apk package
chainguard/kcp-fips-0.31-virtual-workspaces
pkg:apk/chainguard/kcp-fips-0.31-virtual-workspaces
Vulnerabilities (42)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-33811 | Hig | 7.5 | < 0.31.1-r1 | 0.31.1-r1 | May 7, 2026 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash. | |
| CVE-2026-35469 | Med | 6.5 | < 0.31.0-r1 | 0.31.0-r1 | Apr 16, 2026 | spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, |
- affected < 0.31.1-r1fixed 0.31.1-r1
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
- affected < 0.31.0-r1fixed 0.31.0-r1
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count,
Page 3 of 3