VYPR

apk package

chainguard/dockerd-29

pkg:apk/chainguard/dockerd-29

Vulnerabilities (62)

  • CVE-2026-23992MedJan 22, 2026
    affected < 29.2.0-r1fixed 29.2.0-r1

    go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This

  • CVE-2026-23991MedJan 22, 2026
    affected < 29.2.0-r1fixed 29.2.0-r1

    go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing,

Page 4 of 4