VYPR

apk package

chainguard/jitsucom-jitsu-console

pkg:apk/chainguard/jitsucom-jitsu-console

Vulnerabilities (109)

  • CVE-2025-12816HigNov 25, 2025
    affected < 2.11.0-r8fixed 2.11.0-r8

    An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and s

  • CVE-2025-13033HigNov 14, 2025
    affected < 2.11.0-r4fixed 2.11.0-r4

    A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This causes the application to m

  • CVE-2025-64718MedNov 13, 2025
    affected < 2.11.0-r7fixed 2.11.0-r7

    js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. T

  • CVE-2025-58754HigSep 12, 2025
    affected < 2.11.0-r2fixed 2.11.0-r2

    Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire

  • CVE-2025-9910MedSep 11, 2025
    affected < 2.11.0-r3fixed 2.11.0-r3

    Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads that may lead to code execution if untrusted payloads were used as source for the diff, and th

  • CVE-2025-57822MedAug 29, 2025
    affected < 2.11.0-r1fixed 2.11.0-r1

    Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it could lead to SSRF in self-hosted applications that incorrectly forwarded user-supplied headers. Thi

  • CVE-2025-57752MedAug 29, 2025
    affected < 2.11.0-r1fixed 2.11.0-r1

    Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization API routes are affected by cache key confusion. When images returned from API routes vary based on request headers (such

  • CVE-2025-55173MedAug 29, 2025
    affected < 2.11.0-r1fixed 2.11.0-r1

    Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization is vulnerable to content injection. The issue allowed attacker-controlled external image sources to trigger file download

  • CVE-2025-7783CriJul 18, 2025
    affected < 2.10.0-r4fixed 2.10.0-r4

    Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.

  • CVE-2025-49005LowJul 3, 2025
    affected < 2.10.0-r2fixed 2.10.0-r2

    Next.js is a React framework for building full-stack web applications. In Next.js App Router from 15.3.0 to before 15.3.3 and Vercel CLI from 41.4.1 to 42.2.0, a cache poisoning vulnerability was found. The issue allowed page requests for HTML content to return a React Server Com

  • CVE-2025-48387HigJun 2, 2025
    affected < 2.10.0-r0fixed 2.10.0-r0

    tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore o

  • CVE-2025-29927CriMar 21, 2025
    affected < 2.9.0-r0fixed 2.9.0-r0

    Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware

  • CVE-2025-27789MedMar 11, 2025
    affected < 2.8.6-r3fixed 2.8.6-r3

    Babel is a compiler for writing next generation JavaScript. When using versions of Babel prior to 7.26.10 and 8.0.0-alpha.17 to compile regular expression named capturing groups, Babel will generate a polyfill for the `.replace` method that has quadratic complexity on some specif

  • CVE-2025-27152MedMar 7, 2025
    affected < 2.8.6-r2fixed 2.8.6-r2

    axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leaka

  • CVE-2025-22150MedJan 21, 2025
    affected < 2.8.6-r1fixed 2.8.6-r1

    Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Math.random()` to choose the boundary for a multipart/form-data request. It is known that the output of `Math.random()` can be predicted if several of its generat

  • CVE-2024-56332MedJan 3, 2025
    affected < 2.8.5-r3fixed 2.8.5-r3

    Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, Next.js is vulnerable to a Denial of Service (DoS) attack that allows attackers to construct requests that leaves requests to Serve

  • CVE-2024-55565MedDec 9, 2024
    affected < 2.8.5-r0fixed 2.8.5-r0

    nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.

  • CVE-2024-47831MedOct 14, 2024
    affected < 2.8.2-r1fixed 2.8.2-r1

    Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 contain a vulnerability in the image optimization feature which allows for a potential Denial of Service (DoS) condition which could lead to excessive CPU con

  • CVE-2024-47764MedOct 4, 2024
    affected < 2.8.2-r2fixed 2.8.2-r2

    cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the coo

  • CVE-2024-46982HigSep 17, 2024
    affected < 2.8.2-r1fixed 2.8.2-r1

    Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is sent it

Page 5 of 6