apk package
chainguard/gitlab-workhorse-ce-fips-19.0
pkg:apk/chainguard/gitlab-workhorse-ce-fips-19.0
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-56852 | — | < 0 | 0 | Jul 23, 2026 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. | ||
| CVE-2026-46602 | — | < 19.0.3-r3 | 19.0.3-r3 | Jun 27, 2026 | The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. | ||
| CVE-2026-46604 | — | < 19.0.3-r3 | 19.0.3-r3 | Jun 27, 2026 | The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. | ||
| CVE-2026-46601 | mod | 6.5 | < 0 | 0 | Jun 25, 2026 | golang.org/x/image/webp: golang.org/x/image/webp: Denial of Service via malformed VP8 chunk in WebP images |
- CVE-2026-56852Jul 23, 2026affected < 0fixed 0
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
- CVE-2026-46602Jun 27, 2026affected < 19.0.3-r3fixed 19.0.3-r3
The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.
- CVE-2026-46604Jun 27, 2026affected < 19.0.3-r3fixed 19.0.3-r3
The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.
- affected < 0fixed 0
golang.org/x/image/webp: golang.org/x/image/webp: Denial of Service via malformed VP8 chunk in WebP images