VYPR

docker-manifest-action

by Noelware

CVEs (1)

  • CVE-2026-85469HigSep 16, 2026
    risk 0.52cvss 8.0epss

    A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the…