VYPR

apk package

chainguard/gitleaks

pkg:apk/chainguard/gitleaks

Vulnerabilities (64)

  • CVE-2024-24787MedMay 8, 2024
    affected < 8.18.2-r3fixed 8.18.2-r3

    On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.

  • CVE-2023-45288HigApr 4, 2024
    affected < 8.18.2-r2fixed 8.18.2-r2

    An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed Ma

  • CVE-2021-38561HigDec 26, 2022
    affected < 8.18.2-r1fixed 8.18.2-r1

    golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.

  • CVE-2022-32149HigOct 14, 2022
    affected < 8.18.2-r1fixed 8.18.2-r1

    An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.

Page 4 of 4