VYPR

apk package

chainguard/k8s_gateway-fips

pkg:apk/chainguard/k8s_gateway-fips

Vulnerabilities (63)

  • CVE-2025-59530HigOct 10, 2025
    affected < 1.6.0-r1fixed 1.6.0-r1

    quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. This requir

  • CVE-2025-58063HigSep 9, 2025
    affected < 1.6.1-r0fixed 1.6.1-r0

    CoreDNS is a DNS server that chains plugins. Starting in version 1.2.0 and prior to version 1.12.4, the CoreDNS etcd plugin contains a TTL confusion vulnerability where lease IDs are incorrectly used as TTL values, enabling DNS cache pinning attacks. This effectively creates a Do

  • CVE-2025-47907HigAug 7, 2025
    affected < 0fixed 0

    Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the ex

Page 4 of 4