VYPR

apk package

chainguard/debezium-3.6-connector-jdbc

pkg:apk/chainguard/debezium-3.6-connector-jdbc

Vulnerabilities (5)

  • CVE-2026-55858MedAug 28, 2026
    affected < 3.6.1-r2fixed 3.6.1-r2

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the assumption that the connection character set

  • CVE-2026-55857MedAug 28, 2026
    affected < 3.6.1-r2fixed 3.6.1-r2

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insecure connection. The mysql_clear_password pl

  • CVE-2026-55856MedAug 28, 2026
    affected < 3.6.1-r2fixed 3.6.1-r2

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a password, and does not configure serverSslCer

  • CVE-2026-59949MedAug 18, 2026
    affected < 3.6.1-r1fixed 3.6.1-r1

    yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFact

  • CVE-2026-54291MedJul 6, 2026
    affected < 3.6.2-r1fixed 3.6.2-r1

    pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting i