VYPR

apk package

chainguard/nextcloud-server-33

pkg:apk/chainguard/nextcloud-server-33

Vulnerabilities (82)

  • CVE-2026-49458MedJul 14, 2026
    affected < 33.0.6-r0fixed 33.0.6-r0

    DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms,

  • CVE-2026-46644MedJul 14, 2026
    affected < 33.0.5-r2fixed 33.0.5-r2

    Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enf

  • CVE-2026-48736HigJul 14, 2026
    affected < 33.0.5-r4fixed 33.0.5-r4

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compa

  • CVE-2026-45071HigJul 14, 2026
    affected < 33.0.5-r2fixed 33.0.5-r2

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external entity resolution and allowing a

  • CVE-2026-45068HigJul 14, 2026
    affected < 33.0.5-r2fixed 33.0.5-r2

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appended recipient addresses to the sendmail command line without a -- end-of-options separator, allowing an

  • CVE-2026-45070MedJul 14, 2026
    affected < 33.0.5-r2fixed 33.0.5-r2

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a c

  • CVE-2026-45067MedJul 14, 2026
    affected < 33.0.5-r2fixed 33.0.5-r2

    ### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and throwing on invalid input, so developers treat it as a security boundary. The c

  • CVE-2026-45065MedJul 14, 2026
    affected < 33.0.5-r2fixed 33.0.5-r2

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw requirement plus $; with ungrouped alternations, middle

  • CVE-2026-59879HigJul 8, 2026
    affected < 33.0.7-r1fixed 33.0.7-r1

    Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, ca

  • CVE-2026-59880HigJul 8, 2026
    affected < 33.0.7-r1fixed 33.0.7-r1

    Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.Set keep keys that share the same 32-bit hash in a HashCollisionNode collision bucket that is scanned linearly, allowing an attacker who controls keys inserted i

  • CVE-2026-13149HigJun 30, 2026
    affected < 33.0.6-r9fixed 33.0.6-r9

    brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause sign

  • CVE-2026-55767MedJun 23, 2026
    affected < 33.0.5-r3fixed 33.0.5-r3

    Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty string

  • CVE-2026-55766MedJun 23, 2026
    affected < 33.0.5-r3fixed 33.0.5-r3

    guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reason phrase. If an application placed attack

  • CVE-2026-55568MedJun 23, 2026
    affected < 33.0.5-r3fixed 33.0.5-r3

    Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the Proxy-Authorization header, proxy userinfo in the proxy URL, or

  • CVE-2026-55599MedJun 22, 2026
    affected < 33.0.5-r3fixed 33.0.5-r3

    phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Authority Information Access (AIA) extension

  • CVE-2026-53632MedJun 22, 2026
    affected < 33.0.6-r2fixed 33.0.6-r2

    launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host

  • CVE-2026-53571HigJun 22, 2026
    affected < 33.0.6-r2fixed 33.0.6-r2

    Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, includin

  • CVE-2026-12143HigJun 12, 2026
    affected < 33.0.6-r3fixed 33.0.6-r3

    form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line fee

  • CVE-2026-54133CriJun 12, 2026
    affected < 33.0.6-r9fixed 33.0.6-r9

    jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 can generate and execute attacker-controlled PHP code when `JmesPath\CompilerRuntim

  • CVE-2026-44496HigJun 11, 2026
    affected < 33.0.6-r0fixed 33.0.6-r0

    Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments

Page 2 of 5