected < 2.5.0-r1fixed 2.5.0-r1

    When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

  • CVE-2026-5160MedApr 15, 2026
    affected < 2.6.0-r5fixed 2.6.0-r5

    Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before reso

  • CVE-2026-39883HigApr 8, 2026
    affected < 2.6.0-r2fixed 2.6.0-r2

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platf

  • CVE-2026-39882MedApr 8, 2026
    affected < 0fixed 0

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion when the configured collector e

Page 3 of 3