VYPR

apk package

chainguard/podman-fips

pkg:apk/chainguard/podman-fips

Vulnerabilities (64)

  • CVE-2026-24137MedJan 23, 2026
    affected < 5.7.1-r4fixed 5.7.1-r4

    sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. It constructs a filesystem path by joining a cache base directory with a target na

  • CVE-2026-22772MedJan 12, 2026
    affected < 5.7.1-r3fixed 5.7.1-r3

    Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal servic

  • CVE-2025-4953HigSep 16, 2025
    affected < 6.0.0-r0fixed 6.0.0-r0

    A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the c

  • CVE-2024-3056HigAug 2, 2024
    affected < 6.0.0-r0fixed 6.0.0-r0

    A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious container will continue to exh

Page 4 of 4