VYPR

apk package

chainguard/nemo

pkg:apk/chainguard/nemo

Vulnerabilities (221)

  • CVE-2026-84304HigSep 1, 2026
    affected < 2.7.3-r26fixed 2.7.3-r26

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain

  • CVE-2026-81727HigAug 27, 2026
    affected < 2.7.3-r27fixed 2.7.3-r27

    NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a sha

  • CVE-2026-81724MedAug 27, 2026
    affected < 2.7.3-r27fixed 2.7.3-r27

    NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets

  • CVE-2026-81723LowAug 27, 2026
    affected < 2.7.3-r27fixed 2.7.3-r27

    NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files to cause severe CPU consumption and denial of serv

  • CVE-2026-81722HigAug 27, 2026
    affected < 2.7.3-r27fixed 2.7.3-r27

    nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' characters on every call, and _measure() invokes it f

  • CVE-2026-79675CriAug 25, 2026
    affected < 2.7.3-r27fixed 2.7.3-r27

    NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to

  • CVE-2026-78680HigAug 25, 2026
    affected < 2.7.3-r27fixed 2.7.3-r27

    NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary in the search path or current working direc

  • CVE-2026-66393HigAug 22, 2026
    affected < 2.7.2-r1fixed 2.7.2-r1

    NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unh

  • CVE-2026-71514LowAug 22, 2026
    affected < 2.7.3-r27fixed 2.7.3-r27

    NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result with the builtin open() rather than the path

  • CVE-2026-71513HigAug 22, 2026
    affected < 2.7.3-r27fixed 2.7.3-r27

    NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attacker

  • CVE-2026-68508HigAug 21, 2026
    affected < 2.7.3-r25fixed 2.7.3-r25

    Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instantiate2.py, allowing attacker-controlled targe

  • CVE-2026-72818HigAug 20, 2026
    affected < 2.7.3-r27fixed 2.7.3-r27

    The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label sepa

  • CVE-2026-71428CriAug 20, 2026
    affected < 2.7.3-r28fixed 2.7.3-r28

    The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partition_md is fetched without host vali

  • CVE-2026-46603HigAug 14, 2026
    affected < 2.7.3-r21fixed 2.7.3-r21

    VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.

  • CVE-2026-56865HigAug 13, 2026
    affected < 2.7.3-r26fixed 2.7.3-r26

    A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious modul

  • CVE-2026-56864HigAug 13, 2026
    affected < 2.7.3-r26fixed 2.7.3-r26

    A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order

  • CVE-2026-56862HigAug 13, 2026
    affected < 2.7.3-r26fixed 2.7.3-r26

    Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indef

  • CVE-2026-56860MedAug 13, 2026
    affected < 2.7.3-r26fixed 2.7.3-r26

    Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-b

  • CVE-2026-56859HigAug 13, 2026
    affected < 2.7.3-r26fixed 2.7.3-r26

    Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

  • CVE-2026-56858MedAug 13, 2026
    affected < 2.7.3-r26fixed 2.7.3-r26

    Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

Page 1 of 12