VYPR

rpm package

opensuse/helm&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/helm&distro=openSUSE%20Tumbleweed

Vulnerabilities (45)

  • CVE-2026-63209HigSep 29, 2026
    affected < 4.3.0-4.1fixed 4.3.0-4.1

    compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Enco

  • CVE-2026-81872MedSep 16, 2026
    affected < 4.3.0-3.1fixed 4.3.0-3.1

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills its asynchronous export buffer while the exporter is backpressured. NewBa

  • CVE-2026-81871MedSep 16, 2026
    affected < 4.3.0-3.1fixed 4.3.0-3.1

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate environment variables through loadEnvTLS i

  • CVE-2026-81870LowSep 16, 2026
    affected < 4.3.0-4.1fixed 4.3.0-4.1

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client conf

  • CVE-2026-85732MedSep 16, 2026
    affected < 4.3.0-2.1fixed 4.3.0-2.1

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. Tags, Referrers, and Repositories paginatio

  • CVE-2026-84445HigSep 14, 2026
    affected < 4.2.4-3.1fixed 4.2.4-3.1

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/se

  • CVE-2026-56855HigSep 2, 2026
    affected < 4.3.0-1.1fixed 4.3.0-1.1

    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and t

  • CVE-2026-84304HigSep 1, 2026
    affected < 4.2.4-3.1fixed 4.2.4-3.1

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain

  • CVE-2026-84303MedSep 1, 2026
    affected < 4.2.4-3.1fixed 4.2.4-3.1

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-cas

  • CVE-2026-37236CriAug 28, 2026
    affected < 4.2.4-3.1fixed 4.2.4-3.1

    grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the

  • CVE-2026-56865HigAug 13, 2026
    affected < 4.2.4-1.1fixed 4.2.4-1.1

    A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious modul

  • CVE-2026-56864HigAug 13, 2026
    affected < 4.2.4-1.1fixed 4.2.4-1.1

    A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order

  • CVE-2026-56852HigJul 21, 2026
    affected < 4.2.3-3.1fixed 4.2.3-3.1

    A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

  • CVE-2026-50163HigJul 17, 2026
    affected < 4.2.4-1.1fixed 4.2.4-1.1

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret", "<extract_base>/payload.tar.gz/evil_cwd

  • CVE-2026-50151HigJul 17, 2026
    affected < 4.2.3-2.1fixed 4.2.3-2.1

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST reques

  • CVE-2026-48978LowJul 17, 2026
    affected < 4.2.2-2.1fixed 4.2.2-2.1

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such a

  • CVE-2026-63308MedJul 17, 2026
    affected < 4.2.3-4.1fixed 4.2.3-4.1

    Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can includ

  • CVE-2026-41178MedJun 4, 2026
    affected < 4.2.4-1.1fixed 4.2.4-1.1

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the iss

  • CVE-2026-39821CriMay 22, 2026
    affected < 4.2.0-3.1fixed 4.2.0-3.1

    The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program

  • CVE-2026-41888MedMay 14, 2026
    affected < 4.2.0-1.1fixed 4.2.0-1.1

    Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2//manifests/ endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even w

Page 1 of 3