VYPR

apk package

chainguard/mattermost-fips-10.9-compat

pkg:apk/chainguard/mattermost-fips-10.9-compat

Vulnerabilities (6)

  • CVE-2025-58058MedAug 28, 2025
    affected < 10.9.5-r1fixed 10.9.5-r1

    xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the

  • CVE-2025-47907Aug 7, 2025
    affected < 10.9.4-r1fixed 10.9.4-r1

    Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the ex

  • CVE-2025-3445HigApr 13, 2025
    affected < 10.9.2-r1fixed 10.9.2-r1

    A Path Traversal "Zip Slip" vulnerability has been identified in mholt/archiver in Go. This vulnerability allows using a crafted ZIP file containing path traversal symlinks to create or overwrite files with the user's privileges or application utilizing the library. When using t

  • CVE-2025-29923LowMar 20, 2025
    affected < 10.9.2-r1fixed 10.9.2-r1

    go-redis is the official Redis client library for the Go programming language. Prior to 9.5.5, 9.6.3, and 9.7.3, go-redis potentially responds out of order when `CLIENT SETINFO` times out during connection establishment. This can happen when the client is configured to transmit i

  • CVE-2024-0406Apr 6, 2024
    affected < 10.9.2-r1fixed 10.9.2-r1

    A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or applic

  • CVE-2022-31022Jun 1, 2022
    affected < 10.9.2-r1fixed 10.9.2-r1

    Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitation of a node’s filesystem where the bleve index resides, if the user has used bleve’s own HTTP (blev