VYPR

YuniKorn

by Apache

CVEs (3)

  • CVE-2026-97146MedOct 7, 2026
    risk 0.31cvss —epss —

    Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a secondary label on the pod. If the pod has the label 'app=yunikorn' the checks limiting the user annotation content are not run. The label is used to identify the YuniKorn…

  • CVE-2026-78243LowOct 7, 2026
    risk 0.14cvss —epss —

    Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specified in the pod the server crashes if a…

  • CVE-2026-92393LowOct 7, 2026
    risk 0.13cvss —epss —

    Apache YuniKorn 1.9.0 and earlier does not implement label and user annotation checks for workload UPDATE action bypassing all checks. Workloads in YuniKorn are defined as the following Kubernetes objects: "deployments", "replicasets", "statefulsets", "daemonsets", "jobs",…