VYPR

apk package

wolfi/clickhouse-operator-metrics-exporter

pkg:apk/wolfi/clickhouse-operator-metrics-exporter

Vulnerabilities (25)

  • CVE-2025-61726HigJan 28, 2026
    affected < 0.25.6-r1fixed 0.25.6-r1

    The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a la

  • CVE-2025-47910MedSep 22, 2025
    affected < 0.25.3-r2fixed 0.25.3-r2

    When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended sec

  • CVE-2025-4673MedJun 11, 2025
    affected < 0.25.0-r1fixed 0.25.0-r1

    Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

  • CVE-2025-22874HigJun 11, 2025
    affected < 0.25.0-r1fixed 0.25.0-r1

    Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

  • CVE-2025-22872MedApr 16, 2025
    affected < 0.24.5-r1fixed 0.24.5-r1

    The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can resul

Page 2 of 2