VYPR

rpm package

opensuse/helm3&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/helm3&distro=openSUSE%20Tumbleweed

Vulnerabilities (39)

  • CVE-2026-63209HigSep 29, 2026
    affected < 3.22.0-3.1fixed 3.22.0-3.1

    compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Enco

  • CVE-2026-81872MedSep 16, 2026
    affected < 3.22.0-2.1fixed 3.22.0-2.1

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills its asynchronous export buffer while the exporter is backpressured. NewBa

  • CVE-2026-81871MedSep 16, 2026
    affected < 3.22.0-2.1fixed 3.22.0-2.1

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate environment variables through loadEnvTLS i

  • CVE-2026-85732MedSep 16, 2026
    affected < 3.22.0-1.1fixed 3.22.0-1.1

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. Tags, Referrers, and Repositories paginatio

  • CVE-2026-85731HigSep 16, 2026
    affected < 3.22.0-1.1fixed 3.22.0-1.1

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractTarDirectory and ensureLinkPath validates sy

  • CVE-2026-84445HigSep 14, 2026
    affected < 3.21.3-8.1fixed 3.21.3-8.1

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/se

  • CVE-2026-84304HigSep 1, 2026
    affected < 3.21.3-8.1fixed 3.21.3-8.1

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain

  • CVE-2026-84303MedSep 1, 2026
    affected < 3.21.3-8.1fixed 3.21.3-8.1

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-cas

  • CVE-2026-37236CriAug 28, 2026
    affected < 3.21.3-7.1fixed 3.21.3-7.1

    grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the

  • CVE-2026-56852HigJul 21, 2026
    affected < 3.21.3-3.1fixed 3.21.3-3.1

    A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

  • CVE-2026-50151HigJul 17, 2026
    affected < 3.21.3-2.1fixed 3.21.3-2.1

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST reques

  • CVE-2026-48978LowJul 17, 2026
    affected < 3.21.2-2.1fixed 3.21.2-2.1

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such a

  • CVE-2026-63308MedJul 17, 2026
    affected < 3.21.3-4.1fixed 3.21.3-4.1

    Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger an index out of range panic by including zero-length byte slices in chart files. Attackers can includ

  • CVE-2026-41178MedJun 4, 2026
    affected < 3.21.3-6.1fixed 3.21.3-6.1

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the iss

  • CVE-2026-39821CriMay 22, 2026
    affected < 3.21.0-2.1fixed 3.21.0-2.1

    The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program

  • CVE-2026-41888MedMay 14, 2026
    affected < 3.21.0-1.1fixed 3.21.0-1.1

    Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2//manifests/ endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even w

  • CVE-2026-33814HigMay 7, 2026
    affected < 3.21.0-1.1fixed 3.21.0-1.1

    When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

  • CVE-2026-35206MedApr 9, 2026
    affected < 3.20.2-1.1fixed 3.20.2-1.1

    Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/chartname] to write the Chart's contents to the immediate output directory (as defaulted to the current working di

  • CVE-2025-58190MedFeb 5, 2026
    affected < 3.19.2-1.1fixed 3.19.2-1.1

    The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

  • CVE-2025-47911MedFeb 5, 2026
    affected < 3.19.2-1.1fixed 3.19.2-1.1

    The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

Page 1 of 2