Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CGA-mjqm-8766-q5fh
    Fix available
    Packages

    coder-fips-2.29

    Summary

    Published
    3 Sept 2026
    CGA-x5m6-vjfh-qm45
    Fix available
    Packages

    crossplane-provider-aws-redshift-fips

    Summary

    Published
    3 Sept 2026
    CGA-pcjj-57f3-3q3w
    Fix available
    Packages

    crossplane-provider-aws-redshift-fips

    Summary

    Published
    3 Sept 2026
    CGA-xvwf-r87v-cjrg
    Fix available
    Packages

    kyverno-init-container-fips-1.19

    Summary

    Published
    3 Sept 2026
    CGA-9w5c-c9qr-vxhx
    Fix available
    Packages

    kyverno-init-container-fips-1.19

    Summary

    Published
    3 Sept 2026
    CGA-fmxf-28w2-cfrr
    Fix available
    Packages

    coder-fips-2.32

    Summary

    Published
    3 Sept 2026
    CGA-hfwr-vm2m-429c
    Fix available
    Packages

    coder-fips-2.32

    Summary

    Published
    3 Sept 2026
    CGA-g524-5m78-h2hp
    Fix available
    Packages

    skopeo, skopeo

    Summary

    Published
    3 Sept 2026
    CGA-6h7q-qpxx-chq6
    Fix available
    Packages

    skopeo, skopeo

    Summary

    Published
    3 Sept 2026
    CGA-cqwr-mm4q-37gv
    Fix available
    Packages

    kube-conformance-1.34

    Summary

    Published
    3 Sept 2026
    CGA-mjqc-wqpr-fjcv
    Fix available
    Packages

    kube-conformance-1.34

    Summary

    Published
    3 Sept 2026
    CGA-7h29-58vp-r7qc
    Fix available
    Packages

    crossplane-provider-aws-signer

    Summary

    Published
    3 Sept 2026
    CGA-26r9-w94w-pgh9
    Fix available
    Packages

    crossplane-provider-aws-signer

    Summary

    Published
    3 Sept 2026
    CGA-c6wm-mmrq-wfrm
    Fix available
    Packages

    crossplane-aws-glacier-fips

    Summary

    Published
    3 Sept 2026
    CGA-pfrv-6cf3-v66j
    Fix available
    Packages

    crossplane-aws-glacier-fips

    Summary

    Published
    3 Sept 2026
    CGA-75gw-8fh4-8rh2
    Fix available
    Packages

    grpcurl-fips

    Summary

    Published
    3 Sept 2026
    CGA-45xx-42gx-qh47
    Fix available
    Packages

    grpcurl-fips

    Summary

    Published
    3 Sept 2026
    CGA-mcv4-vrwf-9p87
    Fix available
    Packages

    crossplane-provider-aws-appstream

    Summary

    Published
    3 Sept 2026
    CGA-v8x4-2255-86jw
    Fix available
    Packages

    crossplane-provider-aws-appstream

    Summary

    Published
    3 Sept 2026
    CGA-6r6f-jj76-wv5p
    Fix available
    Packages

    grpcurl-fips

    Summary

    Published
    3 Sept 2026
    CGA-vcfq-xv5w-rfh4
    Fix available
    Packages

    grpcurl-fips

    Summary

    Published
    3 Sept 2026
    CGA-vc34-39qj-v9gm
    Fix available
    Packages

    crossplane-provider-aws-servicediscovery-fips

    Summary

    Published
    3 Sept 2026
    CGA-vw79-83p7-89vg
    Fix available
    Packages

    crossplane-provider-aws-servicediscovery-fips

    Summary

    Published
    3 Sept 2026
    CGA-7q87-f5xm-878p
    Fix available
    Packages

    crossplane-provider-aws-mwaa-fips

    Summary

    Published
    3 Sept 2026
    CGA-fg36-gfjv-5hfm
    Fix available
    Packages

    crossplane-provider-aws-mwaa-fips

    Summary

    Published
    3 Sept 2026
    CVE-2026-85046
    Fix available
    Packages

    Summary

    Published
    3 Sept 2026
    CGA-8j8w-vp48-4gvc
