VYPR

apk package

chainguard/gitlab-kas-fips-18.10

pkg:apk/chainguard/gitlab-kas-fips-18.10

Vulnerabilities (43)

  • CVE-2026-32280HigApr 8, 2026
    affected < 18.10.7-r0fixed 18.10.7-r0

    During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls

  • CVE-2026-27140HigApr 8, 2026
    affected < 18.10.7-r0fixed 18.10.7-r0

    SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

  • CVE-2026-34986HigApr 6, 2026
    affected < 18.10.4-r1fixed 18.10.4-r1

    Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JW

Page 3 of 3