container statistics
11 container package(s) · generated 2026-08-08T05:00:46Z
ghcr.io/openvoxproject/openbolt
ghcr.io/openvoxproject/openbolt:latest (2026-07-31)
Trivy
No confirmed findings.
Grype
NVD/CPE filtered 3
No confirmed findings.
Filtered NVD/CPE matches (3)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed |
ghcr.io/openvoxproject/openvoxagent
Downloads
ghcr.io/openvoxproject/openvoxagent:latest (2026-07-09)
Trivy
HIGH 7
MEDIUM 63
LOW 6
UNKNOWN 2
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-42504 | stdlib | v1.26.3 | 1.25.11, 1.26.4 | mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header — usr/bin/pebble |
| HIGH | CVE-2026-39822 | stdlib | v1.26.3 | 1.25.12, 1.26.5, 1.27.0-rc.2 | golang: Go os.Root: Symlink following vulnerability allows directory traversal — usr/bin/pebble |
| HIGH | CVE-2026-27145 | stdlib | v1.26.3 | 1.25.11, 1.26.4 | crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries — usr/bin/pebble |
| HIGH | CVE-2026-39821 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/bin/pebble |
| HIGH | CVE-2026-33814 | golang.org/x/net | v0.40.0 | 0.53.0 | net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame — usr/bin/pebble |
| HIGH | CVE-2026-27136 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass — usr/bin/pebble |
| HIGH | CVE-2026-25681 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting — usr/bin/pebble |
| MEDIUM | CVE-2026-35368 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability exists in the chroot utility of uutils coreutils when ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35367 | rust-coreutils | 0.8.0-0ubuntu3 | The nohup utility in uutils coreutils creates its default output file, ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35364 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35363 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in the rm utility of uutils coreutils allows the bypas ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35360 | rust-coreutils | 0.8.0-0ubuntu3 | The touch utility in uutils coreutils is vulnerable to a Time-of-Check ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35359 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utilit ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35357 | rust-coreutils | 0.8.0-0ubuntu3 | The cp utility in uutils coreutils is vulnerable to an information dis ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35354 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35352 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35351 | rust-coreutils | 0.8.0-0ubuntu3 | The mv utility in uutils coreutils fails to preserve file ownership du ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35350 | rust-coreutils | 0.8.0-0ubuntu3 | The cp utility in uutils coreutils fails to properly handle setuid and ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35348 | rust-coreutils | 0.8.0-0ubuntu3 | The sort utility in uutils coreutils is vulnerable to a process panic ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35345 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in the tail utility of uutils coreutils allows for the ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35344 | rust-coreutils | 0.8.0-0ubuntu3 | The dd utility in uutils coreutils suppresses errors during file trunc ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35341 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in uutils coreutils mkfifo allows for the unauthorized ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35370 | rust-coreutils | 0.8.0-0ubuntu3 | The id utility in uutils coreutils miscalculates the groups= section o ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35371 | rust-coreutils | 0.8.0-0ubuntu3 | The id utility in uutils coreutils exhibits incorrect behavior in its ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35373 | rust-coreutils | 0.8.0-0ubuntu3 | A logic error in the ln utility of uutils coreutils causes the program ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35374 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the sp ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35377 | rust-coreutils | 0.8.0-0ubuntu3 | A logic error in the env utility of uutils coreutils causes a failure ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-5704 | tar | 1.35+dfsg-4ubuntu0.2 | 1.35+dfsg-4ubuntu0.4 | tar: tar: Hidden file injection via crafted archives — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | util-linux | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | util-linux | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2025-47911 | golang.org/x/net | v0.40.0 | 0.45.0 | golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html — usr/bin/pebble |
| MEDIUM | CVE-2025-58190 | golang.org/x/net | v0.40.0 | 0.45.0 | golang.org/x/net/html: Infinite parsing loop in golang.org/x/net — usr/bin/pebble |
| MEDIUM | CVE-2026-25680 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing — usr/bin/pebble |
| MEDIUM | CVE-2026-42502 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering — usr/bin/pebble |
| MEDIUM | CVE-2026-42506 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing — usr/bin/pebble |
| MEDIUM | CVE-2026-42505 | stdlib | v1.26.3 | 1.25.12, 1.26.5, 1.27.0-rc.2 | crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — usr/bin/pebble |
| MEDIUM | CVE-2026-42507 | stdlib | v1.26.3 | 1.25.11, 1.26.4 | net/textproto: golang: Golang net/textproto: Misleading error messages via input injection — usr/bin/pebble |
| MEDIUM | CVE-2026-6238 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Application crash or uninitialized memory read via crafted DNS response — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5928 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5450 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5435 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Out-of-bounds write via TSIG record processing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-4046 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Denial of Service via iconv() function with specific character sets — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6238 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Application crash or uninitialized memory read via crafted DNS response — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5928 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5450 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5435 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Out-of-bounds write via TSIG record processing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-4046 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Denial of Service via iconv() function with specific character sets — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6238 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Application crash or uninitialized memory read via crafted DNS response — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5928 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5450 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5435 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Out-of-bounds write via TSIG record processing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-4046 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Denial of Service via iconv() function with specific character sets — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | libblkid1 | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | libblkid1 | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | bsdutils | 1:2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | bsdutils | 1:2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | libmount1 | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | libmount1 | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-54411 | libpam-modules | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-54411 | libpam-modules-bin | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | mount | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-54411 | libpam-runtime | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-54411 | libpam0g | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | libsmartcols1 | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | libsmartcols1 | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | mount | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | libuuid1 | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | libuuid1 | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| LOW | CVE-2024-56433 | passwd | 1:4.17.4-2ubuntu3 | shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| LOW | CVE-2024-56433 | login.defs | 1:4.17.4-2ubuntu3 | shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| LOW | CVE-2026-40228 | libudev1 | 259.5-0ubuntu3 | systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| LOW | CVE-2026-40228 | libsystemd0 | 259.5-0ubuntu3 | systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| LOW | CVE-2026-27171 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| LOW | CVE-2024-2236 | libgcrypt20 | 1.12.0-2ubuntu1 | libgcrypt: vulnerable to Marvin Attack — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| UNKNOWN | CVE-2026-39824 | golang.org/x/sys | v0.33.0 | 0.44.0 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows — usr/bin/pebble |
| UNKNOWN | CVE-2026-46600 | golang.org/x/net | v0.40.0 | 0.56.0 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ... — usr/bin/pebble |
Grype
HIGH 2
MEDIUM 122
LOW 10
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GO-2026-5026 | golang.org/x/net | v0.40.0 | 0.55.0 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/pebble |
| HIGH | GO-2026-5037 | stdlib | go1.26.3 | 1.25.11, 1.26.4 | (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. — /usr/bin/pebble |
| MEDIUM | CVE-2026-13595 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35370 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35359 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18477 | tar | 1.35+dfsg-4ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35360 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35377 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35345 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35354 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35364 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35357 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54370 | libacl1 | 2.3.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35374 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35367 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35344 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35373 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35371 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35350 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54411 | libpam0g | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54411 | libpam-runtime | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-54411 | libpam-modules-bin | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-54411 | libpam-modules | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57433 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6238 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6238 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6238 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5928 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5928 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5928 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5704 | tar | 1.35+dfsg-4ubuntu0.2 | 1.35+dfsg-4ubuntu0.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-48959 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-12087 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4046 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-4046 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-4046 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | GO-2026-5039 | stdlib | go1.26.3 | 1.25.11, 1.26.4 | When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. — /usr/bin/pebble |
| MEDIUM | GO-2026-5856 | stdlib | go1.26.3 | 1.25.12, 1.26.5, 1.27.0-rc.2 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/bin/pebble |
| MEDIUM | CVE-2026-42497 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13221 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54371 | libattr1 | 1:2.5.2-4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18508 | tar | 1.35+dfsg-4ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35351 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35348 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56391 | gnu-coreutils | 9.7-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56391 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35368 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-5450 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5450 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-35352 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56392 | gnu-coreutils | 9.7-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56392 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54369 | libacl1 | 2.3.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35341 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35363 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57432 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-5435 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5435 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5435 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5450 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-9538 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53910 | diffutils | 1:3.12-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54876 | openssl-provider-legacy | 3.5.5-1ubuntu3.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54876 | openssl | 3.5.5-1ubuntu3.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54876 | libssl3t64 | 3.5.5-1ubuntu3.2 | /var/lib/dpkg/status | |
| LOW | CVE-2024-2236 | libgcrypt20 | 1.12.0-2ubuntu1 | /var/lib/dpkg/status | |
| LOW | CVE-2026-42250 | libbz2-1.0 | 1.0.8-6build2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-57062 | gpgv | 2.4.8-4ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-40228 | libudev1 | 259.5-0ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-40228 | libsystemd0 | 259.5-0ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2024-56433 | login.defs | 1:4.17.4-2ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2024-56433 | passwd | 1:4.17.4-2ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2025-5278 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | /var/lib/dpkg/status | |
| LOW | CVE-2025-5278 | gnu-coreutils | 9.7-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-27171 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | /var/lib/dpkg/status |
ghcr.io/openvoxproject/openvoxdb
Downloads
ghcr.io/openvoxproject/openvoxdb:latest (2026-07-23)
Trivy
HIGH 6
MEDIUM 62
LOW 6
UNKNOWN 2
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-39822 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | golang: Go os.Root: Symlink following vulnerability allows directory traversal — usr/bin/pebble |
| HIGH | CVE-2026-39821 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/bin/pebble |
| HIGH | CVE-2026-33814 | golang.org/x/net | v0.40.0 | 0.53.0 | net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame — usr/bin/pebble |
| HIGH | CVE-2026-27136 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass — usr/bin/pebble |
| HIGH | CVE-2026-25681 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting — usr/bin/pebble |
| HIGH | CVE-2022-41404 | org.ini4j:ini4j | 0.5.4 | org.ini4j: unspecified DoS — Java | |
