apk package
chainguard/tempo-fips-2.8-query
pkg:apk/chainguard/tempo-fips-2.8-query
Vulnerabilities (42)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-25679 | Hig | 7.5 | < 2.8.3-r1 | 2.8.3-r1 | Mar 6, 2026 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | |
| CVE-2026-27141 | Hig | 7.5 | < 2.8.3-r1 | 2.8.3-r1 | Feb 26, 2026 | Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic |
- affected < 2.8.3-r1fixed 2.8.3-r1
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
- affected < 2.8.3-r1fixed 2.8.3-r1
Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic
Page 3 of 3