rpm package
opensuse/go-containerregistry&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/go-containerregistry&distro=openSUSE%20Tumbleweed
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-63209 | Hig | 7.5 | < 0.22.1-2.1 | 0.22.1-2.1 | Sep 29, 2026 | compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Enco | |
| CVE-2025-22868 | Hig | 7.5 | < 0.20.3-2.1 | 0.20.3-2.1 | Feb 26, 2025 | An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing. |
- affected < 0.22.1-2.1fixed 0.22.1-2.1
compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Enco
- affected < 0.20.3-2.1fixed 0.20.3-2.1
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.