VYPR

apk package

chainguard/langfuse-fips-4-worker

pkg:apk/chainguard/langfuse-fips-4-worker

Vulnerabilities (24)

  • CVE-2026-67213MedJul 29, 2026
    affected < 4.6.0-r2fixed 4.6.0-r2

    nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An a

  • CVE-2026-54272MedJul 27, 2026
    affected < 4.4.0-r0fixed 4.4.0-r0

    ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies an address by matching it against a table

  • CVE-2026-14257HigJul 23, 2026
    affected < 4.3.1-r1fixed 4.3.1-r1

    brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps

  • CVE-2026-41907HigApr 24, 2026
    affected < 4.7.1-r1fixed 4.7.1-r1

    uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fi

Page 2 of 2