VYPR

apk package

wolfi/nextcloud-server-32

pkg:apk/wolfi/nextcloud-server-32

Vulnerabilities (55)

  • CVE-2026-76172HigAug 24, 2026
    affected < 32.0.14-r1fixed 32.0.14-r1

    fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme c

  • CVE-2026-75975HigAug 24, 2026
    affected < 32.0.14-r1fixed 32.0.14-r1

    fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 desti

  • CVE-2026-75931HigAug 24, 2026
    affected < 32.0.14-r1fixed 32.0.14-r1

    fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own en

  • CVE-2026-75899HigAug 24, 2026
    affected < 32.0.14-r1fixed 32.0.14-r1

    fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different network

  • CVE-2026-73646HigAug 17, 2026
    affected < 32.0.13-r2fixed 32.0.13-r2

    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and load

  • CVE-2026-73089HigAug 11, 2026
    affected < 32.0.14-r2fixed 32.0.14-r2

    Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, al

  • CVE-2026-73088HigAug 11, 2026
    affected < 32.0.14-r2fixed 32.0.14-r2

    Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-sta

  • CVE-2026-69153MedAug 3, 2026
    affected < 32.0.13-r4fixed 32.0.13-r4

    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or d

  • CVE-2026-67355MedAug 1, 2026
    affected < 32.0.12-r6fixed 32.0.12-r6

    guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disc

  • CVE-2026-67354MedAug 1, 2026
    affected < 32.0.12-r6fixed 32.0.12-r6

    guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generat

  • CVE-2026-67353MedAug 1, 2026
    affected < 32.0.12-r6fixed 32.0.12-r6

    guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data i

  • CVE-2026-67339MedAug 1, 2026
    affected < 32.0.12-r6fixed 32.0.12-r6

    guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that

  • CVE-2026-67320HigAug 1, 2026
    affected < 32.0.12-r6fixed 32.0.12-r6

    axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immutable interceptor pattern such

  • CVE-2026-67319LowAug 1, 2026
    affected < 32.0.12-r6fixed 32.0.12-r6

    axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another component. While the top-level merged config uses a null prototype, nested plain obj

  • CVE-2026-67318MedAug 1, 2026
    affected < 32.0.12-r6fixed 32.0.12-r6

    axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node's HTTP/2 request API does not honor the maxBodyLength option and axios's byte-counting stream wrap

  • CVE-2026-67317HigAug 1, 2026
    affected < 32.0.12-r6fixed 32.0.12-r6

    axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egr

  • CVE-2026-67316HigAug 1, 2026
    affected < 32.0.12-r6fixed 32.0.12-r6

    axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()),

  • CVE-2026-67315HigAug 1, 2026
    affected < 32.0.12-r6fixed 32.0.12-r6

    axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially

  • CVE-2026-67314MedAug 1, 2026
    affected < 32.0.12-r6fixed 32.0.12-r6

    axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-pollution primitive and makes an axios reques

  • CVE-2026-67313HigAug 1, 2026
    affected < 32.0.12-r6fixed 32.0.12-r6

    axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack a

Page 1 of 3