VYPR

Go modules package

github.com/zarf-dev/zarf

pkg:golang/github.com/zarf-dev/zarf

Vulnerabilities (1)

  • CVE-2026-40090HigApr 15, 2026
    affected >= 0.23.0, < 0.74.2fixed 0.74.2

    Zarf is an Airgap Native Packager Manager for Kubernetes. Versions 0.23.0 through 0.74.1 contain an arbitrary file write vulnerability in the zarf package inspect sbom and zarf package inspect documentation subcommands. These subcommands output file paths are constructed by joini