VYPR

rpm package

almalinux/udica

pkg:rpm/almalinux/udica

Vulnerabilities (122)

  • CVE-2026-56862HigAug 13, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indef

  • CVE-2026-56860MedAug 13, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-b

  • CVE-2026-56859HigAug 13, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

  • CVE-2026-56858MedAug 13, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

  • CVE-2026-56853HigAug 13, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

  • CVE-2026-33818HigAug 13, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.

  • CVE-2026-57231HigJun 26, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that usi

  • CVE-2026-42508CriMay 22, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

  • CVE-2026-39835MedMay 22, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

  • CVE-2026-39832CriMay 22, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now

  • CVE-2026-39830CriMay 22, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now

  • CVE-2026-39829HigMay 22, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clien

  • CVE-2026-42499HigMay 7, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

  • CVE-2026-33811HigMay 7, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

  • CVE-2026-32283HigApr 8, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

  • CVE-2026-32281HigApr 8, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root C

  • CVE-2026-32280HigApr 8, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls

  • CVE-2026-34986HigApr 6, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JW

  • CVE-2026-25679HigMar 6, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

  • CVE-2025-68121CriFeb 5, 2026
    affected < 0.2.6-21.module_el8.10.0+4068+0e21408ffixed 0.2.6-21.module_el8.10.0+4068+0e21408f

    During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and

Page 1 of 7