VYPR

rpm package

opensuse/govulncheck-vulndb&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0

Vulnerabilities (1,719)

  • CVE-2025-47911MedFeb 5, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

  • CVE-2025-61732HigFeb 5, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

  • CVE-2025-22873LowFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or f

  • CVE-2026-25579MedFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users can crash the Navidrome server by supplying an excessively large size parameter to /rest/getCoverArt or to a shared-image URL (/share/img/). When proces

  • CVE-2026-25578MedFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, a cross-site scripting vulnerability in the frontend allows a malicious attacker to inject code through the comment metadata of a song to exfiltrate user credentials. This issue h

  • CVE-2026-25538HigFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists in Devtron's Attributes API interface, allowing any authenticated user (including low-privileged CI/CD Developers) to obtain the global API Token signing key by

  • CVE-2026-25518MedFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. In versions from 1.18.0 to before 1.18.5 and from 1.19.0 to before 1.19.3, the cert-manager-controller

  • CVE-2026-25499HigFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configuration documentation, the sudoer line suggested is insecure and can result in escaping the folder using ../, allowing any files on the system to be edited. This

  • CVE-2026-25161HigFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application contains path traversal vulnerability in multiple file operation handlers. An authenticated attacker can bypass directory-level authorisation by inje

  • CVE-2026-25160CriFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certificate verification by default for all outgoing storage driver communications, making the system vulnerable to Man-in-the-Middle (M

  • CVE-2026-25145MedFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to before 0.40.3, an attacker who can influence a melange configuration file (e.g., through pull request-driven CI or build-as-a-service scenarios) could read arbitrary files from the host

  • CVE-2026-25143HigFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacker who can influence inputs to the patch pipeline could execute arbitrary shell commands on the build host. The patch pipeline in pkg/build/pipelines/patch.yaml

  • CVE-2026-24844HigFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input values, but not modify pipeline definitions, could execute arbitrary shell commands if the pipeline uses ${{vars.*}} or ${{inputs.*

  • CVE-2026-24843HigFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could write files outside the intended workspace directory on the host. The retrieveWorkspace function ext

  • CVE-2026-25140HigFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or compromises an APK repository used by apko could cause resource exhaustion on the build host. The ExpandApk function in pkg/apk/ex

  • CVE-2026-25122MedFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.0, expandapk.Split drains the first gzip stream of an APK archive via io.Copy(io.Discard, gzi) without explicit bounds. With an attacker-controlled input stream,

  • CVE-2026-25121HigFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerability was discovered in apko's dirFS filesystem abstraction. An attacker who can supply a malicious APK package (e.g., via a compromi

  • CVE-2026-24735HigFeb 4, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. An unauthenticated API endpoint incorrectly exposes full revision history for deleted content. This allows unauthorized user to ret

  • CVE-2026-24514MedFeb 3, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingr

  • CVE-2026-24513LowFeb 3, 2026
    affected < 0.0.20260723T184607-160000.1.1fixed 0.0.20260723T184607-160000.1.1

    A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific misconfiguration. If the ingress-nginx controller is configured with a default custom-errors configuration that

Page 63 of 86