VYPR

rpm package

opensuse/flux2-cli&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/flux2-cli&distro=openSUSE%20Tumbleweed

Vulnerabilities (3)

  • CVE-2026-45571MedMay 27, 2026
    affected < 2.8.8-1.1fixed 2.8.8-1.1

    go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These v

  • CVE-2026-45570CriMay 27, 2026
    affected < 2.8.8-1.1fixed 2.8.8-1.1

    go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A reposito

  • CVE-2026-45022HigMay 27, 2026
    affected < 2.8.7-1.1fixed 2.8.7-1.1

    go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous or malformed headers, go-git’s decoded representa