VYPR

rpm package

almalinux/cockpit-image-builder

pkg:rpm/almalinux/cockpit-image-builder

Vulnerabilities (4)

  • CVE-2026-84292HigSep 2, 2026
    affected < 94.4-1.el10_2fixed 94.4-1.el10_2

    fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting th

  • CVE-2026-76172HigAug 24, 2026
    affected < 94.4-1.el10_2fixed 94.4-1.el10_2

    fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme c

  • CVE-2026-75975HigAug 24, 2026
    affected < 94.4-1.el10_2fixed 94.4-1.el10_2

    fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 desti

  • CVE-2026-75899HigAug 24, 2026
    affected < 94.4-1.el10_2fixed 94.4-1.el10_2

    fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different network