VYPR

apk package

chainguard/kibana-9.5-iamguarded

pkg:apk/chainguard/kibana-9.5-iamguarded

Vulnerabilities (3)

  • CVE-2026-82562LowAug 30, 2026
    affected < 9.5.3-r1fixed 9.5.3-r1

    ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the same value under a flat key (`a=1,2,3,4`),

  • CVE-2026-82417MedAug 30, 2026
    affected < 9.5.3-r1fixed 9.5.3-r1

    ### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is t

  • CVE-2026-45822MedJun 30, 2026
    affected < 9.5.2-r3fixed 9.5.2-r3

    decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-linear parsing time: 200 '%ab' tokens takes approximately 0.7s, 700 tokens approximately 6s, and 1400