VYPR

apk package

chainguard/privatebin

pkg:apk/chainguard/privatebin

Vulnerabilities (3)

  • CVE-2026-55767Jun 19, 2026
    affected < 2.0.4-r2fixed 2.0.4-r2

    ### Impact `CookieJar` incorrectly accepts cookies with a dot-only `Domain` attribute, such as `Domain=.`, `Domain=..`, `Domain=...`, and whitespace-padded variants such as `Domain= . `. In affected versions, `SetCookie::matchesDomain()` removes leading dots from the cookie doma

  • CVE-2026-55568Jun 19, 2026
    affected < 2.0.4-r2fixed 2.0.4-r2

    ### Impact The built-in cURL handlers (`GuzzleHttp\Handler\CurlHandler` and `GuzzleHttp\Handler\CurlMultiHandler`, used by default whenever the PHP cURL extension is available) accept an `https://` proxy — a proxy reached over a TLS-encrypted connection — through the `proxy` req

  • CVE-2026-48998MedJun 11, 2026
    affected < 2.0.4-r2fixed 2.0.4-r2

    guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. An attacker can provide a malformed Host he