VYPR

apk package

chainguard/traccar-fips

pkg:apk/chainguard/traccar-fips

Vulnerabilities (14)

  • CVE-2026-10051Jul 29, 2026
    affected < 6.14.5-r3fixed 6.14.5-r3

    In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the trailers of the first request. Subsequent request that do have trai

  • CVE-2026-59949medJul 24, 2026
    affected < 6.14.5-r4fixed 6.14.5-r4

    ### Summary Insufficient validation of byte array arguments in JNI-based XXHash implementations in lz4-java 1.11.0 and earlier allows callers to crash the JVM by passing an invalid array reference or invalid range to native XXHash methods. This affects applications where an att

  • CVE-2026-56745Jul 23, 2026
    affected < 6.14.5-r2fixed 6.14.5-r2

    Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a

  • CVE-2026-56746Jul 23, 2026
    affected < 6.14.5-r2fixed 6.14.5-r2

    Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortC

  • CVE-2026-55833Jul 21, 2026
    affected < 6.14.5-r2fixed 6.14.5-r2

    Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the

  • CVE-2026-55831Jul 21, 2026
    affected < 6.14.5-r2fixed 6.14.5-r2

    Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting

  • CVE-2026-8384Jul 18, 2026
    affected < 6.14.5-r3fixed 6.14.5-r3

    In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as it will not serve the secret.t

  • CVE-2026-6790Jul 18, 2026
    affected < 6.14.5-r3fixed 6.14.5-r3

    In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present). This was not enforced in earlier HTTP RFC (for example, in RFC 2616), but it is in the latest R

  • CVE-2026-59921modJul 9, 2026
    affected < 6.14.5-r2fixed 6.14.5-r2

    io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

  • CVE-2026-59901impJul 9, 2026
    affected < 6.14.5-r2fixed 6.14.5-r2

    io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)

  • CVE-2026-59900modJul 9, 2026
    affected < 6.14.5-r2fixed 6.14.5-r2

    io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2

  • CVE-2026-59899impJul 9, 2026
    affected < 6.14.5-r2fixed 6.14.5-r2

    io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)

  • CVE-2026-59898modJul 9, 2026
    affected < 6.14.5-r2fixed 6.14.5-r2

    io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)

  • CVE-2026-54291Jul 7, 2026
    affected < 6.14.5-r1fixed 6.14.5-r1

    pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting i