rpm package
opensuse/vexctl&distro=openSUSE Leap 15.6
pkg:rpm/opensuse/vexctl&distro=openSUSE%20Leap%2015.6
Vulnerabilities (9)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-24137 | Med | 5.8 | < 0.4.1+git78.f951e3a-150000.1.11.1 | 0.4.1+git78.f951e3a-150000.1.11.1 | Jan 23, 2026 | sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. It constructs a filesystem path by joining a cache base directory with a target na | |
| CVE-2026-22772 | — | < 0.4.1+git78.f951e3a-150000.1.11.1 | 0.4.1+git78.f951e3a-150000.1.11.1 | Jan 12, 2026 | Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal servic | ||
| CVE-2025-58181 | — | < 0.4.1+git78.f951e3a-150000.1.11.1 | 0.4.1+git78.f951e3a-150000.1.11.1 | Nov 19, 2025 | SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption. | ||
| CVE-2025-30204 | Hig | 7.5 | < 0.4.1+git78.f951e3a-150000.1.11.1 | 0.4.1+git78.f951e3a-150000.1.11.1 | Mar 21, 2025 | golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a maliciou | |
| CVE-2025-22870 | Med | 4.4 | < 0.4.1+git78.f951e3a-150000.1.11.1 | 0.4.1+git78.f951e3a-150000.1.11.1 | Mar 12, 2025 | Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied. | |
| CVE-2025-22868 | — | < 0.4.1+git78.f951e3a-150000.1.11.1 | 0.4.1+git78.f951e3a-150000.1.11.1 | Feb 26, 2025 | An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing. | ||
| CVE-2025-22869 | — | < 0.4.1+git78.f951e3a-150000.1.11.1 | 0.4.1+git78.f951e3a-150000.1.11.1 | Feb 26, 2025 | SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted. | ||
| CVE-2025-27144 | Med | — | < 0.4.1+git78.f951e3a-150000.1.11.1 | 0.4.1+git78.f951e3a-150000.1.11.1 | Feb 24, 2025 | Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when par | |
| CVE-2024-45337 | Cri | 9.1 | < 0.4.1+git78.f951e3a-150000.1.11.1 | 0.4.1+git78.f951e3a-150000.1.11.1 | Dec 12, 2024 | Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that |
- affected < 0.4.1+git78.f951e3a-150000.1.11.1fixed 0.4.1+git78.f951e3a-150000.1.11.1
sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. It constructs a filesystem path by joining a cache base directory with a target na
- CVE-2026-22772Jan 12, 2026affected < 0.4.1+git78.f951e3a-150000.1.11.1fixed 0.4.1+git78.f951e3a-150000.1.11.1
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal servic
- CVE-2025-58181Nov 19, 2025affected < 0.4.1+git78.f951e3a-150000.1.11.1fixed 0.4.1+git78.f951e3a-150000.1.11.1
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
- affected < 0.4.1+git78.f951e3a-150000.1.11.1fixed 0.4.1+git78.f951e3a-150000.1.11.1
golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a maliciou
- affected < 0.4.1+git78.f951e3a-150000.1.11.1fixed 0.4.1+git78.f951e3a-150000.1.11.1
Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.
- CVE-2025-22868Feb 26, 2025affected < 0.4.1+git78.f951e3a-150000.1.11.1fixed 0.4.1+git78.f951e3a-150000.1.11.1
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
- CVE-2025-22869Feb 26, 2025affected < 0.4.1+git78.f951e3a-150000.1.11.1fixed 0.4.1+git78.f951e3a-150000.1.11.1
SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.
- affected < 0.4.1+git78.f951e3a-150000.1.11.1fixed 0.4.1+git78.f951e3a-150000.1.11.1
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when par
- affected < 0.4.1+git78.f951e3a-150000.1.11.1fixed 0.4.1+git78.f951e3a-150000.1.11.1
Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that