VYPR

apk package

chainguard/wazuh-dashboard-dashboards-visualizations-fips

pkg:apk/chainguard/wazuh-dashboard-dashboards-visualizations-fips

Vulnerabilities (27)

  • CVE-2026-44240HigMay 12, 2026
    affected < 4.14.7-r9fixed 4.14.7-r9

    basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner p

  • CVE-2026-33228CriMar 20, 2026
    affected < 4.14.6-r1fixed 4.14.6-r1

    flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, a

  • CVE-2026-32141HigMar 12, 2026
    affected < 4.14.6-r1fixed 4.14.6-r1

    flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, caus

  • CVE-2026-2391LowFeb 12, 2026
    affected < 4.14.7-r14fixed 4.14.7-r14

    ### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass

  • CVE-2025-69873LowFeb 11, 2026
    affected < 4.14.7-r10fixed 4.14.7-r10

    ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp(

  • CVE-2025-15284LowDec 29, 2025
    affected < 4.14.7-r14fixed 4.14.7-r14

    Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLim

  • CVE-2025-64718MedNov 13, 2025
    affected < 4.14.6-r3fixed 4.14.6-r3

    js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. T

Page 2 of 2