VYPR

apk package

chainguard/openstack-nova-2025.1

pkg:apk/chainguard/openstack-nova-2025.1

Vulnerabilities (10)

  • CVE-2026-69249HigAug 3, 2026
    affected < 31.3.0_git20260717-r3fixed 31.3.0_git20260717-r3

    python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candida

  • CVE-2026-69248MedAug 3, 2026
    affected < 31.3.0_git20260717-r3fixed 31.3.0_git20260717-r3

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptog

  • CVE-2026-69247HigAug 3, 2026
    affected < 31.3.0_git20260717-r3fixed 31.3.0_git20260717-r3

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguish

  • CVE-2026-59939HigJul 8, 2026
    affected < 31.3.0_git20260717-r1fixed 31.3.0_git20260717-r1

    httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server

  • CVE-2015-3280Oct 26, 2015
    affected < 0fixed 0

    OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.

  • CVE-2015-0259Apr 1, 2015
    affected < 0fixed 0

    OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.

  • CVE-2014-3708Oct 31, 2014
    affected < 0fixed 0

    OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.

  • CVE-2014-3517Aug 7, 2014
    affected < 0fixed 0

    api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timin

  • CVE-2013-4179Sep 16, 2013
    affected < 0fixed 0

    The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete

  • CVE-2013-2256Sep 16, 2013
    affected < 0fixed 0

    OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unsp