VYPR

rpm package

suse/kubernetes-old&distro=SUSE Linux Enterprise Module for Containers 15 SP7

pkg:rpm/suse/kubernetes-old&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP7

Vulnerabilities (3)

  • CVE-2026-33814HigMay 7, 2026
    affected < 1.33.11-150600.13.32.1fixed 1.33.11-150600.13.32.1

    When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

  • CVE-2026-35469MedApr 16, 2026
    affected < 1.33.11-150600.13.32.1fixed 1.33.11-150600.13.32.1

    spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count,

  • CVE-2025-22872MedApr 16, 2025
    affected < 1.31.9-150600.13.10.1fixed 1.31.9-150600.13.10.1

    The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can resul