VYPR

rpm package

opensuse/tekton-cli&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/tekton-cli&distro=openSUSE%20Tumbleweed

Vulnerabilities (6)

  • CVE-2026-48702HigAug 13, 2026
    affected < 0.45.1-1.1fixed 0.45.1-1.1

    Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the

  • CVE-2026-49835MedJul 17, 2026
    affected < 0.45.1-1.1fixed 0.45.1-1.1

    Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before rout

  • CVE-2026-42505MedJul 8, 2026
    affected < 0.46.0-1.1fixed 0.46.0-1.1

    Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

  • CVE-2026-34986HigApr 6, 2026
    affected < 0.44.1-1.1fixed 0.44.1-1.1

    Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JW

  • CVE-2026-33211CriMar 24, 2026
    affected < 0.44.1-1.1fixed 0.44.1-1.1

    Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A t

  • CVE-2026-25679HigMar 6, 2026
    affected < 0.45.0-1.1fixed 0.45.0-1.1

    url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.