VYPR

apk package

chainguard/nextcloud-server-31

pkg:apk/chainguard/nextcloud-server-31

Vulnerabilities (56)

  • CVE-2026-73646HigAug 17, 2026
    affected < 31.0.14-r6fixed 31.0.14-r6

    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and load

  • CVE-2026-69246HigAug 3, 2026
    affected < 31.0.14-r6fixed 31.0.14-r6

    Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler

  • CVE-2026-69245MedAug 3, 2026
    affected < 31.0.14-r6fixed 31.0.14-r6

    Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's

  • CVE-2026-69153MedAug 3, 2026
    affected < 31.0.14-r6fixed 31.0.14-r6

    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or d

  • CVE-2026-69152HigAug 3, 2026
    affected < 31.0.14-r6fixed 31.0.14-r6

    The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled in

  • CVE-2026-67354MedAug 1, 2026
    affected < 31.0.14-r5fixed 31.0.14-r5

    guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generat

  • CVE-2026-67353MedAug 1, 2026
    affected < 31.0.14-r5fixed 31.0.14-r5

    guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data i

  • CVE-2026-67339MedAug 1, 2026
    affected < 31.0.14-r5fixed 31.0.14-r5

    guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that

  • CVE-2026-67319LowAug 1, 2026
    affected < 31.0.14-r5fixed 31.0.14-r5

    axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another component. While the top-level merged config uses a null prototype, nested plain obj

  • CVE-2026-67318MedAug 1, 2026
    affected < 31.0.14-r5fixed 31.0.14-r5

    axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node's HTTP/2 request API does not honor the maxBodyLength option and axios's byte-counting stream wrap

  • CVE-2026-67317HigAug 1, 2026
    affected < 31.0.14-r5fixed 31.0.14-r5

    axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egr

  • CVE-2026-67316HigAug 1, 2026
    affected < 31.0.14-r5fixed 31.0.14-r5

    axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()),

  • CVE-2026-67313HigAug 1, 2026
    affected < 31.0.14-r5fixed 31.0.14-r5

    axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack a

  • CVE-2026-67312HigAug 1, 2026
    affected < 31.0.14-r5fixed 31.0.14-r5

    axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json). When an application passes attacker-controlled

  • CVE-2026-67213MedJul 29, 2026
    affected < 31.0.14-r7fixed 31.0.14-r7

    nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An a

  • CVE-2026-45623HigJul 27, 2026
    affected < 31.0.14-r6fixed 31.0.14-r6

    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferen

  • CVE-2026-14257HigJul 23, 2026
    affected < 31.0.14-r6fixed 31.0.14-r6

    brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps

  • CVE-2026-59883MedJul 8, 2026
    affected < 31.0.14-r5fixed 31.0.14-r5

    Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::

  • CVE-2026-13149HigJun 30, 2026
    affected < 31.0.14-r5fixed 31.0.14-r5

    brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause sign

  • CVE-2026-55767MedJun 23, 2026
    affected < 31.0.14-r5fixed 31.0.14-r5

    Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty string

Page 1 of 3