| MEDIUM | CVE-2026-35364 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35363 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in the rm utility of uutils coreutils allows the bypas ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35360 | rust-coreutils | 0.8.0-0ubuntu3 | The touch utility in uutils coreutils is vulnerable to a Time-of-Check ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35359 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utilit ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35357 | rust-coreutils | 0.8.0-0ubuntu3 | The cp utility in uutils coreutils is vulnerable to an information dis ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35354 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35352 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35351 | rust-coreutils | 0.8.0-0ubuntu3 | The mv utility in uutils coreutils fails to preserve file ownership du ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35350 | rust-coreutils | 0.8.0-0ubuntu3 | The cp utility in uutils coreutils fails to properly handle setuid and ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35348 | rust-coreutils | 0.8.0-0ubuntu3 | The sort utility in uutils coreutils is vulnerable to a process panic ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35345 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in the tail utility of uutils coreutils allows for the ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35344 | rust-coreutils | 0.8.0-0ubuntu3 | The dd utility in uutils coreutils suppresses errors during file trunc ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35341 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in uutils coreutils mkfifo allows for the unauthorized ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | mount | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | mount | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35367 | rust-coreutils | 0.8.0-0ubuntu3 | The nohup utility in uutils coreutils creates its default output file, ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35368 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability exists in the chroot utility of uutils coreutils when ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35370 | rust-coreutils | 0.8.0-0ubuntu3 | The id utility in uutils coreutils miscalculates the groups= section o ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35371 | rust-coreutils | 0.8.0-0ubuntu3 | The id utility in uutils coreutils exhibits incorrect behavior in its ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35373 | rust-coreutils | 0.8.0-0ubuntu3 | A logic error in the ln utility of uutils coreutils causes the program ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35374 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the sp ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35377 | rust-coreutils | 0.8.0-0ubuntu3 | A logic error in the env utility of uutils coreutils causes a failure ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | util-linux | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | util-linux | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2025-47911 | golang.org/x/net | v0.40.0 | 0.45.0 | golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html — usr/bin/pebble |
| MEDIUM | CVE-2025-58190 | golang.org/x/net | v0.40.0 | 0.45.0 | golang.org/x/net/html: Infinite parsing loop in golang.org/x/net — usr/bin/pebble |
| MEDIUM | CVE-2026-25680 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing — usr/bin/pebble |
| MEDIUM | CVE-2026-42502 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering — usr/bin/pebble |
| MEDIUM | CVE-2026-42506 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing — usr/bin/pebble |
| MEDIUM | CVE-2026-42505 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — usr/bin/pebble |
| MEDIUM | CVE-2026-3184 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-5928 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5450 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5435 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Out-of-bounds write via TSIG record processing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-4046 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Denial of Service via iconv() function with specific character sets — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6238 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Application crash or uninitialized memory read via crafted DNS response — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5928 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5450 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5435 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Out-of-bounds write via TSIG record processing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-4046 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Denial of Service via iconv() function with specific character sets — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6238 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Application crash or uninitialized memory read via crafted DNS response — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5928 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5450 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5435 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Out-of-bounds write via TSIG record processing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-4046 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Denial of Service via iconv() function with specific character sets — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | libblkid1 | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | libblkid1 | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | bsdutils | 1:2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | bsdutils | 1:2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | libuuid1 | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | libuuid1 | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | libsmartcols1 | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | libsmartcols1 | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-54411 | libpam0g | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-54411 | libpam-runtime | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-54411 | libpam-modules-bin | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-54411 | libpam-modules | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13757 | libp11-kit0 | 0.26.2-2 | p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | libmount1 | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | libmount1 | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-6238 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Application crash or uninitialized memory read via crafted DNS response — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-27171 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| LOW | CVE-2026-40228 | libsystemd0 | 259.5-0ubuntu3 | systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| LOW | CVE-2026-40228 | libudev1 | 259.5-0ubuntu3 | systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| LOW | CVE-2024-2236 | libgcrypt20 | 1.12.0-2ubuntu1 | libgcrypt: vulnerable to Marvin Attack — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| LOW | CVE-2024-56433 | passwd | 1:4.17.4-2ubuntu3 | shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| LOW | CVE-2024-56433 | login.defs | 1:4.17.4-2ubuntu3 | shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| UNKNOWN | CVE-2026-46600 | golang.org/x/net | v0.40.0 | 0.56.0 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ... — usr/bin/pebble |
| UNKNOWN | CVE-2026-39824 | golang.org/x/sys | v0.33.0 | 0.44.0 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows — usr/bin/pebble |
Grype
HIGH 2
MEDIUM 183
LOW 13
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GHSA-jr6h-r7vg-f9mc | ini4j | 0.5.4 | org.ini4j allows attackers to cause a Denial of Service (DoS) — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar | |
| HIGH | GO-2026-5026 | golang.org/x/net | v0.40.0 | 0.55.0 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/pebble |
| MEDIUM | CVE-2026-27456 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35344 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35367 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35370 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35359 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18477 | tar | 1.35+dfsg-4ubuntu0.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35360 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35377 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35345 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35354 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35364 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51295 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-11856 | curl | 8.18.0-1ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35341 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54369 | libacl1 | 2.3.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56392 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56392 | gnu-coreutils | 9.7-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35352 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35368 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13757 | libp11-kit0 | 0.26.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56391 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56391 | gnu-coreutils | 9.7-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35348 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35351 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18508 | tar | 1.35+dfsg-4ubuntu0.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54371 | libattr1 | 1:2.5.2-4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35350 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35371 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35373 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51296 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51297 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51298 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51300 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51302 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51303 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51304 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35357 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54370 | libacl1 | 2.3.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35374 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51290 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51291 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51292 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51293 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51294 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | GO-2026-5856 | stdlib | go1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/bin/pebble |
| MEDIUM | CVE-2026-4046 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-4046 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-4046 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-12087 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-12087 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-12087 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-12087 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47058 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-66033 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-5928 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5928 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5928 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6238 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6238 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6238 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57433 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57433 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57433 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-11856 | libcurl4t64 | 8.18.0-1ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-5450 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5450 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5450 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-47057 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13221 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13221 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13221 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13221 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54876 | libssl3t64 | 3.5.5-1ubuntu3.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54876 | openssl | 3.5.5-1ubuntu3.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54876 | openssl-provider-legacy | 3.5.5-1ubuntu3.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47063 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53910 | diffutils | 1:3.12-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-66034 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47010 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-5435 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5435 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5435 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57432 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57432 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57432 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57432 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35363 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54411 | libpam-modules-bin | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-54411 | libpam-modules | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-54411 | libpam-runtime | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-54411 | libpam0g | 1.7.0-5ubuntu3 | 1.7.0-5ubuntu3.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57433 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-66035 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47059 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47021 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-46917 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47027 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-66032 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-60147 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-46968 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| LOW | CVE-2018-10126 | libjpeg-turbo8 | 2.1.5-4ubuntu4 | /var/lib/dpkg/status | |
| LOW | CVE-2024-2236 | libgcrypt20 | 1.12.0-2ubuntu1 | /var/lib/dpkg/status | |
| LOW | CVE-2026-40228 | libudev1 | 259.5-0ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-40228 | libsystemd0 | 259.5-0ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-57062 | gpgv | 2.4.8-4ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2025-5278 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | /var/lib/dpkg/status | |
| LOW | CVE-2025-5278 | gnu-coreutils | 9.7-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-42250 | libbz2-1.0 | 1.0.8-6build2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-8932 | libcurl4t64 | 8.18.0-1ubuntu2.3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-8932 | curl | 8.18.0-1ubuntu2.3 | /var/lib/dpkg/status | |
| LOW | CVE-2024-56433 | passwd | 1:4.17.4-2ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2024-56433 | login.defs | 1:4.17.4-2ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-27171 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | /var/lib/dpkg/status |
ghcr.io/openvoxproject/openvoxdb:latest-alpine (2026-07-23)
Trivy
HIGH 3
MEDIUM 5
LOW 2
UNKNOWN 1
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-41254 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| HIGH | CVE-2026-47063 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Enhance Jar handling (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| HIGH | CVE-2022-41404 | org.ini4j:ini4j | 0.5.4 | org.ini4j: unspecified DoS — Java | |
