VYPR

apk package

chainguard/tileserver-gl-fips

pkg:apk/chainguard/tileserver-gl-fips

Vulnerabilities (65)

  • CVE-2025-25290MedFeb 14, 2025
    affected < 5.4.0-r2fixed 5.4.0-r2

    @octokit/request sends parameterized requests to GitHub’s APIs with sensible defaults in browsers and Node. Starting in version 1.0.0 and prior to versions 9.2.1 and 8.4.1, the regular expression `/<([^>]+)>; rel="deprecation"/` used to match the `link` header in HTTP responses i

  • CVE-2025-25289MedFeb 14, 2025
    affected < 5.4.0-r2fixed 5.4.0-r2

    @octokit/request-error is an error class for Octokit request errors. Starting in version 1.0.0 and prior to version 6.1.7, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the processing of HTTP request headers. By sending an authorization header containing

  • CVE-2025-25288MedFeb 14, 2025
    affected < 5.4.0-r2fixed 5.4.0-r2

    @octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.0.0 and prior to 11.4.1 of the npm package `@octokit/plugin-paginate-rest`, when calling `octokit.paginate.iterator()`, a specially crafted `octokit` instance—p

  • CVE-2024-52798HigDec 5, 2024
    affected < 5.1.1-r0fixed 5.1.1-r0

    path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path

  • CVE-2024-21538HigNov 8, 2024
    affected < 5.0.0-r1fixed 5.0.0-r1

    Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted

Page 4 of 4