VYPR

apk package

chainguard/pelias-api

pkg:apk/chainguard/pelias-api

Vulnerabilities (41)

  • CVE-2025-13465MedJan 21, 2026
    affected < 7.6.0-r1fixed 7.6.0-r1

    Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwritin

Page 3 of 3