VYPR

apk package

chainguard/trident

pkg:apk/chainguard/trident

Vulnerabilities (22)

  • CVE-2026-29181HigApr 7, 2026
    affected < 26.02.0-r4fixed 26.02.0-r4

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many bagg

  • CVE-2026-2303MedFeb 10, 2026
    affected < 26.02.1-r5fixed 26.02.1-r5

    The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI b

Page 2 of 2