VYPR

apk package

chainguard/kayenta-fips-2026.2

pkg:apk/chainguard/kayenta-fips-2026.2

Vulnerabilities (6)

  • CVE-2026-68525CriAug 25, 2026
    affected < 2026.2.5-r2fixed 2026.2.5-r2

    Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 t

  • CVE-2026-65905CriAug 25, 2026
    affected < 2026.2.5-r2fixed 2026.2.5-r2

    Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is replayab

  • CVE-2026-65182CriAug 25, 2026
    affected < 2026.2.5-r2fixed 2026.2.5-r2

    Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 thro

  • CVE-2026-2332HigApr 14, 2026
    affected < 2026.2.5-r1fixed 2026.2.5-r1

    In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty term

  • CVE-2025-11143LowMar 5, 2026
    affected < 2026.2.5-r1fixed 2026.2.5-r1

    The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the UR

  • CVE-2024-6763LowOct 14, 2024
    affected < 2026.2.5-r1fixed 2026.2.5-r1

    Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs fro