| MEDIUM | CVE-2026-46917 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Improve DTLS handshaking (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-46968 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-47021 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Enhance XBM image support (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-47027 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Enhance Jar file processing (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-60147 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Improve certification checking (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-47010 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Enhance JPEG handling (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-47059 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Enhance AWT ImagingLib (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| UNKNOWN | CVE-2026-62574 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
Grype
HIGH 4
MEDIUM 5
LOW 2
NVD/CPE filtered 9
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GHSA-jr6h-r7vg-f9mc | ini4j | 0.5.4 | org.ini4j allows attackers to cause a Denial of Service (DoS) — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar | |
| HIGH | CVE-2026-41254 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-47063 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-62574 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-60147 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-47021 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-46968 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-46917 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-47027 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-47059 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-47010 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
Filtered NVD/CPE matches (9)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| MEDIUM | CVE-2016-2781 | coreutils | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils-env | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils-fmt | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils-sha512sum | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-5704 | tar | 1.35-r5 | A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed |
ghcr.io/openvoxproject/openvoxserver
Downloads
ghcr.io/openvoxproject/openvoxserver:latest (2026-07-24)
Trivy
CRITICAL 2
HIGH 50
MEDIUM 616
LOW 98
UNKNOWN 2
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-53260 | linux-libc-dev | 7.0.0-28.28 | kernel: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| CRITICAL | CVE-2026-53215 | linux-libc-dev | 7.0.0-28.28 | kernel: net: mvpp2: refill RX buffers before XDP or skb use — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53145 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/gem: Try to fix change_handle ioctl, attempt 4 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-52924 | linux-libc-dev | 7.0.0-28.28 | kernel: sctp: purge outqueue on stale COOKIE-ECHO handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-52910 | linux-libc-dev | 7.0.0-28.28 | kernel: bpf: Free reuseport cBPF prog after RCU grace period — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-52909 | linux-libc-dev | 7.0.0-28.28 | kernel: ip6_vti: set netns_immutable on the fallback device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-52908 | linux-libc-dev | 7.0.0-28.28 | kernel: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-46331 | linux-libc-dev | 7.0.0-28.28 | kernel: net/sched: act_pedit: extend the writable skb range per key — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2025-40190 | linux-libc-dev | 7.0.0-28.28 | kernel: ext4: guard against EA inode refcount underflow in xattr update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53235 | linux-libc-dev | 7.0.0-28.28 | kernel: net: add pskb_may_pull() to skb_gro_receive_list() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53239 | linux-libc-dev | 7.0.0-28.28 | kernel: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53240 | linux-libc-dev | 7.0.0-28.28 | kernel: xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53250 | linux-libc-dev | 7.0.0-28.28 | kernel: xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53254 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: RFCOMM: validate skb length in MCC handlers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53256 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53259 | linux-libc-dev | 7.0.0-28.28 | kernel: ipv6: anycast: insert aca into global hash under idev->lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53262 | linux-libc-dev | 7.0.0-28.28 | kernel: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53264 | linux-libc-dev | 7.0.0-28.28 | kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53266 | linux-libc-dev | 7.0.0-28.28 | kernel: Linux kernel: netfilter: ebtables SNAT target writes to shared memory pages during ARP hardware address rewrite — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53269 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: synproxy: add mutex to guard hook reference counting — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2022-41404 | org.ini4j:ini4j | 0.5.4 | org.ini4j: unspecified DoS — Java | |
| HIGH | CVE-2026-53224 | linux-libc-dev | 7.0.0-28.28 | kernel: sctp: validate embedded INIT chunk and address list lengths in cookie — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53212 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: nft_tunnel: fix use-after-free on object destroy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53198 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53196 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53193 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: timer: Forcibly close timer instances at closing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53192 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: timer: Fix UAF at snd_timer_user_params() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53186 | linux-libc-dev | 7.0.0-28.28 | kernel: RDMA/srp: bound SRP_RSP sense copy by the received length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53185 | linux-libc-dev | 7.0.0-28.28 | kernel: zram: fix use-after-free in zram_bvec_write_partial() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53183 | linux-libc-dev | 7.0.0-28.28 | kernel: mptcp: allow subflow rcv wnd to shrink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53182 | linux-libc-dev | 7.0.0-28.28 | kernel: wifi: nl80211: reject oversized EMA RNR lists — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53178 | linux-libc-dev | 7.0.0-28.28 | kernel: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53176 | linux-libc-dev | 7.0.0-28.28 | kernel: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53175 | linux-libc-dev | 7.0.0-28.28 | kernel: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53173 | linux-libc-dev | 7.0.0-28.28 | kernel: accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53172 | linux-libc-dev | 7.0.0-28.28 | kernel: accel/ethosu: fix IFM region index out-of-bounds in command stream parser — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53171 | linux-libc-dev | 7.0.0-28.28 | kernel: accel/ethosu: fix arithmetic issues in dma_length() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53170 | linux-libc-dev | 7.0.0-28.28 | kernel: accel/ethosu: reject DMA commands with uninitialized length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53159 | linux-libc-dev | 7.0.0-28.28 | kernel: misc: fastrpc: fix DMA address corruption due to find_vma misuse — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53153 | linux-libc-dev | 7.0.0-28.28 | kernel: mm/list_lru: drain before clearing xarray entry on reparent — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53151 | linux-libc-dev | 7.0.0-28.28 | kernel: rxrpc: Fix the ACK parser to extract the SACK table for parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53148 | linux-libc-dev | 7.0.0-28.28 | kernel: thunderbolt: Clamp XDomain response data copy to allocation size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-25681 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting — usr/bin/pebble |
| HIGH | CVE-2026-27136 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass — usr/bin/pebble |
| HIGH | CVE-2026-33814 | golang.org/x/net | v0.40.0 | 0.53.0 | net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame — usr/bin/pebble |
| HIGH | CVE-2026-39821 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/bin/pebble |
| HIGH | CVE-2026-39822 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | golang: Go os.Root: Symlink following vulnerability allows directory traversal — usr/bin/pebble |
| HIGH | CVE-2026-64531 | linux-libc-dev | 7.0.0-28.28 | kernel: net: openvswitch: reject oversized nested action attrs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53359 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53276 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: ISO: Fix a use-after-free of the hci_conn pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53275 | linux-libc-dev | 7.0.0-28.28 | kernel: ipv6: mcast: Fix use-after-free when processing MLD queries — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-53270 | linux-libc-dev | 7.0.0-28.28 | kernel: ipvs: clear the svc scheduler ptr early on edit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64395 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: require source read access for duplicate extents — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64376 | linux-libc-dev | 7.0.0-28.28 | kernel: firmware_loader: fix device reference leak in firmware_upload_register() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64375 | linux-libc-dev | 7.0.0-28.28 | kernel: proc: protect ptrace_may_access() with exec_update_lock (FD links) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64374 | linux-libc-dev | 7.0.0-28.28 | kernel: sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64373 | linux-libc-dev | 7.0.0-28.28 | kernel: cpufreq: Fix hotplug-suspend race during reboot — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64372 | linux-libc-dev | 7.0.0-28.28 | kernel: cpufreq: pcc: fix use-after-free and double free in _OSC evaluation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64371 | linux-libc-dev | 7.0.0-28.28 | kernel: proc: protect ptrace_may_access() with exec_update_lock (part 1) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64370 | linux-libc-dev | 7.0.0-28.28 | kernel: posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64369 | linux-libc-dev | 7.0.0-28.28 | kernel: s390: Revert support for DCACHE_WORD_ACCESS — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64368 | linux-libc-dev | 7.0.0-28.28 | kernel: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64367 | linux-libc-dev | 7.0.0-28.28 | kernel: HID: hid-goodix-spi: validate report size to prevent stack buffer overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64366 | linux-libc-dev | 7.0.0-28.28 | kernel: HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64365 | linux-libc-dev | 7.0.0-28.28 | kernel: HID: letsketch: fix UAF on inrange_timer at driver unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64394 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64393 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: run set info with opener credentials — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64392 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: use opener credentials for delete-on-close — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64391 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: use opener credentials for ADS I/O — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64390 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: track the connection owning a byte-range lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64389 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: validate NTLMv2 response before updating session key — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64388 | linux-libc-dev | 7.0.0-28.28 | kernel: smb/client: fix chown/chgrp with SMB3 POSIX Extensions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64387 | linux-libc-dev | 7.0.0-28.28 | kernel: smb: client: fix query directory replay double-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64386 | linux-libc-dev | 7.0.0-28.28 | kernel: smb: client: fix query_info() replay double-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64385 | linux-libc-dev | 7.0.0-28.28 | kernel: smb: client: fix double-free in SMB2_ioctl() replay — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64384 | linux-libc-dev | 7.0.0-28.28 | kernel: smb: client: fix change notify replay double-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64383 | linux-libc-dev | 7.0.0-28.28 | kernel: smb: client: fix double-free in SMB2_flush() replay — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64382 | linux-libc-dev | 7.0.0-28.28 | kernel: smb: client: fix double-free in SMB2_open() replay — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64381 | linux-libc-dev | 7.0.0-28.28 | kernel: smb: client: Fix next buffer leak in receive_encrypted_standard() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64380 | linux-libc-dev | 7.0.0-28.28 | kernel: smb: client: harden POSIX SID length parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64379 | linux-libc-dev | 7.0.0-28.28 | kernel: smb: client: mask server-provided mode to 07777 in modefromsid — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64378 | linux-libc-dev | 7.0.0-28.28 | kernel: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64377 | linux-libc-dev | 7.0.0-28.28 | kernel: cpufreq: qcom-cpufreq-hw: Fix possible double free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64396 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64420 | linux-libc-dev | 7.0.0-28.28 | kernel: mfd: cros_ec: Delay dev_set_drvdata() until probe success — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64421 | linux-libc-dev | 7.0.0-28.28 | kernel: media: nxp: imx8-isi: Fix use-after-free on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64422 | linux-libc-dev | 7.0.0-28.28 | kernel: net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64423 | linux-libc-dev | 7.0.0-28.28 | kernel: ipv4: igmp: remove multicast group from hash table on device destruction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64424 | linux-libc-dev | 7.0.0-28.28 | kernel: netpoll: fix a use-after-free on shutdown path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64425 | linux-libc-dev | 7.0.0-28.28 | kernel: io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64426 | linux-libc-dev | 7.0.0-28.28 | kernel: io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64428 | linux-libc-dev | 7.0.0-28.28 | kernel: gpio: sch: use raw_spinlock_t in the irq startup path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64429 | linux-libc-dev | 7.0.0-28.28 | kernel: gpio: eic-sprd: use raw_spinlock_t in the irq startup path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64430 | linux-libc-dev | 7.0.0-28.28 | kernel: NTB: epf: Avoid calling pci_irq_vector() from hardirq context — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64432 | linux-libc-dev | 7.0.0-28.28 | kernel: fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64433 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64434 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64435 | linux-libc-dev | 7.0.0-28.28 | kernel: audit: Fix data races of skb_queue_len() readers on audit_queue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64436 | linux-libc-dev | 7.0.0-28.28 | kernel: net: af_key: initialize alg_key_len for IPComp states — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64438 