VYPR

apk package

chainguard/gitea-fips

pkg:apk/chainguard/gitea-fips

Vulnerabilities (78)

  • CVE-2026-78662HigSep 2, 2026
    affected < 1.27.3-r5fixed 1.27.3-r5

    Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such

  • CVE-2026-56855HigSep 2, 2026
    affected < 1.27.3-r5fixed 1.27.3-r5

    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and t

  • CVE-2026-84304HigSep 1, 2026
    affected < 1.27.3-r4fixed 1.27.3-r4

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain

  • CVE-2026-56854HigAug 28, 2026
    affected < 1.27.3-r1fixed 1.27.3-r1

    The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCal

  • CVE-2026-60004CriKEVAug 26, 2026
    affected < 1.27.1-r0fixed 1.27.1-r0

    Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

  • CVE-2026-46603HigAug 14, 2026
    affected < 1.27.2-r1fixed 1.27.2-r1

    VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.

  • CVE-2026-56865HigAug 13, 2026
    affected < 0fixed 0

    A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious modul

  • CVE-2026-56864HigAug 13, 2026
    affected < 0fixed 0

    A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order

  • CVE-2026-71557MedAug 7, 2026
    affected < 1.27.1-r1fixed 1.27.1-r1

    go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example con

  • CVE-2026-71556HigAug 7, 2026
    affected < 1.27.1-r1fixed 1.27.1-r1

    go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a malicious

  • CVE-2026-56852HigJul 21, 2026
    affected < 1.27.0-r3fixed 1.27.0-r3

    A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

  • CVE-2026-42505MedJul 8, 2026
    affected < 1.26.4-r4fixed 1.26.4-r4

    Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

  • CVE-2026-39822HigJul 8, 2026
    affected < 0fixed 0

    On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symb

  • CVE-2026-46602HigJun 25, 2026
    affected < 0fixed 0

    The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.

  • CVE-2026-46601HigJun 25, 2026
    affected < 1.26.4-r1fixed 1.26.4-r1

    The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.

  • CVE-2026-42507MedJun 2, 2026
    affected < 1.26.2-r5fixed 1.26.2-r5

    When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

  • CVE-2026-42504HigJun 2, 2026
    affected < 1.26.2-r5fixed 1.26.2-r5

    Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

  • CVE-2026-27145MedJun 2, 2026
    affected < 1.26.2-r5fixed 1.26.2-r5

    (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratic

  • CVE-2026-45571MedMay 27, 2026
    affected < 1.26.2-r1fixed 1.26.2-r1

    go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These v

  • CVE-2026-45570CriMay 27, 2026
    affected < 1.26.2-r1fixed 1.26.2-r1

    go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A reposito

Page 1 of 4