VYPR

apk package

chainguard/knative-kafka-broker-1.21-receiver-loom

pkg:apk/chainguard/knative-kafka-broker-1.21-receiver-loom

Vulnerabilities (45)

  • CVE-2026-1002MedJan 15, 2026
    affected < 1.21.1-r3fixed 1.21.1-r3

    The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handler using specifically crafted request URI. The issue comes from an improper implementation of the C. rule of section 5.2.4 of RFC3986 and is fixed in Vert.x Co

  • CVE-2025-67735MedDec 16, 2025
    affected < 1.21.1-r4fixed 1.21.1-r4

    Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling wh

  • CVE-2025-66566HigDec 5, 2025
    affected < 1.21.2-r0fixed 1.21.2-r0

    yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted compressed input. In applications where the

  • CVE-2025-12183HigNov 28, 2025
    affected < 1.21.1-r1fixed 1.21.1-r1

    Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

  • CVE-2025-11226HigOct 1, 2025
    affected < 1.21.4-r5fixed 1.21.4-r5

    ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment varia

Page 3 of 3