VYPR

rpm package

opensuse/alloy&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/alloy&distro=openSUSE%20Tumbleweed

Vulnerabilities (55)

  • CVE-2026-48496MedSep 11, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to open a nonregular mapping file, such as a FI

  • CVE-2026-89090MedSep 11, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outsid

  • CVE-2026-56854HigAug 28, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCal

  • CVE-2026-37236CriAug 28, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the

  • CVE-2026-81521MedAug 27, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input a

  • CVE-2026-75889HigAug 27, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sends its contents as a bearer token to an att

  • CVE-2026-75890Aug 18, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that already had an existing CVE assignment.

  • CVE-2026-71557MedAug 7, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example con

  • CVE-2026-71556HigAug 7, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a malicious

  • CVE-2026-56852HigJul 21, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

  • CVE-2026-46600HigJul 21, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

  • CVE-2026-41178MedJun 4, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the iss

  • CVE-2026-10722LowJun 3, 2026
    affected < 1.17.1-1.1fixed 1.17.1-1.1

    A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be pe

  • CVE-2026-45686HigJun 2, 2026
    affected < 1.17.0-1.1fixed 1.17.0-1.1

    OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. W

  • CVE-2026-45685HigJun 2, 2026
    affected < 1.17.0-1.1fixed 1.17.0-1.1

    OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to c

  • CVE-2026-45684MedJun 2, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by reading only the first iovec entry but using the total iov_iter.count as the copy leng

  • CVE-2026-45683LowJun 2, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_probe_read instead of bpf_probe_read_user. An instrumented local process can theref

  • CVE-2026-45682MedJun 2, 2026
    affected < 1.17.0-1.1fixed 1.17.0-1.1

    OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking never removes keys from its insertion-order queue when entries are deleted. In l

  • CVE-2026-45681MedJun 2, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the per-CPU message-buffer fallback path uses a 256-byte backup buffer but preserves the original payload size, which can be up to 8KB. If a CPU mismatch

  • CVE-2026-45680MedJun 2, 2026
    affected < 1.19.2-1.1fixed 1.19.2-1.1

    OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observations by looping once per recorded run count. On busy systems, the run-count delta can become very large,

Page 1 of 3