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64439 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: krb5 - filter out async aead implementations at alloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64440 | linux-libc-dev | 7.0.0-28.28 | kernel: staging: rtl8723bs: fix OOB write in HT_caps_handler() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64441 | linux-libc-dev | 7.0.0-28.28 | kernel: staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64442 | linux-libc-dev | 7.0.0-28.28 | kernel: staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64443 | linux-libc-dev | 7.0.0-28.28 | kernel: staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64444 | linux-libc-dev | 7.0.0-28.28 | kernel: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64445 | linux-libc-dev | 7.0.0-28.28 | kernel: staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64397 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: serialize QUERY_DIRECTORY requests per file — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64398 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: add a permission check for FSCTL_SET_ZERO_DATA — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64399 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64400 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: prevent path traversal bypass by restricting caseless retry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64401 | linux-libc-dev | 7.0.0-28.28 | kernel: smb: client: resolve SWN tcon from live registrations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64402 | linux-libc-dev | 7.0.0-28.28 | kernel: coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64403 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: L2CAP: validate option length before reading conf opt value — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64404 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64405 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64406 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: fix UAF in bt_accept_dequeue() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64407 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64408 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: bnep: pin L2CAP connection during netdev registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64409 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64410 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: flowtable: IPIP tunnel hardware offload is not yet support — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64411 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: ebtables: terminate table name before find_table_lock() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64412 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: ebtables: module names must be null-terminated — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64413 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: ebtables: zero chainstack array — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64414 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: handle unreadable frags — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64415 | linux-libc-dev | 7.0.0-28.28 | kernel: mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64416 | linux-libc-dev | 7.0.0-28.28 | kernel: mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64417 | linux-libc-dev | 7.0.0-28.28 | kernel: mm: shrinker: fix NULL pointer dereference in debugfs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64418 | linux-libc-dev | 7.0.0-28.28 | kernel: mm: shrinker: fix shrinker_info teardown race with expansion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64419 | linux-libc-dev | 7.0.0-28.28 | kernel: mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | bsdutils | 1:2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64306 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: drbg - Fix returning success on failure in CTR_DRBG — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64307 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64308 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64309 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64310 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: ccp - Do not initialize SNP for SEV ioctls — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64312 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: pcrypt - restore callback for non-parallel fallback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64313 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: ecc - Fix carry overflow in vli multiplication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64314 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: chacha20poly1305 - validate poly1305 template argument — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64315 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: caam - use print_hex_dump_devel to guard key hex dumps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64316 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: caam - use print_hex_dump_devel to guard key hex dumps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64317 | linux-libc-dev | 7.0.0-28.28 | kernel: isofs: bound Rock Ridge symlink components to the SL record — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64318 | linux-libc-dev | 7.0.0-28.28 | kernel: partitions: aix: bound the pp_count scan to the ppe array — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64319 | linux-libc-dev | 7.0.0-28.28 | kernel: nvmet-auth: validate reply message payload bounds against transfer length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64320 | linux-libc-dev | 7.0.0-28.28 | kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64321 | linux-libc-dev | 7.0.0-28.28 | kernel: nvme: target: rdma: fix ndev refcount leak on queue connect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64322 | linux-libc-dev | 7.0.0-28.28 | kernel: udf: validate sparing table length as an entry count, not a byte count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64323 | linux-libc-dev | 7.0.0-28.28 | kernel: udf: validate VAT header length against the VAT inode size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64324 | linux-libc-dev | 7.0.0-28.28 | kernel: udf: validate free block extents against the partition length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64325 | linux-libc-dev | 7.0.0-28.28 | kernel: wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64287 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64288 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64289 | linux-libc-dev | 7.0.0-28.28 | kernel: iommufd: Set upper bounds on cache invalidation entry_num and entry_len — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64290 | linux-libc-dev | 7.0.0-28.28 | kernel: iommufd: Break the loop on failure in iommufd_fault_fops_read() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64291 | linux-libc-dev | 7.0.0-28.28 | kernel: iommufd: Set veventq_depth upper bound — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64292 | linux-libc-dev | 7.0.0-28.28 | kernel: iommufd: Move vevent memory allocation outside spinlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64293 | linux-libc-dev | 7.0.0-28.28 | kernel: iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64294 | linux-libc-dev | 7.0.0-28.28 | kernel: mm: do file ownership checks with the proper mount idmap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64295 | linux-libc-dev | 7.0.0-28.28 | kernel: mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN access — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64296 | linux-libc-dev | 7.0.0-28.28 | kernel: exfat: bound uniname advance in exfat_find_dir_entry() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64297 | linux-libc-dev | 7.0.0-28.28 | kernel: module: decompress: check return value of module_extend_max_pages() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64298 | linux-libc-dev | 7.0.0-28.28 | kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64299 | linux-libc-dev | 7.0.0-28.28 | kernel: tracing: Prevent out-of-bounds read in glob matching — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64300 | linux-libc-dev | 7.0.0-28.28 | kernel: perf/aux: Fix page UAF in map_range() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64301 | linux-libc-dev | 7.0.0-28.28 | kernel: regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64302 | linux-libc-dev | 7.0.0-28.28 | kernel: x86/mm: Fix freeing of PMD-sized vmemmap pages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64303 | linux-libc-dev | 7.0.0-28.28 | kernel: spi: fsl-lpspi: terminate the RX channel on TX prepare failure path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64304 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: qat - validate RSA CRT component lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64305 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: qat - protect service table iterations with service_lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64326 | linux-libc-dev | 7.0.0-28.28 | kernel: block: skip sync_blockdev() on surprise removal in bdev_mark_dead() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64346 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: gadget: udc: Fix use-after-free in gadget_match_driver — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64347 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64348 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: free iso schedules on failed submit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64349 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64350 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64351 | linux-libc-dev | 7.0.0-28.28 | kernel: net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64352 | linux-libc-dev | 7.0.0-28.28 | kernel: bpf: Allow LPM map access from sleepable BPF programs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64353 | linux-libc-dev | 7.0.0-28.28 | kernel: bpf: Keep dynamic inner array lookups nullable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64354 | linux-libc-dev | 7.0.0-28.28 | kernel: bpf: Validate BTF repeated field counts before expansion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64355 | linux-libc-dev | 7.0.0-28.28 | kernel: bpf: Reject fragmented frames in devmap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64356 | linux-libc-dev | 7.0.0-28.28 | kernel: xfs: fix memory leak in xfs_dqinode_metadir_create() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64357 | linux-libc-dev | 7.0.0-28.28 | kernel: xfs: fix exchmaps reservation limit check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64358 | linux-libc-dev | 7.0.0-28.28 | kernel: media: mtk-jpeg: cancel workqueue on release for supported platforms only — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64359 | linux-libc-dev | 7.0.0-28.28 | kernel: nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64360 | linux-libc-dev | 7.0.0-28.28 | kernel: hfs/hfsplus: zero-initialize buffer in hfs_bnode_read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64361 | linux-libc-dev | 7.0.0-28.28 | kernel: hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64362 | linux-libc-dev | 7.0.0-28.28 | kernel: HID: lg-g15: cancel pending work on remove to fix a use-after-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64363 | linux-libc-dev | 7.0.0-28.28 | kernel: HID: appleir: fix UAF on pending key_up_timer in remove() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64364 | linux-libc-dev | 7.0.0-28.28 | kernel: HID: multitouch: fix out-of-bounds bit access on mt_io_flags — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64327 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64328 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: gadget: f_fs: Fix DMA fence leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64329 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64330 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: typec: tcpm: Validate SVID index in svdm_consume_modes() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64331 | linux-libc-dev | 7.0.0-28.28 | kernel: usbip: vudc: fix NULL deref in vep_dequeue() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64332 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: ulpi: fix memory leak on registration failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64333 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: serial: digi_acceleport: fix write buffer corruption — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64334 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: serial: digi_acceleport: fix hard lockup on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64335 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: serial: digi_acceleport: fix broken rx after throttle — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64336 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: serial: keyspan_pda: fix information leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64337 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: mtu3: unmap request DMA on queue failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64338 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: misc: uss720: unregister parport on probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64339 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: misc: usbio: bound bulk IN response length to the received transfer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64340 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: legousbtower: fix use-after-free on disconnect race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64341 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: iowarrior: fix use-after-free on disconnect race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64342 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: iowarrior: fix use-after-free on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64343 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: ldusb: fix use-after-free on disconnect race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64344 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: idmouse: fix use-after-free on disconnect race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64345 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: gadget: f_printer: take kref only for successful open — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64541 | linux-libc-dev | 7.0.0-28.28 | kernel: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64561 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64562 | linux-libc-dev | 7.0.0-28.28 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64563 | linux-libc-dev | 7.0.0-28.28 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64564 | linux-libc-dev | 7.0.0-28.28 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64565 | linux-libc-dev | 7.0.0-28.28 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64566 | linux-libc-dev | 7.0.0-28.28 | kernel: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64567 | linux-libc-dev | 7.0.0-28.28 | kernel: btrfs: reject free space cache with more entries than pages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64568 | linux-libc-dev | 7.0.0-28.28 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64569 | linux-libc-dev | 7.0.0-28.28 | kernel: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64570 | linux-libc-dev | 7.0.0-28.28 | kernel: wifi: mac80211: fix fils_discovery double free on alloc failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64571 | linux-libc-dev | 7.0.0-28.28 | kernel: wifi: p54: validate RX frame length in p54_rx_eeprom_readback() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64572 | linux-libc-dev | 7.0.0-28.28 | kernel: ipv4: fib: free fib_alias with kfree_rcu() on insert