Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    MINI-cxr9-3xpf-m735
    Fix available
    Packages

    rabbitmq-cluster-operator-fips

    Summary

    Published
    10 Sept 2026
    MINI-fp87-v8c7-fr7w
    Fix available
    Packages

    rabbitmq-cluster-operator

    Summary

    Published
    10 Sept 2026
    MINI-jq67-45w4-2wjc
    Fix available
    Packages

    rabbitmq-cluster-operator-fips

    Summary

    Published
    10 Sept 2026
    MINI-v5c4-9pc8-mpgv
    Fix available
    Packages

    rabbitmq-cluster-operator

    Summary

    Published
    10 Sept 2026
    MINI-w9vg-xm5p-593f
    Fix available
    Packages

    rabbitmq-cluster-operator

    Summary

    Published
    10 Sept 2026
    MINI-53hj-pj4j-3x3h
    Fix available
    Packages

    langfuse-4, langfuse-4-worker

    Summary

    Published
    10 Sept 2026
    MINI-c3hj-pmj9-x7x9
    Fix available
    Packages

    langfuse-4-worker

    Summary

    Published
    10 Sept 2026
    MINI-vhv4-c8fv-49rj
    Fix available
    Packages

    kubescape

    Summary

    Published
    10 Sept 2026
    MINI-w752-pqc8-cj85
    Fix available
    Packages

    kubescape

    Summary

    Published
    10 Sept 2026
    MINI-4jfr-28h3-r5pc
    Fix available
    Packages

    dapr-placement-1.18

    Summary

    Published
    10 Sept 2026
    MINI-jjhj-4rjp-8phx
    Fix available
    Packages

    dapr-operator-fips-1.18

    Summary

    Published
    10 Sept 2026
    MINI-m76j-4m33-87v3
    Fix available
    Packages

    dapr-operator-fips-1.18

    Summary

    Published
    10 Sept 2026
    MINI-phg9-ppw7-f6jc
    Fix available
    Packages

    dapr-operator-fips-1.18

    Summary

    Published
    10 Sept 2026
    MINI-w3g5-5xmq-jpf6
    Fix available
    Packages

    dapr-scheduler-fips-1.18

    Summary

    Published
    10 Sept 2026
    MINI-6xg8-9r45-hv5f
    Fix available
    Packages

    dapr-placement-1.18

    Summary

    Published
    10 Sept 2026
    MINI-68v8-xp49-fwvc
    Fix available
    Packages

    dapr-scheduler-fips-1.18

    Summary

    Published
    10 Sept 2026
    MINI-43m7-xmxj-2grh
    Fix available
    Packages

    dapr-daprd-1.18

    Summary

    Published
    10 Sept 2026
    MINI-7cr5-38c6-7pvf
    Fix available
    Packages

    dapr-injector-fips-1.18

    Summary

    Published
    10 Sept 2026
    MINI-7jcw-wm4m-5j34
    Fix available
    Packages

    dapr-daprd-1.18

    Summary

    Published
    10 Sept 2026
    MINI-9ccj-8g5g-fwv9
    Fix available
    Packages

    dapr-daprd-1.18

    Summary

    Published
    10 Sept 2026
    MINI-cx8p-p949-fw29
    Fix available
    Packages

    dapr-daprd-1.18

    Summary

    Published
    10 Sept 2026
    MINI-g5f5-wxg4-p9qh
    Fix available
    Packages

    dapr-injector-fips-1.18

    Summary

    Published
    10 Sept 2026
    MINI-grf9-w2vr-r22c
    Fix available
    Packages

    dapr-daprd-1.18

    Summary

    Published
    10 Sept 2026
    MINI-qpvf-vvqm-gq5v
    Fix available
    Packages

    dapr-injector-fips-1.18

    Summary

    Published
    10 Sept 2026
    MINI-vj95-gm4c-37pr
    Fix available
    Packages

    dapr-daprd-1.18

    Summary

    Published
    10 Sept 2026
    MINI-xfrc-6j2f-hw7p
    Fix available
    Packages

    dapr-daprd-1.18

    Summary

    Published
    10 Sept 2026
    Packages

    apache-nifi

    Summary

    In Spring Security, versions 5

    Published
    10 Sept 2026
    Packages

    apache-superset

    Summary

    sqlparse is a non-validating SQL parser module for Python

    Published
    10 Sept 2026
    Packages

    calico

    Summary

    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

    Published
    10 Sept 2026
    Packages

    cert-manager

    Summary

    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

    Published
    10 Sept 2026
    Packages

    calico

    Summary

    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

    Published
    10 Sept 2026
    Packages

    az

    Summary

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

    Published
    10 Sept 2026
    Packages

    calico

    Summary

    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

    Published
    10 Sept 2026
    Packages

    helm

    Summary

    Previously, resolving relative paths containing parent directory ('

    Published
    10 Sept 2026
    Packages

    haproxy-ingress

    Summary

    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...

    Published
    10 Sept 2026
    Packages

    dex

    Summary

    malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log

    Published
    10 Sept 2026
    Packages

    dex

    Summary

    filippo

    Published
    10 Sept 2026
    Packages

    haproxy-ingress

    Summary

    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...

    Published
    10 Sept 2026
    Packages

    helm

    Summary

    Previously, resolving relative paths containing parent directory ('

    Published
    10 Sept 2026
    Packages

    haproxy-ingress

    Summary

    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...

    Published
    10 Sept 2026
    Packages

    ingress-nginx-controller

    Summary

    Previously, resolving relative paths containing parent directory ('

    Published
    10 Sept 2026
    CGA-349f-q4fw-g7m7
    No fix available
    Packages

    spark-fips-4.1-scala-2.13

    Summary

    Published
    10 Sept 2026
    Packages

    k8s-sidecar

    Summary

    pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels

    Published
    10 Sept 2026
    Packages

    kafka

    Summary

    JLine is a Java library for handling console input

    Published
    10 Sept 2026
    Packages

    kubernetes-dns-node-cache

    Summary

    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

    Published
    10 Sept 2026
    Packages

    kyverno

    Summary

    malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log

    Published
    10 Sept 2026
    Packages

    kyverno

    Summary

    oras-go is a Go library for managing OCI artifacts

    Published
    10 Sept 2026
    Packages

    kubernetes-dns-node-cache

    Summary

    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

    Published
    10 Sept 2026
    Packages

    metallb

    Summary

    Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer

    Published
    10 Sept 2026
    Packages

    logstash-exporter

    Summary

    Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures

    Published
    10 Sept 2026