VYPR

apk package

chainguard/gitlab-rails-ce-fips-18.8

pkg:apk/chainguard/gitlab-rails-ce-fips-18.8

Vulnerabilities (68)

  • CVE-2026-1282Feb 11, 2026
    affected < 18.8.4-r0fixed 18.8.4-r0

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles.

  • CVE-2026-1456Feb 11, 2026
    affected < 18.8.4-r0fixed 18.8.4-r0

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger expo

  • CVE-2026-1458Feb 11, 2026
    affected < 18.8.4-r0fixed 18.8.4-r0

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.

  • CVE-2026-25934Feb 9, 2026
    affected < 18.8.4-r1fixed 18.8.4-r1

    go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files,

  • CVE-2025-68121CriFeb 5, 2026
    affected < 18.8.4-r0fixed 18.8.4-r0

    During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and

  • CVE-2025-61732Feb 5, 2026
    affected < 18.8.4-r0fixed 18.8.4-r0

    A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

  • CVE-2025-68696HigDec 23, 2025
    affected < 18.8.8-r0fixed 18.8.8-r0

    httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. This issue has been patched via commit 0529bcd.

  • CVE-2025-54410Jul 30, 2025
    affected < 18.8.4-r1fixed 18.8.4-r1

    Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby releases before 28.0.0. When firewalld reloads, Docker fail

Page 4 of 4