VYPR

apk package

chainguard/ranger

pkg:apk/chainguard/ranger

Vulnerabilities (7)

  • CVE-2026-49844MedJul 10, 2026
    affected < 2.9.0-r5fixed 2.9.0-r5

    Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover

  • CVE-2026-10532LowJun 1, 2026
    affected < 2.9.0-r5fixed 2.9.0-r5

    Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or

  • CVE-2026-9828LowMay 28, 2026
    affected < 2.9.0-r5fixed 2.9.0-r5

    Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or

  • CVE-2026-1225LowJan 22, 2026
    affected < 2.9.0-r5fixed 2.9.0-r5

    ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file. The instanti

  • CVE-2025-12183HigNov 28, 2025
    affected < 2.9.0-r5fixed 2.9.0-r5

    Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

  • CVE-2025-31672MedApr 9, 2025
    affected < 2.9.0-r5fixed 2.9.0-r5

    Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in t

  • CVE-2024-47554MedOct 3, 2024
    affected < 0fixed 0

    Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are