    Fix available
    Packages

    crossplane-provider-aws-macie2-fips

    Summary

    Published
    3 Sept 2026
    CGA-v7jh-p9fv-xhrh
    Fix available
    Packages

    crossplane-provider-aws-macie2-fips

    Summary

    Published
    3 Sept 2026
    CGA-3x2r-5xhq-w65g
    Fix available
    Packages

    crossplane-2.1, crossplane-2.1

    Summary

    Published
    3 Sept 2026
    CGA-4cww-v28m-88vr
    Fix available
    Packages

    crossplane-2.1, crossplane-2.1

    Summary

    Published
    3 Sept 2026
    GHSA-cxvf-gvfq-36w2
    Fix available
    Packages

    github.com/semaphoreui/semaphore

    Summary

    Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision

    Published
    3 Sept 2026
    CGA-rmxp-qxpg-rrg6
    Fix available
    Packages

    backup-restore-operator-8.1

    Summary

    Published
    3 Sept 2026
    CGA-phfh-j536-r3jp
    Fix available
    Packages

    backup-restore-operator-8.1

    Summary

    Published
    3 Sept 2026
    GHSA-8cj9-r88m-8945
    Fix available
    Packages

    github.com/semaphoreui/semaphore

    Summary

    Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation

    Published
    3 Sept 2026
    CGA-55x2-4rxr-rr6q
    Fix available
    Packages

    crossplane-provider-aws-chime-fips

    Summary

    Published
    3 Sept 2026
    CGA-c5f9-7vgq-xgqq
    Fix available
    Packages

    crossplane-provider-aws-chime-fips

    Summary

    Published
    3 Sept 2026
    CGA-7pfr-p5rh-8h8f
    Fix available
    Packages

    crossplane-2.1, crossplane-2.1

    Summary

    Published
    3 Sept 2026
    CGA-87rm-m7gv-pqx6
    Fix available
    Packages

    crossplane-2.1, crossplane-2.1

    Summary

    Published
    3 Sept 2026
    CGA-q5gx-v7rq-h27w
    Fix available
    Packages

    envoy-gateway-fips-1.6-egctl

    Summary

    Published
    3 Sept 2026
    CGA-p5r5-pjj7-8xjf
    Fix available
    Packages

    envoy-gateway-fips-1.6-egctl

    Summary

    Published
    3 Sept 2026
    CGA-2vjm-g4g9-26gq
    Fix available
    Packages

    crossplane-provider-aws-appconfig

    Summary

    Published
    3 Sept 2026
    CGA-j3x6-6ff9-5mqm
    Fix available
    Packages

    crossplane-provider-aws-appconfig

    Summary

    Published
    3 Sept 2026
    GHSA-fg9p-mrxr-hvq7
    Fix available
    Packages

    orval

    Summary

    Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)

    Published
    3 Sept 2026
    Packages

    ruby-zip, ruby-zip, ruby-zip

    Summary

    Published
    3 Sept 2026
    AZL-99750
    No fix available
    Packages

    python-tensorboard

    Summary

    CVE-2026-85393 affecting package python-tensorboard 2.16.2-6

    Published
    3 Sept 2026
    AZL-99087
    No fix available
    Packages

    rubygem-rubyzip

    Summary

    CVE-2026-85396 affecting package rubygem-rubyzip 2.3.2-1

    Published
    3 Sept 2026
    Packages

    c-ares, c-ares, c-ares, c-ares

    Summary

    Published
    3 Sept 2026
    Packages

    c-ares, c-ares

    Summary

    Published
    3 Sept 2026
    AZL-99093
    Fix available
    Packages

    fluent-bit

    Summary

    CVE-2026-33630 affecting package fluent-bit for versions less than 3.1.10-7

    Published
    3 Sept 2026
    AZL-99095
    No fix available
    Packages

    nodejs

    Summary

    CVE-2026-33630 affecting package nodejs 24.18.1-1

    Published
    3 Sept 2026