VYPR

apk package

chainguard/pinot

pkg:apk/chainguard/pinot

Vulnerabilities (64)

  • CVE-2025-67721HigDec 12, 2025
    affected < 1.5.0-r0fixed 1.5.0-r0

    Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. In versions 3.3 and below, incorrect handling of malformed data in Java-based decompressor implementations for Snappy and LZ4 allow remote attackers to read previous buffe

  • CVE-2025-59419MedOct 15, 2025
    affected < 1.5.0-r19fixed 1.5.0-r19

    Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r) and Line Feed (\n) char

  • CVE-2025-8916MedAug 13, 2025
    affected < 1.5.0-r0fixed 1.5.0-r0

    Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy Castle Inc. BCPKIX FIPS bcpkix-fips on All (API m

  • CVE-2024-6763LowOct 14, 2024
    affected < 1.5.1-r0fixed 1.5.1-r0

    Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs fro

Page 4 of 4