VYPR

apk package

chainguard/langfuse-fips-2-worker

pkg:apk/chainguard/langfuse-fips-2-worker

Vulnerabilities (108)

  • CVE-2025-68665Dec 23, 2025
    affected < 2.95.12-r4fixed 2.95.12-r4

    LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and prior to langchain versions 0.3.37 and 1.2.3, a serialization injection vulnerability exists in LangChain JS's toJSON() method (and subsequently when string-ify

  • CVE-2025-68130HigDec 16, 2025
    affected < 2.95.12-r3fixed 2.95.12-r3

    tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27.0 and prior to versions 10.45.3 and 11.8.0, a A prototype pollution vulnerability exists in `@trpc/server`'s `formDataToObject` function, which is used by the

  • CVE-2025-61729Dec 2, 2025
    affected < 2.95.12-r1fixed 2.95.12-r1

    Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a

  • CVE-2025-66400Dec 1, 2025
    affected < 2.95.12-r1fixed 2.95.12-r1

    mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the p

  • CVE-2025-62522MedOct 20, 2025
    affected < 2.95.12-r28fixed 2.95.12-r28

    Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent i

  • CVE-2025-58752Sep 8, 2025
    affected < 2.95.12-r28fixed 2.95.12-r28

    Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.ho

  • CVE-2025-58751Sep 8, 2025
    affected < 2.95.12-r28fixed 2.95.12-r28

    Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network

  • CVE-2025-24010Jan 20, 2025
    affected < 2.95.12-r28fixed 2.95.12-r28

    Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6

Page 6 of 6