VYPR

apk package

wolfi/nrjmx

pkg:apk/wolfi/nrjmx

Vulnerabilities (4)

  • CVE-2026-64607MedJul 31, 2026
    affected < 2.13.0-r3fixed 2.13.0-r3

    HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient bas

  • CVE-2026-54428HigJul 1, 2026
    affected < 2.13.0-r2fixed 2.13.0-r2

    Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks

  • CVE-2026-54399HigJul 1, 2026
    affected < 2.13.0-r1fixed 2.13.0-r1

    Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of he

  • CVE-2025-48924MedJul 11, 2025
    affected < 2.7.0-r3fixed 2.7.0-r3

    Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowErr