VYPR

apk package

chainguard/ruby3.1-fluentd-kubernetes-daemonset-1.16

pkg:apk/chainguard/ruby3.1-fluentd-kubernetes-daemonset-1.16

Vulnerabilities (9)

  • CVE-2025-58767Sep 17, 2025
    affected < 1.16.8.1.0-r4fixed 1.16.8.1.0-r4

    REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. If you need to parse untrusted XMLs, you may be impacted to these vulnerabilities. The REXML gem 3.4.2 or later include the patches

  • CVE-2025-27788Mar 12, 2025
    affected < 1.16.7.1.1-r1fixed 1.16.7.1.1-r1

    JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted document could cause an out of bound read, most likely resulting in a crash. Versions prior to 2.10.0 are not vulnerable. Version 2.10.2 fixes the problem. No known

  • CVE-2024-49761Oct 28, 2024
    affected < 1.16.6.1.2-r1fixed 1.16.6.1.2-r1

    REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected mainta

  • CVE-2024-47220Sep 22, 2024
    affected < 1.16.6.1.2-r1fixed 1.16.6.1.2-r1

    An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's po

  • CVE-2024-7254Sep 19, 2024
    affected < 1.16.6.1.2-r1fixed 1.16.6.1.2-r1

    Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf

  • CVE-2024-43398Aug 22, 2024
    affected < 1.16.6.1.2-r1fixed 1.16.6.1.2-r1

    REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXML::Document.new, you may be impacted to t

  • CVE-2024-41946Aug 1, 2024
    affected < 1.16.6.1.2-r1fixed 1.16.6.1.2-r1

    REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. The REXML gem 3.3.3 or later include the patch to fix the vulnerability.

  • CVE-2024-41123Aug 1, 2024
    affected < 1.16.6.1.2-r1fixed 1.16.6.1.2-r1

    REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters such as whitespace character, `>]` and `]>`. The REXML gem 3.3.3 or later include the patches to fix these vulnerabilities.

  • CVE-2024-39908Jul 16, 2024
    affected < 1.16.6.1.2-r1fixed 1.16.6.1.2-r1

    REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as `<`, `0` and `%>`. If you need to parse untrusted XMLs, you many be impacted to these vulnerabilities. The REXML gem 3.3.2 or