apk package
chainguard/knative-operator-1.18-webhook
pkg:apk/chainguard/knative-operator-1.18-webhook
Vulnerabilities (23)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-61726 | Hig | 7.5 | < 1.18.3-r3 | 1.18.3-r3 | Jan 28, 2026 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a la | |
| CVE-2025-47907 | Hig | 7.0 | < 1.18.1-r4 | 1.18.1-r4 | Aug 7, 2025 | Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the ex | |
| CVE-2025-22868 | Hig | 7.5 | < 1.18.1-r2 | 1.18.1-r2 | Feb 26, 2025 | An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing. |
- affected < 1.18.3-r3fixed 1.18.3-r3
The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a la
- affected < 1.18.1-r4fixed 1.18.1-r4
Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the ex
- affected < 1.18.1-r2fixed 1.18.1-r2
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
Page 2 of 2