VYPR

apk package

chainguard/kubescape-server-fips-downloader

pkg:apk/chainguard/kubescape-server-fips-downloader

Vulnerabilities (85)

  • CVE-2026-54787Aug 1, 2026
    affected < 4.0.11-r3fixed 4.0.11-r3

    sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker

  • CVE-2026-46600Jul 24, 2026
    affected < 0fixed 0

    Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

  • CVE-2026-56852Jul 23, 2026
    affected < 4.0.11-r1fixed 4.0.11-r1

    A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

  • CVE-2026-49834Jul 19, 2026
    affected < 4.0.10-r7fixed 4.0.10-r7

    sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or per validation path rather than per log authority, allowing a sing

  • CVE-2026-56742Jul 15, 2026
    affected < 4.0.10-r9fixed 4.0.10-r9

    Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the Refe

  • CVE-2026-53935Jul 7, 2026
    affected < 4.0.10-r5fixed 4.0.10-r5

    Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Servic

  • CVE-2026-50162modJul 1, 2026
    affected < 4.0.10-r4fixed 4.0.10-r4

    oras-go: oras-go: File store write outside working directory via symlink traversal

  • CVE-2026-50151modJul 1, 2026
    affected < 4.0.10-r4fixed 4.0.10-r4

    oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload

  • CVE-2026-48978lowJul 1, 2026
    affected < 4.0.10-r4fixed 4.0.10-r4

    oras-go: oras-go: Information disclosure and TLS downgrade via malicious registry realm

  • CVE-2026-49835modJun 30, 2026
    affected < 4.0.10-r3fixed 4.0.10-r3

    timestamp-authority: Sigstore Timestamp Authority: Denial of Service via unbounded metric label cardinality

  • CVE-2026-49478modJun 30, 2026
    affected < 4.0.10-r2fixed 4.0.10-r2

    github.com/sigstore/fulcio: Fulcio: Server-Side Request Forgery and Kubernetes ServiceAccount token leakage

  • CVE-2026-46602Jun 27, 2026
    affected < 0fixed 0

    The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.

  • CVE-2026-46604Jun 27, 2026
    affected < 0fixed 0

    The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.

  • CVE-2026-48702impJun 25, 2026
    affected < 4.0.9-r4fixed 4.0.9-r4

    github.com/sigstore/rekor: Rekor: Denial of Service due to unbounded gzip decompression in Alpine APK parsing

  • CVE-2026-46601modJun 25, 2026
    affected < 4.0.9-r5fixed 4.0.9-r5

    golang.org/x/image/webp: golang.org/x/image/webp: Denial of Service via malformed VP8 chunk in WebP images

  • CVE-2026-53492higJun 19, 2026
    affected < 4.0.9-r2fixed 4.0.9-r2

    ### Impact containerd's CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations fro

  • CVE-2026-53489higJun 19, 2026
    affected < 4.0.9-r2fixed 4.0.9-r2

    ### Impact A bug was found in containerd where the CRI plugin restores `container.log` from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via `kubectl logs`. ### Patches This bug has been fixed in the following

  • CVE-2026-53488higJun 19, 2026
    affected < 4.0.9-r2fixed 4.0.9-r2

    ### Impact A bug was found in containerd where the CRI plugin propagates labels from an image config (`LABEL` instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels f

  • CVE-2026-50195Jun 19, 2026
    affected < 4.0.9-r2fixed 4.0.9-r2

    ## Impact containerd's CRI checkpoint import process contains a vulnerability where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to

  • CVE-2026-47262Jun 19, 2026
    affected < 4.0.9-r2fixed 4.0.9-r2

    ### Impact A vulnerability in containerd allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the contai

Page 1 of 5