VYPR

apk package

chainguard/saf

pkg:apk/chainguard/saf

Vulnerabilities (82)

  • CVE-2025-58754HigSep 12, 2025
    affected < 1.5.1-r0fixed 1.5.1-r0

    Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire

  • CVE-2025-54798LowAug 7, 2025
    affected < 1.5.1-r0fixed 1.5.1-r0

    tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir parameter. This is fixed in version 0.2.4.

Page 5 of 5