VYPR

apk package

chainguard/langfuse-2-worker

pkg:apk/chainguard/langfuse-2-worker

Vulnerabilities (111)

  • CVE-2025-13465MedJan 21, 2026
    affected < 2.95.12-r6fixed 2.95.12-r6

    Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwritin

  • CVE-2025-15284Dec 29, 2025
    affected < 2.95.12-r4fixed 2.95.12-r4

    Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLim

  • CVE-2025-68665Dec 23, 2025
    affected < 2.95.12-r4fixed 2.95.12-r4

    LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and prior to langchain versions 0.3.37 and 1.2.3, a serialization injection vulnerability exists in LangChain JS's toJSON() method (and subsequently when string-ify

  • CVE-2025-68130HigDec 16, 2025
    affected < 2.95.12-r3fixed 2.95.12-r3

    tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27.0 and prior to versions 10.45.3 and 11.8.0, a A prototype pollution vulnerability exists in `@trpc/server`'s `formDataToObject` function, which is used by the

  • CVE-2025-61729Dec 2, 2025
    affected < 2.95.12-r1fixed 2.95.12-r1

    Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a

  • CVE-2025-66400Dec 1, 2025
    affected < 2.95.12-r2fixed 2.95.12-r2

    mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the p

  • CVE-2025-62522MedOct 20, 2025
    affected < 2.95.12-r26fixed 2.95.12-r26

    Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent i

  • CVE-2025-58752Sep 8, 2025
    affected < 2.95.12-r26fixed 2.95.12-r26

    Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.ho

  • CVE-2025-58751Sep 8, 2025
    affected < 2.95.12-r26fixed 2.95.12-r26

    Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network

  • CVE-2025-9799MedSep 1, 2025
    affected < 2.95.12-r2fixed 2.95.12-r2

    A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file web/src/features/prompts/server/routers/promptRouter.ts of the component Webhook Handler. Performing manipulation results in server-s

  • CVE-2025-24010Jan 20, 2025
    affected < 2.95.12-r26fixed 2.95.12-r26

    Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6

Page 6 of 6