VYPR

apk package

chainguard/mlrun-api

pkg:apk/chainguard/mlrun-api

Vulnerabilities (4)

  • CVE-2026-15925CriJul 16, 2026
    affected < 1.11.0-r4fixed 1.11.0-r4

    Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access cou

  • CVE-2026-48818HigJun 17, 2026
    affected < 0fixed 0

    Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the ser

  • CVE-2026-10143HigJun 10, 2026
    affected < 1.11.0-r5fixed 1.11.0-r5

    kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the client event loop by supplying an excessively large iteration count. In scram.py, ScramClient.process_serv

  • CVE-2026-10142HigJun 10, 2026
    affected < 1.11.0-r5fixed 1.11.0-r5

    kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length value without bounds validation. Attackers