VYPR

apk package

wolfi/renovate

pkg:apk/wolfi/renovate

Vulnerabilities (125)

  • CVE-2024-21538HigNov 8, 2024
    affected < 39.22.0-r0fixed 39.22.0-r0

    Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted

  • CVE-2024-41818HigJul 29, 2024
    affected < 38.18.0-r0fixed 38.18.0-r0

    fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.

  • CVE-2024-4067MedMay 14, 2024
    affected < 38.52.0-r0fixed 38.52.0-r0

    The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching w

  • CVE-2024-27307CriMar 6, 2024
    affected < 37.229.2-r0fixed 37.229.2-r0

    JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote

  • CVE-2023-42282CriFeb 8, 2024
    affected < 37.186.1-r0fixed 37.186.1-r0

    The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

Page 7 of 7