VYPR

apk package

chainguard/wazuh-manager-framework-fips

pkg:apk/chainguard/wazuh-manager-framework-fips

Vulnerabilities (24)

  • CVE-2026-4539LowMar 22, 2026
    affected < 4.14.7-r0fixed 4.14.7-r0

    A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit

  • CVE-2026-24049HigJan 22, 2026
    affected < 4.14.7-r2fixed 4.14.7-r2

    wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the fil

  • CVE-2026-23949HigJan 20, 2026
    affected < 4.14.7-r2fixed 4.14.7-r2

    jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `jaraco.context.tarball()` function starting in version 5.2.0 and prior to version 6.1.0. The vulnerability may allow atta

  • CVE-2025-47273HigMay 17, 2025
    affected < 4.14.6-r3fixed 4.14.6-r3

    setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on

Page 2 of 2