error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64573 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: qca: fix NVM tag length underflow in TLV parser — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64574 | linux-libc-dev | 7.0.0-28.28 | kernel: wifi: mac80211: tear down new links on vif update error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64575 | linux-libc-dev | 7.0.0-28.28 | kernel: bpf: tcp: fix double sock release on batch realloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64576 | linux-libc-dev | 7.0.0-28.28 | kernel: nexthop: initialize extack in nh_res_bucket_migrate() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64577 | linux-libc-dev | 7.0.0-28.28 | kernel: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64578 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: validate compound request size before reading StructureSize2 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64579 | linux-libc-dev | 7.0.0-28.28 | kernel: xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64542 | linux-libc-dev | 7.0.0-28.28 | kernel: ipv6: ndisc: fix NULL deref in accept_untracked_na() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64543 | linux-libc-dev | 7.0.0-28.28 | kernel: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64544 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64545 | linux-libc-dev | 7.0.0-28.28 | kernel: net, bpf: check master for NULL in xdp_master_redirect() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64546 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/edid: fix OOB read in drm_parse_tiled_block() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64547 | linux-libc-dev | 7.0.0-28.28 | kernel: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64548 | linux-libc-dev | 7.0.0-28.28 | kernel: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64549 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64550 | linux-libc-dev | 7.0.0-28.28 | kernel: net: qualcomm: rmnet: validate MAP frame length before ingress parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64551 | linux-libc-dev | 7.0.0-28.28 | kernel: sctp: validate STALE_COOKIE cause length before reading staleness — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64552 | linux-libc-dev | 7.0.0-28.28 | kernel: virtio-net: fix len check in receive_big() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64553 | linux-libc-dev | 7.0.0-28.28 | kernel: net: psample: fix info leak in PSAMPLE_ATTR_DATA — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64554 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64555 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64556 | linux-libc-dev | 7.0.0-28.28 | kernel: perf/core: Detach event groups during remove_on_exec — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64557 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64558 | linux-libc-dev | 7.0.0-28.28 | kernel: s390/pkey: Check length in pkey_pckmo handler implementation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64559 | linux-libc-dev | 7.0.0-28.28 | kernel: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64560 | linux-libc-dev | 7.0.0-28.28 | kernel: posix-cpu-timers: Prevent UAF caused by non-leader exec() race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64580 | linux-libc-dev | 7.0.0-28.28 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35359 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utilit ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35360 | rust-coreutils | 0.8.0-0ubuntu3 | The touch utility in uutils coreutils is vulnerable to a Time-of-Check ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35363 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in the rm utility of uutils coreutils allows the bypas ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35364 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35367 | rust-coreutils | 0.8.0-0ubuntu3 | The nohup utility in uutils coreutils creates its default output file, ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35368 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability exists in the chroot utility of uutils coreutils when ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35370 | rust-coreutils | 0.8.0-0ubuntu3 | The id utility in uutils coreutils miscalculates the groups= section o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35371 | rust-coreutils | 0.8.0-0ubuntu3 | The id utility in uutils coreutils exhibits incorrect behavior in its ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35373 | rust-coreutils | 0.8.0-0ubuntu3 | A logic error in the ln utility of uutils coreutils causes the program ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35374 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the sp ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35377 | rust-coreutils | 0.8.0-0ubuntu3 | A logic error in the env utility of uutils coreutils causes a failure ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | util-linux | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | util-linux | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2025-47911 | golang.org/x/net | v0.40.0 | 0.45.0 | golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html — usr/bin/pebble |
| MEDIUM | CVE-2025-58190 | golang.org/x/net | v0.40.0 | 0.45.0 | golang.org/x/net/html: Infinite parsing loop in golang.org/x/net — usr/bin/pebble |
| MEDIUM | CVE-2026-25680 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing — usr/bin/pebble |
| MEDIUM | CVE-2026-42502 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering — usr/bin/pebble |
| MEDIUM | CVE-2026-42506 | golang.org/x/net | v0.40.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing — usr/bin/pebble |
| MEDIUM | CVE-2026-42505 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — usr/bin/pebble |
| MEDIUM | CVE-2026-64581 | linux-libc-dev | 7.0.0-28.28 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64582 | linux-libc-dev | 7.0.0-28.28 | kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64600 | linux-libc-dev | 7.0.0-28.28 | kernel: XFS data corruption using reflink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | mount | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | mount | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-55655 | openssh-client | 1:10.2p1-2ubuntu3.5 | openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Red Hat Enterprise Linux OpenSSH client versions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2025-10990 | ruby3.3 | 3.3.8-2ubuntu3.1 | rexml: REXML: Denial of Service via inefficient regex parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2025-10990 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | rexml: REXML: Denial of Service via inefficient regex parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35341 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in uutils coreutils mkfifo allows for the unauthorized ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35344 | rust-coreutils | 0.8.0-0ubuntu3 | The dd utility in uutils coreutils suppresses errors during file trunc ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35345 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in the tail utility of uutils coreutils allows for the ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35348 | rust-coreutils | 0.8.0-0ubuntu3 | The sort utility in uutils coreutils is vulnerable to a process panic ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35350 | rust-coreutils | 0.8.0-0ubuntu3 | The cp utility in uutils coreutils fails to properly handle setuid and ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35351 | rust-coreutils | 0.8.0-0ubuntu3 | The mv utility in uutils coreutils fails to preserve file ownership du ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35352 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35354 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35357 | rust-coreutils | 0.8.0-0ubuntu3 | The cp utility in uutils coreutils is vulnerable to an information dis ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64446 | linux-libc-dev | 7.0.0-28.28 | kernel: staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64466 | linux-libc-dev | 7.0.0-28.28 | kernel: rust_binder: clear freeze listener on node removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64467 | linux-libc-dev | 7.0.0-28.28 | kernel: rust_binder: use a u64 stride when cleaning up the offsets array — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64468 | linux-libc-dev | 7.0.0-28.28 | kernel: binder: fix UAF in binder_free_transaction() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64469 | linux-libc-dev | 7.0.0-28.28 | kernel: binder: fix UAF in binder_thread_release() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64470 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: btusb: fix use-after-free on marvell probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64471 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: btusb: fix use-after-free on registration failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64472 | linux-libc-dev | 7.0.0-28.28 | kernel: vfio/mlx5: Fix racy bitfields and tighten struct layout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64473 | linux-libc-dev | 7.0.0-28.28 | kernel: vfio: Remove device debugfs before releasing devres — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64474 | linux-libc-dev | 7.0.0-28.28 | kernel: vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64475 | linux-libc-dev | 7.0.0-28.28 | kernel: vfio/pci: Release the VGA arbiter client on register_device() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64476 | linux-libc-dev | 7.0.0-28.28 | kernel: vfio/pci: Latch disable_idle_d3 per device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64477 | linux-libc-dev | 7.0.0-28.28 | kernel: x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64478 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: usb-audio: avoid kobject path lookup in DualSense match — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64479 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64480 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: ice1712: check snd_ctl_new1() return value — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64481 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: hda/cs35l41: Fix firmware load work teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64482 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: gus: check snd_ctl_new1() return value — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64483 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: firewire: isight: bound the sample count to the packet payload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64484 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: es1938: check snd_ctl_new1() return value — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64447 | linux-libc-dev | 7.0.0-28.28 | kernel: staging: media: ipu7: fix double-free and use-after-free in error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64448 | linux-libc-dev | 7.0.0-28.28 | kernel: smb: client: restrict implied bcc[0] exemption to responses without data area — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64449 | linux-libc-dev | 7.0.0-28.28 | kernel: staging: vme_user: bound slave read/write to the kern_buf size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64450 | linux-libc-dev | 7.0.0-28.28 | kernel: tipc: fix out-of-bounds read in broadcast Gap ACK blocks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64451 | linux-libc-dev | 7.0.0-28.28 | kernel: tracing: Fix NULL pointer dereference in func_set_flag() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64452 | linux-libc-dev | 7.0.0-28.28 | kernel: 6lowpan: fix NHC entry use-after-free on error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64453 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: misc: usbio: fix disconnect UAF in client teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64454 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: dwc3: run gadget disconnect from sleepable suspend context — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64455 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: chaoskey: Fix slab-use-after-free in chaoskey_release() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64456 | linux-libc-dev | 7.0.0-28.28 | kernel: hwrng: virtio: clamp device-reported used.len at copy_data() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64457 | linux-libc-dev | 7.0.0-28.28 | kernel: virtio_pci: fix vq info pointer lookup via wrong index — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64458 | linux-libc-dev | 7.0.0-28.28 | kernel: mm/damon/ops-common: handle extreme intervals in damon_hot_score() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64459 | linux-libc-dev | 7.0.0-28.28 | kernel: tcp: restore RCU grace period in tcp_ao_destroy_sock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64460 | linux-libc-dev | 7.0.0-28.28 | kernel: PCI/IOV: Skip VF Resizable BAR restore on read error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64461 | linux-libc-dev | 7.0.0-28.28 | kernel: PCI: mediatek: Fix IRQ domain leak when port fails to enable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64462 | linux-libc-dev | 7.0.0-28.28 | kernel: PCI: altera: Fix resource leaks on probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64463 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64464 | linux-libc-dev | 7.0.0-28.28 | kernel: xhci: sideband: fix ring sg table pages leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64465 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: xhci: Fix sleep in atomic context in xhci_free_streams() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64485 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: compress: Fix task creation error unwind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64507 | linux-libc-dev | 7.0.0-28.28 | kernel: x86/bugs: Enable IBPB flush on BPF JIT allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64508 | linux-libc-dev | 7.0.0-28.28 | kernel: bpf: Support for hardening against JIT spraying — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64509 | linux-libc-dev | 7.0.0-28.28 | kernel: rust: block: fix GenDisk cleanup paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64510 | linux-libc-dev | 7.0.0-28.28 | kernel: ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64511 | linux-libc-dev | 7.0.0-28.28 | kernel: ACPI: NFIT: core: Fix possible NULL pointer dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64512 | linux-libc-dev | 7.0.0-28.28 | kernel: ACPI: CPPC: Suppress UBSAN warning caused by field misuse — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64513 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: x86: Unconditionally recompute CR8 intercept on PPR update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64514 | linux-libc-dev | 7.0.0-28.28 | kernel: userfaultfd: gate must_wait writability check on pte_present() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64529 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: qat - remove unused character device and IOCTLs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64530 | linux-libc-dev | 7.0.0-28.28 | kernel: net: sched: UAF via missing handler for TC_ACT_CONSUMED in tcf_qevent_handle — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64532 | linux-libc-dev | 7.0.0-28.28 | kernel: fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64533 | linux-libc-dev | 7.0.0-28.28 | kernel: fs/ntfs3: validate lcns_follow in log_replay conversion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64534 | linux-libc-dev | 7.0.0-28.28 | kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64535 | linux-libc-dev | 7.0.0-28.28 | kernel: nvmet-tcp: Fix potential UAF when ddgst mismatch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64536 | linux-libc-dev | 7.0.0-28.28 | kernel: staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64537 | linux-libc-dev | 7.0.0-28.28 | kernel: bridge: cfm: reject invalid CCM interval at configuration time — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64538 | linux-libc-dev | 7.0.0-28.28 | kernel: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64539 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: eir: Fix stack OOB write when prepending the Flags AD — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64540 | linux-libc-dev | 7.0.0-28.28 | kernel: usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64486 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: cmipci: check snd_ctl_new1() return value — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64487 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64488 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: aoa: check snd_ctl_new1() return value — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64489 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: ymfpci: check snd_ctl_new1() return value — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64490 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: virtio: Validate control metadata from the device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64491 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: usx2y: us144mkii: fix work UAF on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64492 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: temperature: tmp006: use devm_iio_trigger_register — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64493 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: pressure: mpl115: fix runtime PM leak on read error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64494 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: light: gp2ap002: fix runtime PM leak on read error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64495 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: gyro: bmg160: bail out when bandwidth/filter is not in table — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64496 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: event: Fix event FIFO reset race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64497 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: chemical: scd30: Cleanup initializations and fix sign-extension bug — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64499 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: adc: ti-ads1119: fix PM reference leak in buffer preenable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64500 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: adc: lpc32xx: Initialize completion before requesting IRQ — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64501 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: adc: ad_sigma_delta: fix CS held asserted and state leaks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64502 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64503 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64504 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: accel: bmc150: clamp the device-reported FIFO frame count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64505 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: gadget: function: rndis: add length check for header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53139 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/v3d: Skip CSD when it has zeroed workgroups — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53140 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53141 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/v3d: Fix global performance monitor reference counting — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53143 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53144 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/amdkfd: fix NULL dereference in get_queue_ids() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53149 | linux-libc-dev | 7.0.0-28.28 | kernel: thunderbolt: Bound root directory content to block size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53150 | linux-libc-dev | 7.0.0-28.28 | kernel: thunderbolt: Reject zero-length property entries in validator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53155 | linux-libc-dev | 7.0.0-28.28 | kernel: mm/huge_memory: use correct flags for device private PMD entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53163 | linux-libc-dev | 7.0.0-28.28 | kernel: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53164 | linux-libc-dev | 7.0.0-28.28 | kernel: iommu/dma: Do not try to iommu_map a 0 length region in swiotlb — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53165 | linux-libc-dev | 7.0.0-28.28 | kernel: iomap: avoid potential null folio->mapping deref during error reporting — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53167 | linux-libc-dev | 7.0.0-28.28 | kernel: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53168 | linux-libc-dev | 7.0.0-28.28 | kernel: fuse: reject fuse_notify() pagecache ops on directories — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53169 | linux-libc-dev | 7.0.0-28.28 | kernel: accel/ethosu: reject NPU_OP_RESIZE commands from userspace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53179 | linux-libc-dev | 7.0.0-28.28 | kernel: staging: rtl8723bs: fix buffer over-read in rtw_update_protection — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53180 | linux-libc-dev | 7.0.0-28.28 | kernel: timers/migration: Fix livelock in tmigr_handle_remote_up() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53181 | linux-libc-dev | 7.0.0-28.28 | kernel: vsock/vmci: fix sk_ack_backlog leak on failed handshake — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53184 | linux-libc-dev | 7.0.0-28.28 | kernel: udp: clear skb->dev before running a sockmap verdict — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53187 | linux-libc-dev | 7.0.0-28.28 | kernel: RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2025-21988 | linux-libc-dev | 7.0.0-28.28 | kernel: fs/netfs/read_collect: add to next->prev_donated — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-46055 | linux-libc-dev | 7.0.0-28.28 | kernel: apparmor: Fix string overrun due to missing termination — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-52917 | linux-libc-dev | 7.0.0-28.28 | kernel: sctp: diag: reject stale associations in dump_one path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-52929 | linux-libc-dev | 7.0.0-28.28 | kernel: sctp: stream: fully roll back denied add-stream state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-52930 | linux-libc-dev | 7.0.0-28.28 | kernel: ipc/shm: serialize orphan cleanup with shm_nattch updates — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-52935 | linux-libc-dev | 7.0.0-28.28 | kernel: xfrm: espintcp: do not reuse an in-progress partial send — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-52938 | linux-libc-dev | 7.0.0-28.28 | kernel: bpf: Fix NULL pointer dereference in bpf_sk_storage_clone and diag paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-52939 | linux-libc-dev | 7.0.0-28.28 | kernel: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-52940 | linux-libc-dev | 7.0.0-28.28 | kernel: tun: zero the whole vnet header in tun_put_user() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-52942 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: nf_log: validate MAC header was set before dumping it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-52947 | linux-libc-dev | 7.0.0-28.28 | kernel: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-52948 | linux-libc-dev | 7.0.0-28.28 | kernel: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53131 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: require Ethernet MAC header before using eth_hdr() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53132 | linux-libc-dev | 7.0.0-28.28 | kernel: vsock/virtio: fix potential unbounded skb queue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53133 | linux-libc-dev | 7.0.0-28.28 | kernel: RDMA/umem: Fix truncation for block sizes >= 4G — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53134 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: nft_fib: fix stale stack leak via the OIFNAME register — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53136 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/amd/display: Clamp VBIOS HDMI retimer register count to array size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53137 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53138 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/amd/display: Bound VBIOS record-chain walk loops — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53242 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53243 | linux-libc-dev | 7.0.0-28.28 | kernel: rseq: Fix using an uninitialized stack variable in rseq_exit_user_update() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53244 | linux-libc-dev | 7.0.0-28.28 | kernel: VFS: fix possible failure to unlock in nfsd4_create_file() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53245 | linux-libc-dev | 7.0.0-28.28 | kernel: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53246 | linux-libc-dev | 7.0.0-28.28 | kernel: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53251 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53252 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: fix memory leak in error path of hci_alloc_dev() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53257 | linux-libc-dev | 7.0.0-28.28 | kernel: wifi: cfg80211: enforce HE/EHT cap/oper consistency — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53263 | linux-libc-dev | 7.0.0-28.28 | kernel: 6lowpan: fix off-by-one in multicast context address compression — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53267 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: nft_ct: bail out on template ct in get eval — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53268 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: conntrack_irc: fix possible out-of-bounds read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53271 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53274 | linux-libc-dev | 7.0.0-28.28 | kernel: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53325 | linux-libc-dev | 7.0.0-28.28 | kernel: agp/amd64: Fix broken error propagation in agp_amd64_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53326 | linux-libc-dev | 7.0.0-28.28 | kernel: debugobjects: Don't call fill_pool() in early boot hardirq context — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53327 | linux-libc-dev | 7.0.0-28.28 | kernel: debugobjects: Do not fill_pool() if pi_blocked_on — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53328 | linux-libc-dev | 7.0.0-28.28 | kernel: sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53329 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/amd/display: Use krealloc_array() in dal_vector_reserve() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53330 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53190 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53191 | linux-libc-dev | 7.0.0-28.28 | kernel: io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53194 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: serial: kl5kusb105: fix bulk-out buffer overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53197 | linux-libc-dev | 7.0.0-28.28 | kernel: xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53199 | linux-libc-dev | 7.0.0-28.28 | kernel: hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53201 | linux-libc-dev | 7.0.0-28.28 | kernel: Revert "drm/xe: Skip exec queue schedule toggle if queue is idle during suspend" — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53208 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53210 | linux-libc-dev | 7.0.0-28.28 | kernel: tee: shm: fix shm leak in register_shm_helper() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53211 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53214 | linux-libc-dev | 7.0.0-28.28 | kernel: ipv6: Fix a potential NPD in cleanup_prefix_route() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53218 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53219 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: x_tables: avoid leaking percpu counter pointers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53220 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: revalidate bridge ports — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53221 | linux-libc-dev | 7.0.0-28.28 | kernel: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53223 | linux-libc-dev | 7.0.0-28.28 | kernel: net: guard timestamp cmsgs to real error queue skbs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53227 | linux-libc-dev | 7.0.0-28.28 | kernel: net: openvswitch: fix possible kfree_skb of ERR_PTR — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53228 | linux-libc-dev | 7.0.0-28.28 | kernel: ipv6: sit: reload inner IPv6 header after GSO offloads — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53231 | linux-libc-dev | 7.0.0-28.28 | kernel: net: phy: don't try to setup PHY-driven SFP cages when using genphy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53241 | linux-libc-dev | 7.0.0-28.28 | kernel: ALSA: seq: dummy: fix UMP event stack overread — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-6238 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Application crash or uninitialized memory read via crafted DNS response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-4046 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Denial of Service via iconv() function with specific character sets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5435 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Out-of-bounds write via TSIG record processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5450 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5928 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6238 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Application crash or uninitialized memory read via crafted DNS response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-4046 | libc6-dev | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Denial of Service via iconv() function with specific character sets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5435 | libc6-dev | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Out-of-bounds write via TSIG record processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5450 | libc6-dev | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5928 | libc6-dev | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6238 | libc6-dev | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Application crash or uninitialized memory read via crafted DNS response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2025-66382 | libexpat1 | 2.7.4-1 | libexpat: libexpat: Denial of service via crafted file processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | libmount1 | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | libmount1 | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-13757 | libp11-kit0 | 0.26.2-2 | p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2025-10990 | libruby3.3 | 3.3.8-2ubuntu3.1 | rexml: REXML: Denial of Service via inefficient regex parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | libsmartcols1 | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | libsmartcols1 | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | libuuid1 | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | bsdutils | 1:2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2024-52005 | git | 1:2.53.0-1ubuntu1 | git: The sideband payload is passed