VYPR

apk package

chainguard/pghero-fips

pkg:apk/chainguard/pghero-fips

Vulnerabilities (6)

  • CVE-2026-61666HigAug 17, 2026
    affected < 3.8.0-r2fixed 3.8.0-r2

    websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSo

  • CVE-2026-73648MedAug 13, 2026
    affected < 3.8.0-r6fixed 3.8.0-r6

    rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href a

  • CVE-2026-73491LowAug 12, 2026
    affected < 3.8.0-r4fixed 3.8.0-r4

    Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split or prefixed with the HTML5 named whitespace

  • CVE-2026-73490MedAug 12, 2026
    affected < 3.8.0-r4fixed 3.8.0-r4

    Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href attribute on SVG use and feImage elements, while brow

  • CVE-2026-66066CriJul 30, 2026
    affected < 3.8.0-r3fixed 3.8.0-r3

    Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming appl

  • CVE-2026-54696LowJun 30, 2026
    affected < 3.8.0-r5fixed 3.8.0-r5

    Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized streamed object. When streaming to an IO JSON.dump(obj, io) and JSON::State#generate(obj, io) can write past the