VYPR

apk package

chainguard/wazuh-dashboard-anomaly-detection-dashboards-plugin-fips

pkg:apk/chainguard/wazuh-dashboard-anomaly-detection-dashboards-plugin-fips

Vulnerabilities (24)

  • CVE-2026-44240HigMay 12, 2026
    affected < 4.14.7-r9fixed 4.14.7-r9

    basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner p

  • CVE-2026-33672MedMar 26, 2026
    affected < 4.14.7-r11fixed 4.14.7-r11

    Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions

  • CVE-2026-33671HigMar 26, 2026
    affected < 4.14.7-r11fixed 4.14.7-r11

    Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when c

  • CVE-2026-2739MedFeb 20, 2026
    affected < 4.14.7-r14fixed 4.14.7-r14

    This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.

Page 2 of 2