unfiltered to the terminal in git — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2024-52005 | git-man | 1:2.53.0-1ubuntu1 | git: The sideband payload is passed unfiltered to the terminal in git — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | libblkid1 | 2.41.3-3ubuntu2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | libblkid1 | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-4046 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Denial of Service via iconv() function with specific character sets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5435 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Out-of-bounds write via TSIG record processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5450 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5928 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6238 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Application crash or uninitialized memory read via crafted DNS response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-4046 | libc-dev-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Denial of Service via iconv() function with specific character sets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5435 | libc-dev-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Out-of-bounds write via TSIG record processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5450 | libc-dev-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5928 | libc-dev-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6238 | libc-dev-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Application crash or uninitialized memory read via crafted DNS response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-4046 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Denial of Service via iconv() function with specific character sets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5435 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Out-of-bounds write via TSIG record processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5450 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5928 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2022-50090 | linux-libc-dev | 7.0.0-28.28 | kernel: btrfs: replace BTRFS_MAX_EXTENT_SIZE with fs_info->max_extent_size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-50230 | linux-libc-dev | 7.0.0-28.28 | kernel: arm64: set UXN on swapper page tables — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-50232 | linux-libc-dev | 7.0.0-28.28 | kernel: arm64: set UXN on swapper page tables — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-50240 | linux-libc-dev | 7.0.0-28.28 | kernel: binder: fix UAF of alloc->vma in race with munmap() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-50332 | linux-libc-dev | 7.0.0-28.28 | kernel: Linux kernel: Denial of Service due to improper PCI device handling in aperture driver — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-50380 | linux-libc-dev | 7.0.0-28.28 | kernel: mm: /proc/pid/smaps_rollup: fix no vma's null-deref — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-50551 | linux-libc-dev | 7.0.0-28.28 | kernel: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-0030 | linux-libc-dev | 7.0.0-28.28 | kernel: Use after Free in nvkm_vmm_pfn_map — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-0160 | linux-libc-dev | 7.0.0-28.28 | kernel: possibility of deadlock in libbpf function sock_hash_delete_elem — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-1193 | linux-libc-dev | 7.0.0-28.28 | kernel: use-after-free in setup_async_work() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-26242 | linux-libc-dev | 7.0.0-28.28 | afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-31082 | linux-libc-dev | 7.0.0-28.28 | kernel: sleeping function called from an invalid context in gsmld_write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-52879 | linux-libc-dev | 7.0.0-28.28 | kernel: tracing: Have trace_event_file have ref counters — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-53642 | linux-libc-dev | 7.0.0-28.28 | kernel: x86: fix clear_user_rep_good() exception handling annotation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-54105 | linux-libc-dev | 7.0.0-28.28 | kernel: can: isotp: check CAN address family in isotp_bind() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-54187 | linux-libc-dev | 7.0.0-28.28 | kernel: f2fs: fix potential corruption when moving a directory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-54190 | linux-libc-dev | 7.0.0-28.28 | kernel: Kernel: Denial of Service via reference count leak in LED core — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2024-35895 | linux-libc-dev | 7.0.0-28.28 | kernel: bpf, sockmap: Prevent lock inversion deadlock in map delete elem — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2024-35995 | linux-libc-dev | 7.0.0-28.28 | kernel: ACPI: CPPC: Use access_width over bit_width for system memory accesses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | libuuid1 | 2.41.3-3ubuntu2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2013-7445 | linux-libc-dev | 7.0.0-28.28 | kernel: memory exhaustion via crafted Graphics Execution Manager (GEM) objects — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2015-7837 | linux-libc-dev | 7.0.0-28.28 | kernel: securelevel disabled after kexec — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2015-8553 | linux-libc-dev | 7.0.0-28.28 | xen: non-maskable interrupts triggerable by guests (xsa120) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2016-8660 | linux-libc-dev | 7.0.0-28.28 | kernel: xfs: local DoS due to a page lock order bug in the XFS seek hole/data implementation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2018-17977 | linux-libc-dev | 7.0.0-28.28 | kernel: Mishandled interactions among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets resulting in a denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2019-15794 | linux-libc-dev | 7.0.0-28.28 | kernel: Overlayfs in the Linux kernel and shiftfs not restoring original value on error leading to a refcount underflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2021-3714 | linux-libc-dev | 7.0.0-28.28 | kernel: Remote Page Deduplication Attacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2021-3864 | linux-libc-dev | 7.0.0-28.28 | kernel: descendant's dumpable setting with certain SUID binaries — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-0400 | linux-libc-dev | 7.0.0-28.28 | kernel: Out of bounds read in the smc protocol stack — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-0480 | linux-libc-dev | 7.0.0-28.28 | kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-1247 | linux-libc-dev | 7.0.0-28.28 | kernel: A race condition bug in rose_connect() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-25836 | linux-libc-dev | 7.0.0-28.28 | ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-2961 | linux-libc-dev | 7.0.0-28.28 | kernel: race condition in rose_bind() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-3238 | linux-libc-dev | 7.0.0-28.28 | kernel: ntfs3 local privledge escalation if NTFS character set and remount and umount called simultaneously — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-4543 | linux-libc-dev | 7.0.0-28.28 | kernel: KASLR Prefetch Bypass Breaks KPTI — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-48846 | linux-libc-dev | 7.0.0-28.28 | kernel: block: release rq qos structures for queue without disk — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-48929 | linux-libc-dev | 7.0.0-28.28 | kernel: bpf: Fix crash due to out of bounds access into reg2btf_ids. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-49940 | linux-libc-dev | 7.0.0-28.28 | kernel: tty: n_gsm: add sanity check for gsm->receive in gsm_receive_buf() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63835 | linux-libc-dev | 7.0.0-28.28 | kernel: batman-adv: v: prevent OGM aggregation on disabled hardif — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63836 | linux-libc-dev | 7.0.0-28.28 | kernel: batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63867 | linux-libc-dev | 7.0.0-28.28 | kernel: mptcp: close TOCTOU race while computing rcv_wnd — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63868 | linux-libc-dev | 7.0.0-28.28 | kernel: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63869 | linux-libc-dev | 7.0.0-28.28 | kernel: wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63870 | linux-libc-dev | 7.0.0-28.28 | kernel: ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63871 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63872 | linux-libc-dev | 7.0.0-28.28 | kernel: esp: fix page frag reference leak on skb_to_sgvec failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63873 | linux-libc-dev | 7.0.0-28.28 | kernel: accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63874 | linux-libc-dev | 7.0.0-28.28 | kernel: net: mctp: usb: fix race between urb completion and rx_retry cancellation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64187 | linux-libc-dev | 7.0.0-28.28 | kernel: xfs: fail recovery on a committed log item with no regions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64188 | linux-libc-dev | 7.0.0-28.28 | kernel: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64189 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: ipset: fix race between dump and ip_set_list resize — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64190 | linux-libc-dev | 7.0.0-28.28 | kernel: net: team: fix NULL pointer dereference in team_xmit during mode change — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64191 | linux-libc-dev | 7.0.0-28.28 | kernel: i2c: stub: Reject I2C block transfers with invalid length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64192 | linux-libc-dev | 7.0.0-28.28 | kernel: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64205 | linux-libc-dev | 7.0.0-28.28 | kernel: i2c: i801: fix hardware state machine corruption in error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64206 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64207 | linux-libc-dev | 7.0.0-28.28 | kernel: net/sched: dualpi2: fix GSO backlog accounting — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63816 | linux-libc-dev | 7.0.0-28.28 | kernel: f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63817 | linux-libc-dev | 7.0.0-28.28 | kernel: f2fs: validate compress cache inode only when enabled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63818 | linux-libc-dev | 7.0.0-28.28 | kernel: f2fs: validate orphan inode entry count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63819 | linux-libc-dev | 7.0.0-28.28 | kernel: f2fs: fix to do sanity check on f2fs_get_node_folio_ra() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63820 | linux-libc-dev | 7.0.0-28.28 | kernel: f2fs: fix missing read bio submission on large folio error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63821 | linux-libc-dev | 7.0.0-28.28 | kernel: wifi: rtw88: usb: fix memory leaks on USB write failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63822 | linux-libc-dev | 7.0.0-28.28 | kernel: wifi: ath11k: fix warning when unbinding — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63823 | linux-libc-dev | 7.0.0-28.28 | kernel: keys: Pin request_key_auth payload in instantiate paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63824 | linux-libc-dev | 7.0.0-28.28 | kernel: KEYS: fix overflow in keyctl_pkey_params_get_2() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63825 | linux-libc-dev | 7.0.0-28.28 | kernel: gcov: use atomic counter updates to fix concurrent access crashes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63826 | linux-libc-dev | 7.0.0-28.28 | kernel: fbdev: fix use-after-free in store_modes() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63827 | linux-libc-dev | 7.0.0-28.28 | kernel: apparmor: fix use-after-free in rawdata dedup loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63828 | linux-libc-dev | 7.0.0-28.28 | kernel: apparmor: mediate the implicit connect of TCP fast open sendmsg — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63829 | linux-libc-dev | 7.0.0-28.28 | kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63830 | linux-libc-dev | 7.0.0-28.28 | kernel: net: skmsg: preserve sg.copy across SG transforms — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63831 | linux-libc-dev | 7.0.0-28.28 | kernel: mac802154: llsec: add skb_cow_data() before in-place crypto — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63832 | linux-libc-dev | 7.0.0-28.28 | kernel: wifi: mt76: add wcid publish check in mt76_sta_add — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63833 | linux-libc-dev | 7.0.0-28.28 | kernel: ntfs3: reject direct userspace writes to reserved $LX* xattrs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63834 | linux-libc-dev | 7.0.0-28.28 | kernel: batman-adv: tp_meter: restrict number of unacked list entries — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64271 | linux-libc-dev | 7.0.0-28.28 | kernel: Input: touchwin - reset the packet index on every complete packet — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64270 | linux-libc-dev | 7.0.0-28.28 | kernel: Input: mms114 - reject an oversized device packet size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64269 | linux-libc-dev | 7.0.0-28.28 | kernel: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64268 | linux-libc-dev | 7.0.0-28.28 | kernel: RDMA/siw: bound Read Response placement to the RREAD length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64267 | linux-libc-dev | 7.0.0-28.28 | kernel: fuse: avoid 32-bit prune notification count wrap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64266 | linux-libc-dev | 7.0.0-28.28 | kernel: fuse: re-lock request before returning from fuse_ref_folio() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64265 | linux-libc-dev | 7.0.0-28.28 | kernel: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64264 | linux-libc-dev | 7.0.0-28.28 | kernel: fuse-uring: fix EFAULT clobber in fuse_uring_commit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64263 | linux-libc-dev | 7.0.0-28.28 | kernel: fuse-uring: fix moving cancelled entry to ent_in_userspace list — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64262 | linux-libc-dev | 7.0.0-28.28 | kernel: fuse-uring: end fuse_req on io-uring cancel task work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64261 | linux-libc-dev | 7.0.0-28.28 | kernel: fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64260 | linux-libc-dev | 7.0.0-28.28 | kernel: fuse-uring: Avoid queue->stopped races and set/read that value under lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64259 | linux-libc-dev | 7.0.0-28.28 | kernel: fuse-uring: make a fuse_req on SQE commit only findable after memcpy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64258 | linux-libc-dev | 7.0.0-28.28 | kernel: fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64256 | linux-libc-dev | 7.0.0-28.28 | kernel: xfs: don't wrap around quota ids in dqiterate — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64255 | linux-libc-dev | 7.0.0-28.28 | kernel: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64254 | linux-libc-dev | 7.0.0-28.28 | kernel: NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64253 | linux-libc-dev | 7.0.0-28.28 | kernel: kernel/fork: clear PF_BLOCK_TS in copy_process() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64251 | linux-libc-dev | 7.0.0-28.28 | kernel: pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64244 | linux-libc-dev | 7.0.0-28.28 | kernel: drivers/base/memory: set mem->altmap after successful device registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64245 | linux-libc-dev | 7.0.0-28.28 | kernel: fbdev: modedb: fix a possible UAF in fb_find_mode() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64286 