VYPR

apk package

chainguard/keep-ui

pkg:apk/chainguard/keep-ui

Vulnerabilities (32)

  • CVE-2026-69153MedAug 3, 2026
    affected < 0.54.2-r2fixed 0.54.2-r2

    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or d

  • CVE-2026-64649MedJul 27, 2026
    affected < 0.54.2-r1fixed 0.54.2-r1

    Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-S

  • CVE-2026-64648MedJul 27, 2026
    affected < 0.54.2-r1fixed 0.54.2-r1

    Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidenti

  • CVE-2026-64647MedJul 27, 2026
    affected < 0.54.2-r1fixed 0.54.2-r1

    Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidentia

  • CVE-2026-64646MedJul 27, 2026
    affected < 0.54.2-r1fixed 0.54.2-r1

    Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server A

  • CVE-2026-64645MedJul 27, 2026
    affected < 0.54.2-r1fixed 0.54.2-r1

    Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostn

  • CVE-2026-64644MedJul 27, 2026
    affected < 0.54.2-r1fixed 0.54.2-r1

    Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled

  • CVE-2026-64643MedJul 27, 2026
    affected < 0.54.2-r1fixed 0.54.2-r1

    Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pag

  • CVE-2026-64641HigJul 27, 2026
    affected < 0.54.2-r1fixed 0.54.2-r1

    Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processi

  • CVE-2026-45623HigJul 27, 2026
    affected < 0.54.2-r2fixed 0.54.2-r2

    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferen

  • CVE-2026-73646higJul 24, 2026
    affected < 0.54.2-r2fixed 0.54.2-r2

    ## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`

  • CVE-2026-16221HigJul 19, 2026
    affected < 0.54.2-r1fixed 0.54.2-r1

    Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https cl

  • CVE-2026-59879HigJul 8, 2026
    affected < 0.54.2-r3fixed 0.54.2-r3

    Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, ca

  • CVE-2026-59880HigJul 8, 2026
    affected < 0.54.2-r3fixed 0.54.2-r3

    Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.Set keep keys that share the same 32-bit hash in a HashCollisionNode collision bucket that is scanned linearly, allowing an attacker who controls keys inserted i

  • CVE-2026-13676HigJun 29, 2026
    affected < 0.54.2-r1fixed 0.54.2-r1

    fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() an

  • CVE-2026-45109HigMay 13, 2026
    affected < 0.51.0-r7fixed 0.51.0-r7

    Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.

  • CVE-2026-44582LowMay 13, 2026
    affected < 0.51.0-r7fixed 0.51.0-r7

    Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected co

  • CVE-2026-44581MedMay 13, 2026
    affected < 0.51.0-r7fixed 0.51.0-r7

    Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed no

  • CVE-2026-44580MedMay 13, 2026
    affected < 0.51.0-r7fixed 0.51.0-r7

    Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script cont

  • CVE-2026-44579HigMay 13, 2026
    affected < 0.51.0-r7fixed 0.51.0-r7

    Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In

Page 1 of 2