VYPR

Zarf

by Mlflow

Source repositories

CVEs (1)

  • CVE-2026-40090HigApr 15, 2026
    risk 0.39cvss 7.1epss 0.00

    Zarf is an Airgap Native Packager Manager for Kubernetes. Versions 0.23.0 through 0.74.1 contain an arbitrary file write vulnerability in the zarf package inspect sbom and zarf package inspect documentation subcommands. These subcommands output file paths are constructed by…