Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    MINI-m5jc-7f2w-x6vf
    Fix available
    Packages

    redpanda-operator-25.3

    Summary

    Published
    8 Sept 2026
    MINI-q6w4-wv8f-gj77
    Fix available
    Packages

    redpanda-operator-25.3

    Summary

    Published
    8 Sept 2026
    MINI-v5q9-vpm3-c34m
    Fix available
    Packages

    redpanda-operator-25.3

    Summary

    Published
    8 Sept 2026
    MINI-4wvw-wjxr-9q94
    Fix available
    Packages

    grafana-beyla-fips

    Summary

    Published
    8 Sept 2026
    MINI-w58v-wfwr-v67h
    Fix available
    Packages

    grafana-beyla-fips

    Summary

    Published
    8 Sept 2026
    MINI-r9hp-rh3f-pcxc
    Fix available
    Packages

    grafana-beyla-fips

    Summary

    Published
    8 Sept 2026
    MINI-p946-8hqf-c2f8
    Fix available
    Packages

    grafana-beyla-fips

    Summary

    Published
    8 Sept 2026
    MINI-87qv-9cjr-36jv
    Fix available
    Packages

    grafana-beyla

    Summary

    Published
    8 Sept 2026
    MINI-96vq-p83f-cjw8
    Fix available
    Packages

    grafana-beyla

    Summary

    Published
    8 Sept 2026
    MINI-pvxx-r446-9h9c
    Fix available
    Packages

    grafana-beyla

    Summary

    Published
    8 Sept 2026
    MINI-338w-jffv-m3w8
    Fix available
    Packages

    grafana-beyla

    Summary

    Published
    8 Sept 2026
    CVE-2026-86516
    Fix available
    Packages

    Summary

    elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management

    Published
    8 Sept 2026
    CVE-2026-86515
    Fix available
    Packages

    Summary

    vgmstream txtp txtp_parser.c add_entry resource consumption

    Published
    8 Sept 2026
    MGASA-2026-0383
    Fix available
    Packages

    freerdp

    Summary

    Updated freerdp packages fix security vulnerabilities

    Published
    8 Sept 2026
    MGASA-2026-0382
    Fix available
    Packages

    tor, tor

    Summary

    Updated tor packages fix security vulnerabilities

    Published
    8 Sept 2026
    CVE-2026-86514
    Fix available
    Packages

    Summary

    vgmstream txth-txtp txth.c sscanf stack-based overflow

    Published
    8 Sept 2026
    CVE-2026-86513
    No fix available
    Packages

    Summary

    java-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokensFromInput allocation of resources

    Published
    8 Sept 2026
    CVE-2026-86512
    No fix available
    Packages

    Summary

    java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control

    Published
    8 Sept 2026
    Packages

    kubernetes

    Summary

    etcd is a distributed key-value store for the data of a distributed system

    Published
    8 Sept 2026
    Packages

    step

    Summary

    gRPC-Go is the Go language implementation of gRPC

    Published
    8 Sept 2026
    Packages

    victoriametrics-operator-fips

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026
    Packages

    cert-manager

    Summary

    OpenTelemetry-Go is the Go implementation of OpenTelemetry

    Published
    8 Sept 2026
    Packages

    langfuse

    Summary

    Hono is a Web application framework that provides support for any JavaScript runtime

    Published
    8 Sept 2026
    Packages

    aws-network-policy-agent

    Summary

    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

    Published
    8 Sept 2026
    Packages

    dynatrace-operator

    Summary

    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...

    Published
    8 Sept 2026
    Packages

    trust-manager

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026
    Packages

    git-lfs

    Summary

    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection

    Published
    8 Sept 2026
    Packages

    dynatrace-operator

    Summary

    malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log

    Published
    8 Sept 2026
    CVE-2026-86511
    No fix available
    Packages

    Summary

    java-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource consumption

    Published
    8 Sept 2026
    Packages

    dynatrace-operator

    Summary

    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...

    Published
    8 Sept 2026
    Packages

    dynatrace-operator

    Summary

    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...

    Published
    8 Sept 2026
    Packages

    step

    Summary

    gRPC-Go is the Go language implementation of gRPC

    Published
    8 Sept 2026
    Packages

    step-issuer

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026
    Packages

    step-issuer

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026
    Packages

    vault-k8s

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026
    Packages

    sealed-secrets

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026
    Packages

    step

    Summary

    gRPC-Go is the Go language implementation of gRPC

    Published
    8 Sept 2026
    Packages

    sealed-secrets

    Summary

    Previously, a channel registered in the mux's chanList is not usable until it is established

    Published
    8 Sept 2026
    Packages

    external-secrets-operator

    Summary

    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...

    Published
    8 Sept 2026
    Packages

    helm-operator

    Summary

    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...

    Published
    8 Sept 2026
    Packages

    helm-operator

    Summary

    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

    Published
    8 Sept 2026
    Packages

    istio

    Summary

    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

    Published
    8 Sept 2026
    Packages

    istio

    Summary

    ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

    Published
    8 Sept 2026
    Packages

    elasticsearch

    Summary

    yawkat LZ4 Java provides LZ4 compression for Java

    Published
    8 Sept 2026
    Packages

    npm

    Summary

    brace-expansion through 5

    Published
    8 Sept 2026
    Packages

    rancher-fleet-agent

    Summary

    Helm is a package manager for Charts for Kubernetes

    Published
    8 Sept 2026
    Packages

    opentelemetry-collector-contrib

    Summary

    malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log

    Published
    8 Sept 2026
    Packages

    weaviate-fips

    Summary

    HashiCorp memberlist before version 0

    Published
    8 Sept 2026
    Packages

    weaviate-fips

    Summary

    HashiCorp memberlist before version 0

    Published
    8 Sept 2026
    Packages

    opentelemetry-collector

    Summary

    source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...

    Published
    8 Sept 2026