apk package
chainguard/haraka
pkg:apk/chainguard/haraka
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-11525 | low | 3.7 | < 3.3.1-r1 | 3.3.1-r1 | Jun 17, 2026 | undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header | |
| CVE-2026-6733 | low | 3.7 | < 3.3.1-r1 | 3.3.1-r1 | Jun 17, 2026 | undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. | |
| CVE-2026-9679 | mod | 5.9 | < 3.3.1-r1 | 3.3.1-r1 | Jun 17, 2026 | undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding | |
| CVE-2026-12151 | imp | 7.5 | < 3.3.1-r1 | 3.3.1-r1 | Jun 17, 2026 | undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames |
- affected < 3.3.1-r1fixed 3.3.1-r1
undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header
- affected < 3.3.1-r1fixed 3.3.1-r1
undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery.
- affected < 3.3.1-r1fixed 3.3.1-r1
undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
- affected < 3.3.1-r1fixed 3.3.1-r1
undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames