VYPR

apk package

chainguard/langfuse-fips-3

pkg:apk/chainguard/langfuse-fips-3

Vulnerabilities (104)

  • CVE-2025-68130HigDec 16, 2025
    affected < 3.141.0-r0fixed 3.141.0-r0

    tRPC allows users to build and consume fully typesafe APIs without schemas or code generation. Starting in version 10.27.0 and prior to versions 10.45.3 and 11.8.0, a A prototype pollution vulnerability exists in `@trpc/server`'s `formDataToObject` function, which is used by the

  • CVE-2025-65945HigDec 4, 2025
    affected < 3.138.0-r0fixed 3.138.0-r0

    auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they us

  • CVE-2025-61729HigDec 2, 2025
    affected < 3.135.1-r1fixed 3.135.1-r1

    Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a

  • CVE-2025-5889LowJun 9, 2025
    affected < 3.179.1-r2fixed 3.179.1-r2

    A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be l

Page 6 of 6