VYPR

apk package

chainguard/datadog-agent-7.76-full

pkg:apk/chainguard/datadog-agent-7.76-full

Vulnerabilities (43)

  • CVE-2026-29181HigApr 7, 2026
    affected < 7.76.3-r12fixed 7.76.3-r12

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many bagg

  • CVE-2026-32287HigMar 26, 2026
    affected < 7.76.3-r11fixed 7.76.3-r11

    Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level selectors such as "1=1" or "true()".

  • CVE-2026-2303MedFeb 10, 2026
    affected < 7.76.3-r27fixed 7.76.3-r27

    The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI b

Page 3 of 3