VYPR

apk package

chainguard/linkerd2-cni-plugin

pkg:apk/chainguard/linkerd2-cni-plugin

Vulnerabilities (43)

  • CVE-2025-47912MedOct 29, 2025
    affected < 1.6.4-r3fixed 1.6.4-r3

    The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresse

  • CVE-2025-47910MedSep 22, 2025
    affected < 1.6.4-r2fixed 1.6.4-r2

    When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended sec

  • CVE-2025-58160LowAug 29, 2025
    affected < 1.6.4-r1fixed 1.6.4-r1

    tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be i

Page 3 of 3