Open Source Vulnerabilities
apache-nifi
In Spring Security, versions 5
apache-superset
sqlparse is a non-validating SQL parser module for Python
apache-superset
sqlparse is a non-validating SQL parser module for Python
calico
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
calico
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
cert-manager
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
cert-manager
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
calico
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
calico
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
az
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
az
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
calico
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
calico
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
helm
Previously, resolving relative paths containing parent directory ('
helm
Previously, resolving relative paths containing parent directory ('
haproxy-ingress
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
haproxy-ingress
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
dex
malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
dex
malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
haproxy-ingress
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
haproxy-ingress
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
helm
Previously, resolving relative paths containing parent directory ('
helm
Previously, resolving relative paths containing parent directory ('
haproxy-ingress
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
haproxy-ingress
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
ingress-nginx-controller
Previously, resolving relative paths containing parent directory ('
ingress-nginx-controller
Previously, resolving relative paths containing parent directory ('
k8s-sidecar
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels
k8s-sidecar
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels
kafka
JLine is a Java library for handling console input
kafka
JLine is a Java library for handling console input
kubernetes-dns-node-cache
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
kubernetes-dns-node-cache
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
kyverno
malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
kyverno
malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
kyverno
oras-go is a Go library for managing OCI artifacts
kyverno
oras-go is a Go library for managing OCI artifacts
kubernetes-dns-node-cache
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
kubernetes-dns-node-cache
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
metallb
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer
metallb
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer
logstash-exporter
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures
logstash-exporter
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures
