VYPR

apk package

chainguard/hono-service-device-registry-jdbc

pkg:apk/chainguard/hono-service-device-registry-jdbc

Vulnerabilities (70)

  • CVE-2026-73508MedAug 13, 2026
    affected < 2.7.0-r33fixed 2.7.0-r33

    Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDo

  • CVE-2026-59898HigJul 29, 2026
    affected < 2.7.0-r29fixed 2.7.0-r29

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade

  • CVE-2026-59919MedJul 29, 2026
    affected < 2.7.0-r31fixed 2.7.0-r31

    Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes AF_UNIX source and destination socket addresses into the HAProxy V1 text protocol without validating

  • CVE-2026-59901HigJul 29, 2026
    affected < 2.7.0-r28fixed 2.7.0-r28

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently c

  • CVE-2026-59900MedJul 29, 2026
    affected < 2.7.0-r33fixed 2.7.0-r33

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` heade

  • CVE-2026-59899HigJul 29, 2026
    affected < 2.7.0-r29fixed 2.7.0-r29

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque` named `acceptEncoding

  • CVE-2026-59921MedJul 28, 2026
    affected < 2.7.0-r29fixed 2.7.0-r29

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME

  • CVE-2026-59949medJul 24, 2026
    affected < 2.7.0-r34fixed 2.7.0-r34

    ### Summary Insufficient validation of byte array arguments in JNI-based XXHash implementations in lz4-java 1.11.0 and earlier allows callers to crash the JVM by passing an invalid array reference or invalid range to native XXHash methods. This affects applications where an att

  • CVE-2026-56746MedJul 21, 2026
    affected < 2.7.0-r29fixed 2.7.0-r29

    Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortC

  • CVE-2026-56745HigJul 21, 2026
    affected < 2.7.0-r29fixed 2.7.0-r29

    Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a

  • CVE-2026-55851HigJul 21, 2026
    affected < 2.7.0-r31fixed 2.7.0-r31

    Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs prot

  • CVE-2026-55833HigJul 21, 2026
    affected < 2.7.0-r29fixed 2.7.0-r29

    Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the

  • CVE-2026-55831HigJul 21, 2026
    affected < 2.7.0-r29fixed 2.7.0-r29

    Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting

  • CVE-2026-59889MedJul 14, 2026
    affected < 2.7.0-r31fixed 2.7.0-r31

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and call

  • CVE-2026-54291MedJul 6, 2026
    affected < 2.7.0-r27fixed 2.7.0-r27

    pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting i

  • CVE-2026-56761MedJun 24, 2026
    affected < 0fixed 0

    hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attribute keys containing characters like quotes or angle brackets t

  • CVE-2026-54515MedJun 23, 2026
    affected < 2.7.0-r31fixed 2.7.0-r31

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameIn

  • CVE-2026-54514MedJun 23, 2026
    affected < 2.7.0-r26fixed 2.7.0-r26

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS

  • CVE-2026-54513HigJun 23, 2026
    affected < 2.7.0-r26fixed 2.7.0-r26

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(),

  • CVE-2026-54512HigJun 23, 2026
    affected < 2.7.0-r26fixed 2.7.0-r26

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization.

Page 1 of 4