VYPR

apk package

chainguard/kubo-fips

pkg:apk/chainguard/kubo-fips

Vulnerabilities (63)

  • CVE-2025-59530HigOct 10, 2025
    affected < 0.38.1-r1fixed 0.38.1-r1

    quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. This requir

  • CVE-2025-47907HigAug 7, 2025
    affected < 0.36.0-r2fixed 0.36.0-r2

    Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the ex

  • CVE-2023-26248MedOct 25, 2024
    affected < 0fixed 0

    The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information for content (i.e., information about who holds the content) to be stored by peers whose peer IDs have a small DHT distance from the content ID. This allows an att

Page 4 of 4