VYPR

apk package

wolfi/ascan

pkg:apk/wolfi/ascan

Vulnerabilities (2)

  • CVE-2026-55093MedSep 14, 2026
    affected < 2.7.2-r1fixed 2.7.2-r1

    Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src/tensors.rs read_tensor for attacker-controlled tensor dimensions, the allocation size, and the repo

  • CVE-2026-55832MedSep 14, 2026
    affected < 2.7.2-r1fixed 2.7.2-r1

    Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location from an ONNX model through onnx/src/tensor.rs get_external_resources and joins the