VYPR

apk package

chainguard/wazuh-manager-framework

pkg:apk/chainguard/wazuh-manager-framework

Vulnerabilities (24)

  • CVE-2026-34073MedMar 31, 2026
    affected < 4.14.4-r1fixed 4.14.4-r1

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently

  • CVE-2026-25645MedMar 25, 2026
    affected < 4.14.4-r1fixed 4.14.4-r1

    Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without valid

  • CVE-2026-4539LowMar 22, 2026
    affected < 4.14.6-r1fixed 4.14.6-r1

    A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit

  • CVE-2025-47273HigMay 17, 2025
    affected < 4.14.6-r1fixed 4.14.6-r1

    setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on

Page 2 of 2