VYPR

rpm package

opensuse/trivy&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/trivy&distro=openSUSE%20Tumbleweed

Vulnerabilities (70)

  • CVE-2026-53495MedSep 14, 2026
    affected < 0.75.0-1.1fixed 0.75.0-1.1

    containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or

  • CVE-2026-84445HigSep 14, 2026
    affected < 0.74.0-4.1fixed 0.74.0-4.1

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/se

  • CVE-2026-56855HigSep 2, 2026
    affected < 0.74.0-3.1fixed 0.74.0-3.1

    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and t

  • CVE-2026-84304HigSep 1, 2026
    affected < 0.74.0-4.1fixed 0.74.0-4.1

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain

  • CVE-2026-84303MedSep 1, 2026
    affected < 0.74.0-4.1fixed 0.74.0-4.1

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-cas

  • CVE-2026-37236CriAug 28, 2026
    affected < 0.74.0-2.1fixed 0.74.0-2.1

    grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the

  • CVE-2026-72817MedAug 14, 2026
    affected < 0.74.0-1.1fixed 0.74.0-1.1

    go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted proxies. A malicious client can prepend a f

  • CVE-2026-56852HigJul 21, 2026
    affected < 0.72.0-2.1fixed 0.72.0-2.1

    A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

  • CVE-2026-50163HigJul 17, 2026
    affected < 0.74.0-2.1fixed 0.74.0-2.1

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret", "<extract_base>/payload.tar.gz/evil_cwd

  • CVE-2026-50151HigJul 17, 2026
    affected < 0.72.0-2.1fixed 0.72.0-2.1

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST reques

  • CVE-2026-53492CriJul 1, 2026
    affected < 0.71.2-1.1fixed 0.71.2-1.1

    containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a conta

  • CVE-2026-53489MedJul 1, 2026
    affected < 0.71.2-1.1fixed 0.71.2-1.1

    containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl l

  • CVE-2026-50195CriJul 1, 2026
    affected < 0.71.2-1.1fixed 0.71.2-1.1

    containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions

  • CVE-2026-47262MedJul 1, 2026
    affected < 0.71.2-1.1fixed 0.71.2-1.1

    containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occ

  • CVE-2026-46680HigJul 1, 2026
    affected < 0.71.1-2.1fixed 0.71.1-2.1

    containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted im

  • CVE-2026-53488HigJul 1, 2026
    affected < 0.71.2-1.1fixed 0.71.2-1.1

    containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary comman

  • CVE-2026-55092HigJun 25, 2026
    affected < 0.71.2-2.1fixed 0.71.2-2.1

    Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled artifac

  • CVE-2026-54448MedJun 25, 2026
    affected < 0.71.2-2.1fixed 0.71.2-2.1

    Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft a small compressed archive tha

  • CVE-2026-41178MedJun 4, 2026
    affected < 0.74.0-2.1fixed 0.74.0-2.1

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log errors, enabling DoS via oversized inputs. Versions 1.42.0 and 1.44.0 fix the iss

  • CVE-2026-44740MedJun 1, 2026
    affected < 0.71.0-1.1fixed 0.71.0-1.1

    Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise

Page 1 of 4