VYPR

apk package

chainguard/elasticsearch-9.2-iamguarded-fips

pkg:apk/chainguard/elasticsearch-9.2-iamguarded-fips

Vulnerabilities (3)

  • CVE-2026-71497MedAug 6, 2026
    affected < 9.2.8-r7fixed 9.2.8-r7

    jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a different element. When a custom Safelist perm

  • CVE-2026-54428HigJul 1, 2026
    affected < 9.2.8-r10fixed 9.2.8-r10

    Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks

  • CVE-2026-54399HigJul 1, 2026
    affected < 9.2.8-r9fixed 9.2.8-r9

    Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of he