apk package
chainguard/kubescape-server-fips-downloader
pkg:apk/chainguard/kubescape-server-fips-downloader
Vulnerabilities (85)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-54787 | — | < 4.0.11-r3 | 4.0.11-r3 | Aug 1, 2026 | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker | ||
| CVE-2026-46600 | — | < 0 | 0 | Jul 24, 2026 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. | ||
| CVE-2026-56852 | — | < 4.0.11-r1 | 4.0.11-r1 | Jul 23, 2026 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. | ||
| CVE-2026-49834 | — | < 4.0.10-r7 | 4.0.10-r7 | Jul 19, 2026 | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or per validation path rather than per log authority, allowing a sing | ||
| CVE-2026-56742 | — | < 4.0.10-r9 | 4.0.10-r9 | Jul 15, 2026 | Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the Refe | ||
| CVE-2026-53935 | — | < 4.0.10-r5 | 4.0.10-r5 | Jul 7, 2026 | Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Servic | ||
| CVE-2026-50162 | mod | 5.3 | < 4.0.10-r4 | 4.0.10-r4 | Jul 1, 2026 | oras-go: oras-go: File store write outside working directory via symlink traversal | |
| CVE-2026-50151 | mod | 5.9 | < 4.0.10-r4 | 4.0.10-r4 | Jul 1, 2026 | oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload | |
| CVE-2026-48978 | low | 3.1 | < 4.0.10-r4 | 4.0.10-r4 | Jul 1, 2026 | oras-go: oras-go: Information disclosure and TLS downgrade via malicious registry realm | |
| CVE-2026-49835 | mod | 5.9 | < 4.0.10-r3 | 4.0.10-r3 | Jun 30, 2026 | timestamp-authority: Sigstore Timestamp Authority: Denial of Service via unbounded metric label cardinality | |
| CVE-2026-49478 | mod | 6.5 | < 4.0.10-r2 | 4.0.10-r2 | Jun 30, 2026 | github.com/sigstore/fulcio: Fulcio: Server-Side Request Forgery and Kubernetes ServiceAccount token leakage | |
| CVE-2026-46602 | — | < 0 | 0 | Jun 27, 2026 | The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption. | ||
| CVE-2026-46604 | — | < 0 | 0 | Jun 27, 2026 | The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. | ||
| CVE-2026-48702 | imp | 7.5 | < 4.0.9-r4 | 4.0.9-r4 | Jun 25, 2026 | github.com/sigstore/rekor: Rekor: Denial of Service due to unbounded gzip decompression in Alpine APK parsing | |
| CVE-2026-46601 | mod | 6.5 | < 4.0.9-r5 | 4.0.9-r5 | Jun 25, 2026 | golang.org/x/image/webp: golang.org/x/image/webp: Denial of Service via malformed VP8 chunk in WebP images | |
| CVE-2026-53492 | hig | — | < 4.0.9-r2 | 4.0.9-r2 | Jun 19, 2026 | ### Impact containerd's CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations fro | |
| CVE-2026-53489 | hig | — | < 4.0.9-r2 | 4.0.9-r2 | Jun 19, 2026 | ### Impact A bug was found in containerd where the CRI plugin restores `container.log` from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via `kubectl logs`. ### Patches This bug has been fixed in the following | |
| CVE-2026-53488 | hig | — | < 4.0.9-r2 | 4.0.9-r2 | Jun 19, 2026 | ### Impact A bug was found in containerd where the CRI plugin propagates labels from an image config (`LABEL` instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels f | |
| CVE-2026-50195 | — | < 4.0.9-r2 | 4.0.9-r2 | Jun 19, 2026 | ## Impact containerd's CRI checkpoint import process contains a vulnerability where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to | ||
| CVE-2026-47262 | — | < 4.0.9-r2 | 4.0.9-r2 | Jun 19, 2026 | ### Impact A vulnerability in containerd allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the contai |
- CVE-2026-54787Aug 1, 2026affected < 4.0.11-r3fixed 4.0.11-r3
sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker
- CVE-2026-46600Jul 24, 2026affected < 0fixed 0
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
- CVE-2026-56852Jul 23, 2026affected < 4.0.11-r1fixed 4.0.11-r1
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
- CVE-2026-49834Jul 19, 2026affected < 4.0.10-r7fixed 4.0.10-r7
sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or per validation path rather than per log authority, allowing a sing
- CVE-2026-56742Jul 15, 2026affected < 4.0.10-r9fixed 4.0.10-r9
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the Refe
- CVE-2026-53935Jul 7, 2026affected < 4.0.10-r5fixed 4.0.10-r5
Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Servic
- affected < 4.0.10-r4fixed 4.0.10-r4
oras-go: oras-go: File store write outside working directory via symlink traversal
- affected < 4.0.10-r4fixed 4.0.10-r4
oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload
- affected < 4.0.10-r4fixed 4.0.10-r4
oras-go: oras-go: Information disclosure and TLS downgrade via malicious registry realm
- affected < 4.0.10-r3fixed 4.0.10-r3
timestamp-authority: Sigstore Timestamp Authority: Denial of Service via unbounded metric label cardinality
- affected < 4.0.10-r2fixed 4.0.10-r2
github.com/sigstore/fulcio: Fulcio: Server-Side Request Forgery and Kubernetes ServiceAccount token leakage
- CVE-2026-46602Jun 27, 2026affected < 0fixed 0
The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.
- CVE-2026-46604Jun 27, 2026affected < 0fixed 0
The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.
- affected < 4.0.9-r4fixed 4.0.9-r4
github.com/sigstore/rekor: Rekor: Denial of Service due to unbounded gzip decompression in Alpine APK parsing
- affected < 4.0.9-r5fixed 4.0.9-r5
golang.org/x/image/webp: golang.org/x/image/webp: Denial of Service via malformed VP8 chunk in WebP images
- affected < 4.0.9-r2fixed 4.0.9-r2
### Impact containerd's CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations fro
- affected < 4.0.9-r2fixed 4.0.9-r2
### Impact A bug was found in containerd where the CRI plugin restores `container.log` from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via `kubectl logs`. ### Patches This bug has been fixed in the following
- affected < 4.0.9-r2fixed 4.0.9-r2
### Impact A bug was found in containerd where the CRI plugin propagates labels from an image config (`LABEL` instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels f
- CVE-2026-50195Jun 19, 2026affected < 4.0.9-r2fixed 4.0.9-r2
## Impact containerd's CRI checkpoint import process contains a vulnerability where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to
- CVE-2026-47262Jun 19, 2026affected < 4.0.9-r2fixed 4.0.9-r2
### Impact A vulnerability in containerd allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the contai
Page 1 of 5