VYPR

apk package

wolfi/knative-serving-1.18-autoscaler-compat

pkg:apk/wolfi/knative-serving-1.18-autoscaler-compat

Vulnerabilities (3)

  • CVE-2025-47910MedSep 22, 2025
    affected < 1.18.1-r6fixed 1.18.1-r6

    When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended sec

  • CVE-2025-47907Aug 7, 2025
    affected < 1.18.1-r4fixed 1.18.1-r4

    Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the ex

  • CVE-2025-22868Feb 26, 2025
    affected < 0fixed 0

    An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.