VYPR

apk package

chainguard/py3.12-duplicity

pkg:apk/chainguard/py3.12-duplicity

Vulnerabilities (5)

  • CVE-2026-0994HigJan 23, 2026
    affected < 3.0.7-r2fixed 3.0.7-r2

    A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling l

  • CVE-2026-24049Jan 22, 2026
    affected < 3.0.7-r2fixed 3.0.7-r2

    wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the fil

  • CVE-2026-23949Jan 20, 2026
    affected < 3.0.7-r2fixed 3.0.7-r2

    jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `jaraco.context.tarball()` function starting in version 5.2.0 and prior to version 6.1.0. The vulnerability may allow atta

  • CVE-2026-23490Jan 16, 2026
    affected < 3.0.7-r2fixed 3.0.7-r2

    pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

  • CVE-2026-21226Jan 13, 2026
    affected < 3.0.7-r2fixed 3.0.7-r2

    Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.