VYPR

apk package

chainguard/langfuse-4-worker

pkg:apk/chainguard/langfuse-4-worker

Vulnerabilities (47)

  • CVE-2026-45820HigJul 22, 2026
    affected < 4.27.0-r4fixed 4.27.0-r4

    fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop inde

  • CVE-2026-56852HigJul 21, 2026
    affected < 4.16.0-r0fixed 4.16.0-r0

    A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

  • CVE-2026-46600HigJul 21, 2026
    affected < 4.16.0-r0fixed 4.16.0-r0

    Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

  • CVE-2026-42505MedJul 8, 2026
    affected < 4.16.0-r0fixed 4.16.0-r0

    Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

  • CVE-2026-39822HigJul 8, 2026
    affected < 4.16.0-r0fixed 4.16.0-r0

    On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symb

  • CVE-2026-39821CriMay 22, 2026
    affected < 4.16.0-r0fixed 4.16.0-r0

    The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program

  • CVE-2026-41907HigApr 24, 2026
    affected < 4.7.1-r0fixed 4.7.1-r0

    uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fi

Page 3 of 3