VYPR

rpm package

opensuse/vexctl&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/vexctl&distro=openSUSE%20Tumbleweed

Vulnerabilities (9)

  • CVE-2026-24137MedJan 23, 2026
    affected < 0.4.1+git78.f951e3a-1.1fixed 0.4.1+git78.f951e3a-1.1

    sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. It constructs a filesystem path by joining a cache base directory with a target na

  • CVE-2026-22772Jan 12, 2026
    affected < 0.4.1+git78.f951e3a-1.1fixed 0.4.1+git78.f951e3a-1.1

    Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal servic

  • CVE-2025-58181Nov 19, 2025
    affected < 0.4.1+git78.f951e3a-1.1fixed 0.4.1+git78.f951e3a-1.1

    SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

  • CVE-2025-30204HigMar 21, 2025
    affected < 0.4.1+git78.f951e3a-1.1fixed 0.4.1+git78.f951e3a-1.1

    golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a maliciou

  • CVE-2025-22870MedMar 12, 2025
    affected < 0.4.1+git78.f951e3a-1.1fixed 0.4.1+git78.f951e3a-1.1

    Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

  • CVE-2025-22868Feb 26, 2025
    affected < 0.4.1+git78.f951e3a-1.1fixed 0.4.1+git78.f951e3a-1.1

    An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

  • CVE-2025-22869Feb 26, 2025
    affected < 0.4.1+git78.f951e3a-1.1fixed 0.4.1+git78.f951e3a-1.1

    SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.

  • CVE-2025-27144MedFeb 24, 2025
    affected < 0.4.1+git78.f951e3a-1.1fixed 0.4.1+git78.f951e3a-1.1

    Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when par

  • CVE-2024-45337CriDec 12, 2024
    affected < 0.4.1+git78.f951e3a-1.1fixed 0.4.1+git78.f951e3a-1.1

    Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that