VYPR

apk package

chainguard/kafka-iamguarded-compat-4.0

pkg:apk/chainguard/kafka-iamguarded-compat-4.0

Vulnerabilities (5)

  • CVE-2025-68161Dec 18, 2025
    affected < 4.0.1-r2fixed 4.0.1-r2

    The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName co

  • CVE-2024-29371Dec 17, 2025
    affected < 4.0.1-r2fixed 4.0.1-r2

    In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and proc

  • CVE-2025-12383Nov 18, 2025
    affected < 4.0.1-r1fixed 4.0.1-r1

    In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but

  • CVE-2025-48924Jul 11, 2025
    affected < 4.0.0-r44fixed 4.0.0-r44

    Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowErr

  • CVE-2025-48734May 28, 2025
    affected < 4.0.0-r42fixed 4.0.0-r42

    Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was no