VYPR

apk package

chainguard/kcp-0.29-virtual-workspaces

pkg:apk/chainguard/kcp-0.29-virtual-workspaces

Vulnerabilities (44)

  • CVE-2026-35469MedApr 16, 2026
    affected < 0.29.3-r5fixed 0.29.3-r5

    spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count,

  • CVE-2026-39883HigApr 8, 2026
    affected < 0.29.3-r2fixed 0.29.3-r2

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platf

  • CVE-2026-39429HigApr 8, 2026
    affected < 0.29.3-r2fixed 0.29.3-r2

    kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place. This allows anyone who can acce

  • CVE-2026-33186CriMar 20, 2026
    affected < 0.29.3-r2fixed 0.29.3-r2

    gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omi

Page 3 of 3