VYPR

apk package

wolfi/aws-eks-pod-identity-agent

pkg:apk/wolfi/aws-eks-pod-identity-agent

Vulnerabilities (22)

  • CVE-2025-22874HigJun 11, 2025
    affected < 0.1.30-r1fixed 0.1.30-r1

    Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

  • CVE-2025-30204HigMar 21, 2025
    affected < 0.1.23-r1fixed 0.1.23-r1

    golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a maliciou

Page 2 of 2