VYPR

apk package

chainguard/dl

pkg:apk/chainguard/dl

Vulnerabilities (2)

  • CVE-2026-46600Jul 24, 2026
    affected < 0fixed 0

    Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

  • CVE-2026-29049Mar 6, 2026
    affected < 0.0.20260623145845-r0fixed 0.0.20260623145845-r0

    melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache.go). An attacker-controlled URI in a mel