VYPR

rpm package

opensuse/openQA&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/openQA&distro=openSUSE%20Tumbleweed

Vulnerabilities (4)

  • CVE-2026-6321HigMay 4, 2026
    affected < 5.1782995932.ffeb09be-1.1fixed 5.1782995932.ffeb09be-1.1

    fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalize

  • CVE-2026-27904HigFeb 26, 2026
    affected < 5.1782995932.ffeb09be-1.1fixed 5.1782995932.ffeb09be-1.1

    minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), wh

  • CVE-2026-26996HigFeb 20, 2026
    affected < 5.1782995932.ffeb09be-1.1fixed 5.1782995932.ffeb09be-1.1

    minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal charact

  • CVE-2026-25547CriFeb 4, 2026
    affected < 5.1770718745.ce2072d3-1.1fixed 5.1770718745.ce2072d3-1.1

    @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated nume