VYPR

apk package

chainguard/gatekeeper-3.19-gator

pkg:apk/chainguard/gatekeeper-3.19-gator

Vulnerabilities (45)

  • CVE-2025-58185MedOct 29, 2025
    affected < 3.19.3-r7fixed 3.19.3-r7

    Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.

  • CVE-2025-58183MedOct 29, 2025
    affected < 3.19.3-r7fixed 3.19.3-r7

    tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When r

  • CVE-2025-47912MedOct 29, 2025
    affected < 3.19.3-r7fixed 3.19.3-r7

    The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresse

  • CVE-2025-47910MedSep 22, 2025
    affected < 3.19.3-r5fixed 3.19.3-r5

    When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended sec

  • CVE-2025-54410LowJul 30, 2025
    affected < 3.19.3-r3fixed 3.19.3-r3

    Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby releases before 28.0.0. When firewalld reloads, Docker fail

Page 3 of 3