VYPR

apk package

chainguard/harbor-fips-2.13-db

pkg:apk/chainguard/harbor-fips-2.13-db

Vulnerabilities (24)

  • CVE-2025-22872MedApr 16, 2025
    affected < 2.13.0-r1fixed 2.13.0-r1

    The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can resul

  • CVE-2025-24358MedApr 15, 2025
    affected < 2.13.0-r1fixed 2.13.0-r1

    gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications & services. Prior to 1.7.2, gorilla/csrf does not validate the Origin header against an allowlist. Its executes its validation of the Referer header for cross-origin requests onl

  • CVE-2025-32386Apr 9, 2025
    affected < 2.13.0-r1fixed 2.13.0-r1

    Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than compressed (e.g., >800x difference). When Helm loads this specially crafted chart, memory can be exhausted causing the application to

  • CVE-2025-32387Apr 9, 2025
    affected < 2.13.0-r1fixed 2.13.0-r1

    Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nested chain of references, leading to parser recursion that can exceed the stack size limit and trigger a stack overflow. This issue has been resolved in Helm v3.1

Page 2 of 2