VYPR

apk package

chainguard/node-feature-discovery-fips-0.16-kubectl-nfd

pkg:apk/chainguard/node-feature-discovery-fips-0.16-kubectl-nfd

Vulnerabilities (28)

  • CVE-2025-58186MedOct 29, 2025
    affected < 0.16.9-r1fixed 0.16.9-r1

    Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption.

  • CVE-2025-58185MedOct 29, 2025
    affected < 0.16.9-r1fixed 0.16.9-r1

    Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.

  • CVE-2025-58183MedOct 29, 2025
    affected < 0.16.9-r1fixed 0.16.9-r1

    tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When r

  • CVE-2025-47912MedOct 29, 2025
    affected < 0.16.9-r1fixed 0.16.9-r1

    The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresse

  • CVE-2025-5187MedAug 27, 2025
    affected < 0.16.9-r2fixed 0.16.9-r2

    A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is su

  • CVE-2025-47907HigAug 7, 2025
    affected < 0.16.8-r2fixed 0.16.8-r2

    Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the ex

  • CVE-2025-1767MedMar 13, 2025
    affected < 0fixed 0

    This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using t

  • CVE-2025-22868HigFeb 26, 2025
    affected < 0.16.8-r1fixed 0.16.8-r1

    An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

Page 2 of 2