VYPR

apk package

chainguard/logstash-8.19-with-output-opensearch

pkg:apk/chainguard/logstash-8.19-with-output-opensearch

Vulnerabilities (87)

  • CVE-2025-58057HigSep 4, 2025
    affected < 8.19.3-r1fixed 8.19.3-r1

    Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with s

  • CVE-2025-58056HigSep 3, 2025
    affected < 8.19.3-r1fixed 8.19.3-r1

    Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, Netty incorrectly accepts standalone newline characters (LF) as a ch

  • CVE-2025-8916MedAug 13, 2025
    affected < 8.19.19-r0fixed 8.19.19-r0

    Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API m

  • CVE-2025-46551LowMay 7, 2025
    affected < 8.19.19-r0fixed 8.19.19-r0

    JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRuby versions starting in 9.3.4.0 prior to 9.4.12.1 and 10.0.0.0 prior to 10.0.0.1), when verifying SSL

  • CVE-2025-27221LowMar 4, 2025
    affected < 8.19.19-r0fixed 8.19.19-r0

    In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

  • CVE-2025-27220MedMar 4, 2025
    affected < 8.19.19-r0fixed 8.19.19-r0

    In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

  • CVE-2025-27219MedMar 4, 2025
    affected < 8.19.19-r0fixed 8.19.19-r0

    In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource

Page 5 of 5