Open Source Vulnerabilities
elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management
elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management
vgmstream txtp txtp_parser.c add_entry resource consumption
freerdp
Updated freerdp packages fix security vulnerabilities
tor, tor
Updated tor packages fix security vulnerabilities
vgmstream txth-txtp txth.c sscanf stack-based overflow
java-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokensFromInput allocation of resources
java-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokensFromInput allocation of resources
java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control
java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control
kubernetes
etcd is a distributed key-value store for the data of a distributed system
kubernetes
etcd is a distributed key-value store for the data of a distributed system
step
gRPC-Go is the Go language implementation of gRPC
step
gRPC-Go is the Go language implementation of gRPC
victoriametrics-operator-fips
Previously, a channel registered in the mux's chanList is not usable until it is established
victoriametrics-operator-fips
Previously, a channel registered in the mux's chanList is not usable until it is established
cert-manager
OpenTelemetry-Go is the Go implementation of OpenTelemetry
cert-manager
OpenTelemetry-Go is the Go implementation of OpenTelemetry
langfuse
Hono is a Web application framework that provides support for any JavaScript runtime
langfuse
Hono is a Web application framework that provides support for any JavaScript runtime
aws-network-policy-agent
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
aws-network-policy-agent
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
dynatrace-operator
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
dynatrace-operator
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
trust-manager
Previously, a channel registered in the mux's chanList is not usable until it is established
trust-manager
Previously, a channel registered in the mux's chanList is not usable until it is established
git-lfs
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
git-lfs
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection
dynatrace-operator
malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
dynatrace-operator
malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
java-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource consumption
java-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource consumption
dynatrace-operator
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
dynatrace-operator
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
dynatrace-operator
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
dynatrace-operator
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
step
gRPC-Go is the Go language implementation of gRPC
step
gRPC-Go is the Go language implementation of gRPC
step-issuer
Previously, a channel registered in the mux's chanList is not usable until it is established
step-issuer
Previously, a channel registered in the mux's chanList is not usable until it is established
step-issuer
Previously, a channel registered in the mux's chanList is not usable until it is established
step-issuer
Previously, a channel registered in the mux's chanList is not usable until it is established
vault-k8s
Previously, a channel registered in the mux's chanList is not usable until it is established
vault-k8s
Previously, a channel registered in the mux's chanList is not usable until it is established
sealed-secrets
Previously, a channel registered in the mux's chanList is not usable until it is established
sealed-secrets
Previously, a channel registered in the mux's chanList is not usable until it is established
step
gRPC-Go is the Go language implementation of gRPC
step
gRPC-Go is the Go language implementation of gRPC
sealed-secrets
Previously, a channel registered in the mux's chanList is not usable until it is established
sealed-secrets
Previously, a channel registered in the mux's chanList is not usable until it is established
external-secrets-operator
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
external-secrets-operator
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
helm-operator
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
helm-operator
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
helm-operator
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
helm-operator
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
istio
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
istio
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
istio
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
istio
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label
elasticsearch
yawkat LZ4 Java provides LZ4 compression for Java
elasticsearch
yawkat LZ4 Java provides LZ4 compression for Java
rancher-fleet-agent
Helm is a package manager for Charts for Kubernetes
rancher-fleet-agent
Helm is a package manager for Charts for Kubernetes
opentelemetry-collector-contrib
malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
opentelemetry-collector-contrib
malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
weaviate-fips
HashiCorp memberlist before version 0
weaviate-fips
HashiCorp memberlist before version 0
opentelemetry-collector
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
opentelemetry-collector
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
