VYPR

Kraken

by Uber

Source repositories

CVEs (3)

  • CVE-2026-75625CriAug 18, 2026
    risk 0.59cvss 9.0epss 0.00

    Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or malicious peers can supply…

  • CVE-2022-47747HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.01

    kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.

  • CVE-2026-92791HigSep 16, 2026
    risk 0.42cvss 7.5epss 0.01

    Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary…