VYPR

apk package

chainguard/logstash-9.5

pkg:apk/chainguard/logstash-9.5

Vulnerabilities (14)

  • CVE-2026-69220HigAug 18, 2026
    affected < 9.5.2-r1fixed 9.5.2-r1

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldVa

  • CVE-2026-69219HigAug 18, 2026
    affected < 9.5.2-r1fixed 9.5.2-r1

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-declared contentLength below Integer.MAX_VA

  • CVE-2026-63337HigAug 18, 2026
    affected < 9.5.2-r1fixed 9.5.2-r1

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted system.describe response and passes it through

  • CVE-2026-63336MedAug 18, 2026
    affected < 9.5.2-r1fixed 9.5.2-r1

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) configure com.rabbitmq.client.TrustEverythi

  • CVE-2026-63335MedAug 18, 2026
    affected < 9.5.2-r1fixed 9.5.2-r1

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processes a content-bearing method and header who

  • CVE-2026-61634NonAug 18, 2026
    affected < 9.5.2-r1fixed 9.5.2-r1

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java

  • CVE-2026-59949MedAug 18, 2026
    affected < 9.5.1-r2fixed 9.5.1-r2

    yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFact

  • CVE-2026-71847HigAug 7, 2026
    affected < 9.5.1-r3fixed 9.5.1-r3

    Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into released storage. When partial_value reconstructs an inco

  • CVE-2026-59901HigJul 29, 2026
    affected < 9.5.0-r1fixed 9.5.0-r1

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently c

  • CVE-2026-59889MedJul 14, 2026
    affected < 9.5.1-r1fixed 9.5.1-r1

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and call

  • CVE-2026-54906CriJun 24, 2026
    affected < 9.5.2-r0fixed 9.5.2-r0

    concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread.

  • CVE-2026-54905MedJun 24, 2026
    affected < 9.5.2-r0fixed 9.5.2-r0

    concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReentrantReadWriteLock can incorrectly grant a write lock after one thread acquires the read lock 32,768 times. The lock stores a thread's local read and write hold counts in one integer. The low

  • CVE-2026-54904HigJun 24, 2026
    affected < 9.5.2-r0fixed 9.5.2-r0

    concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::AtomicReference#update can enter a permanent busy retry loop when the current value is Float::NAN. The issue is caused by the interaction between AtomicReference#update, which retries until compar

  • CVE-2026-54515MedJun 23, 2026
    affected < 9.5.1-r1fixed 9.5.1-r1

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameIn