VYPR

apk package

chainguard/zaproxy

pkg:apk/chainguard/zaproxy

Vulnerabilities (6)

  • CVE-2026-59889MedJul 14, 2026
    affected < 2.17.0-r10fixed 2.17.0-r10

    jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and call

  • CVE-2025-48924MedJul 11, 2025
    affected < 2.17.0-r2fixed 2.17.0-r2

    Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowErr

  • CVE-2025-48734HigMay 28, 2025
    affected < 2.17.0-r0fixed 2.17.0-r0

    Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was no

  • CVE-2024-6763LowOct 14, 2024
    affected < 2.17.0-r5fixed 2.17.0-r5

    Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviour of HttpURI differs fro

  • CVE-2020-13956MedDec 2, 2020
    affected < 2.17.0-r10fixed 2.17.0-r10

    Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

  • CVE-2012-5783Nov 4, 2012
    affected < 2.16.0-r0fixed 2.16.0-r0

    Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows m