VYPR

apk package

chainguard/pelias-api

pkg:apk/chainguard/pelias-api

Vulnerabilities (45)

  • CVE-2026-1526HigMar 12, 2026
    affected < 7.6.0-r4fixed 7.6.0-r4

    The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without en

  • CVE-2026-1525MedMar 12, 2026
    affected < 7.6.0-r4fixed 7.6.0-r4

    Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire. Who is impacted: *

  • CVE-2026-26996HigFeb 20, 2026
    affected < 7.6.0-r3fixed 7.6.0-r3

    minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal charact

  • CVE-2026-2391LowFeb 12, 2026
    affected < 7.6.0-r2fixed 7.6.0-r2

    ### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass

  • CVE-2025-13465MedJan 21, 2026
    affected < 7.6.0-r1fixed 7.6.0-r1

    Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwritin

Page 3 of 3