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64285 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: SEV: Pin source page for write when adding CPUID data for SNP guest — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64246 | linux-libc-dev | 7.0.0-28.28 | kernel: power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64247 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: x86: hyper-v: Bound the bank index when querying sparse banks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64249 | linux-libc-dev | 7.0.0-28.28 | kernel: fpga: region: fix use-after-free in child_regions_with_firmware() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64284 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64283 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: guest_memfd: Treat memslot binding offset+size as unsigned values — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64282 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64280 | linux-libc-dev | 7.0.0-28.28 | kernel: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64279 | linux-libc-dev | 7.0.0-28.28 | kernel: i2c: core: fix adapter deregistration race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64278 | linux-libc-dev | 7.0.0-28.28 | kernel: i2c: imx-lpi2c: mark I2C adapter when hardware is powered down — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64277 | linux-libc-dev | 7.0.0-28.28 | kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64276 | linux-libc-dev | 7.0.0-28.28 | kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64275 | linux-libc-dev | 7.0.0-28.28 | kernel: Input: elan_i2c - prevent division by zero and arithmetic underflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64274 | linux-libc-dev | 7.0.0-28.28 | kernel: Input: goodix - clamp the device-reported contact count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64273 | linux-libc-dev | 7.0.0-28.28 | kernel: Input: iforce - bound the device-reported force-feedback effect index — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64272 | linux-libc-dev | 7.0.0-28.28 | kernel: Input: mms114 - fix touch indexing for MMS134S and MMS136 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53350 | linux-libc-dev | 7.0.0-28.28 | kernel: ASoC: wm_adsp: Fix NULL dereference when removing firmware controls — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53351 | linux-libc-dev | 7.0.0-28.28 | kernel: riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_CFI — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53352 | linux-libc-dev | 7.0.0-28.28 | kernel: signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53353 | linux-libc-dev | 7.0.0-28.28 | kernel: hsr: Remove WARN_ONCE() in hsr_addr_is_self() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53354 | linux-libc-dev | 7.0.0-28.28 | kernel: arm64: errata: Mitigate TLBI errata on various Arm CPUs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53355 | linux-libc-dev | 7.0.0-28.28 | kernel: net: rds: clear i_sends on setup unwind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53356 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/i915/gem: Fix phys BO pread/pwrite with offset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53361 | linux-libc-dev | 7.0.0-28.28 | kernel: af_unix: Set gc_in_progress to true in unix_gc() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53362 | linux-libc-dev | 7.0.0-28.28 | kernel: kernel: ipv6 frag escape — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53363 | linux-libc-dev | 7.0.0-28.28 | kernel: xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53366 | linux-libc-dev | 7.0.0-28.28 | kernel: ipv4: account for fraggap on the paged allocation path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53381 | linux-libc-dev | 7.0.0-28.28 | kernel: virtiofs: fix UAF on submount umount — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53382 | linux-libc-dev | 7.0.0-28.28 | kernel: media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53383 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: reject non-VALID session in compound request branch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53384 | linux-libc-dev | 7.0.0-28.28 | kernel: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53385 | linux-libc-dev | 7.0.0-28.28 | kernel: vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53386 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: adc: ti-ads1298: add bounds check to pga_settings index — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53387 | linux-libc-dev | 7.0.0-28.28 | kernel: iio: light: veml6075: add bounds check to veml6075_it_ms index — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53388 | linux-libc-dev | 7.0.0-28.28 | kernel: fuse: re-lock request before replacing page cache folio — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53331 | linux-libc-dev | 7.0.0-28.28 | kernel: slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53332 | linux-libc-dev | 7.0.0-28.28 | kernel: slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53333 | linux-libc-dev | 7.0.0-28.28 | kernel: mm/mincore: handle non-swap entries before !CONFIG_SWAP guard — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53334 | linux-libc-dev | 7.0.0-28.28 | kernel: mm/damon/reclaim: handle ctx allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53335 | linux-libc-dev | 7.0.0-28.28 | kernel: mm/damon/lru_sort: handle ctx allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53336 | linux-libc-dev | 7.0.0-28.28 | kernel: nvmem: layouts: onie-tlv: fix hang on unknown types — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53337 | linux-libc-dev | 7.0.0-28.28 | kernel: net: bonding: fix NULL pointer dereference in bond_do_ioctl() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53338 | linux-libc-dev | 7.0.0-28.28 | kernel: net: airoha: Add NULL check for of_reserved_mem_lookup() in airoha_qdma_init_hfwd_queues() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53339 | linux-libc-dev | 7.0.0-28.28 | kernel: i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53340 | linux-libc-dev | 7.0.0-28.28 | kernel: i2c: imx: fix clock and pinctrl state inconsistency in runtime PM — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53341 | linux-libc-dev | 7.0.0-28.28 | kernel: fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53342 | linux-libc-dev | 7.0.0-28.28 | kernel: arm64: mm: call pagetable dtor when freeing hot-removed page tables — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53343 | linux-libc-dev | 7.0.0-28.28 | kernel: ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53344 | linux-libc-dev | 7.0.0-28.28 | kernel: pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53345 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53346 | linux-libc-dev | 7.0.0-28.28 | kernel: rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53347 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/virtio: Fix driver removal with disabled KMS — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53348 | linux-libc-dev | 7.0.0-28.28 | kernel: ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53349 | linux-libc-dev | 7.0.0-28.28 | kernel: netfilter: nf_conntrack: destroy stale expectfn expectations on unregister — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63794 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63795 | linux-libc-dev | 7.0.0-28.28 | kernel: 9p: avoid putting oldfid in p9_client_walk() error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63796 | linux-libc-dev | 7.0.0-28.28 | kernel: ocfs2: reject oversized group bitmap descriptors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63797 | linux-libc-dev | 7.0.0-28.28 | kernel: rpmsg: char: Fix use-after-free on probe error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63798 | linux-libc-dev | 7.0.0-28.28 | kernel: irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63799 | linux-libc-dev | 7.0.0-28.28 | kernel: sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63800 | linux-libc-dev | 7.0.0-28.28 | kernel: pNFS: Fix use-after-free in pnfs_update_layout() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63801 | linux-libc-dev | 7.0.0-28.28 | kernel: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63802 | linux-libc-dev | 7.0.0-28.28 | kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63803 | linux-libc-dev | 7.0.0-28.28 | kernel: hdlc_ppp: sync per-proto timers before freeing hdlc state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63804 | linux-libc-dev | 7.0.0-28.28 | kernel: gfs2: fix use-after-free in gfs2_qd_dealloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63805 | linux-libc-dev | 7.0.0-28.28 | kernel: crypto: nx - fix nx_crypto_ctx_exit argument — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63806 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63807 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63808 | linux-libc-dev | 7.0.0-28.28 | kernel: exfat: fix potential use-after-free in exfat_find_dir_entry() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63809 | linux-libc-dev | 7.0.0-28.28 | kernel: bpf: use kvfree() for replaced sysctl write buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63810 | linux-libc-dev | 7.0.0-28.28 | kernel: block: Avoid mounting the bdev pseudo-filesystem in userspace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63811 | linux-libc-dev | 7.0.0-28.28 | kernel: f2fs: read COW data with the original inode during atomic write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63812 | linux-libc-dev | 7.0.0-28.28 | kernel: f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63813 | linux-libc-dev | 7.0.0-28.28 | kernel: Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block" — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63814 | linux-libc-dev | 7.0.0-28.28 | kernel: f2fs: validate ACL entry sizes in f2fs_acl_from_disk() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63815 | linux-libc-dev | 7.0.0-28.28 | kernel: f2fs: bound i_inline_xattr_size for non-inline-xattr inodes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53389 | linux-libc-dev | 7.0.0-28.28 | kernel: net/tcp-ao: fix use-after-free of key in del_async path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53390 | linux-libc-dev | 7.0.0-28.28 | kernel: ksmbd: fix out-of-bounds read in smb_check_perm_dacl() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53391 | linux-libc-dev | 7.0.0-28.28 | kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53392 | linux-libc-dev | 7.0.0-28.28 | kernel: NFSv4/flexfiles: reject zero filehandle version count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53393 | linux-libc-dev | 7.0.0-28.28 | kernel: nfsd: reset write verifier on deferred writeback errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53394 | linux-libc-dev | 7.0.0-28.28 | kernel: nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53395 | linux-libc-dev | 7.0.0-28.28 | kernel: nfsd: fix dead ACL conflict guard in nfsd4_create — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53396 | linux-libc-dev | 7.0.0-28.28 | kernel: nfsd: fix posix_acl leak and ignored error in nfsd4_create_file — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53397 | linux-libc-dev | 7.0.0-28.28 | kernel: nfsd: fix posix_acl leak on SETACL decode failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53398 | linux-libc-dev | 7.0.0-28.28 | kernel: NFSD: Fix SECINFO_NO_NAME decode error cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53399 | linux-libc-dev | 7.0.0-28.28 | kernel: nfsd: release layout stid on setlease failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53400 | linux-libc-dev | 7.0.0-28.28 | kernel: i2c: core: fix adapter registration race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53401 | linux-libc-dev | 7.0.0-28.28 | kernel: fbdev: omap2: fix use-after-free in omapfb_mmap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-63793 | linux-libc-dev | 7.0.0-28.28 | kernel: ntfs: serialize volume label accesses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53402 | linux-libc-dev | 7.0.0-28.28 | kernel: fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53403 | linux-libc-dev | 7.0.0-28.28 | kernel: fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2024-2236 | libgcrypt20 | 1.12.0-2ubuntu1 | libgcrypt: vulnerable to Marvin Attack — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2024-56433 | login.defs | 1:4.17.4-2ubuntu3 | shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | libgprofng0 | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53273 | linux-libc-dev | 7.0.0-28.28 | kernel: tee: optee: prevent use-after-free when the client exits before the supplicant — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53272 | linux-libc-dev | 7.0.0-28.28 | kernel: erofs: fix use-after-free on sbi->sync_decompress — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53265 | linux-libc-dev | 7.0.0-28.28 | kernel: dm cache policy smq: check allocation under invalidate lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53261 | linux-libc-dev | 7.0.0-28.28 | kernel: devlink: Release nested relation on devlink free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53258 | linux-libc-dev | 7.0.0-28.28 | kernel: wifi: fix leak if split 6 GHz scanning fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53255 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: MGMT: validate advertising TLV before type checks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53253 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: bnep: reject short frames before parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53249 | linux-libc-dev | 7.0.0-28.28 | kernel: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53248 | linux-libc-dev | 7.0.0-28.28 | kernel: net: airoha: Fix use-after-free in metadata dst teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53247 | linux-libc-dev | 7.0.0-28.28 | kernel: net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-40228 | libudev1 | 259.5-0ubuntu3 | systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53237 | linux-libc-dev | 7.0.0-28.28 | kernel: gpio: mvebu: fix NULL pointer dereference in suspend/resume — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53238 | linux-libc-dev | 7.0.0-28.28 | kernel: netlabel: validate unlabeled address and mask attribute lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-27171 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-27171 | zlib1g-dev | 1:1.3.dfsg+really1.3.1-1ubuntu3 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | libbinutils | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2025-61594 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | uri: URI module: Credential exposure via URI + operator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2025-58767 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | rexml: REXML denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | binutils-common | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2025-61594 | ruby3.3 | 3.3.8-2ubuntu3.1 | uri: URI module: Credential exposure via URI + operator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2025-58767 | ruby3.3 | 3.3.8-2ubuntu3.1 | rexml: REXML denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | libctf-nobfd0 | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2021-45261 | patch | 2.8-2build1 | patch: Invalid Pointer via another_hunk function — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2019-20633 | patch | 2.8-2build1 | patch: double free in another_hunk function in pch.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2018-6952 | patch | 2.8-2build1 | patch: Double free of memory in pch.c:another_hunk() causes a crash — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2024-56433 | passwd | 1:4.17.4-2ubuntu3 | shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-55654 | openssh-client | 1:10.2p1-2ubuntu3.5 | openssh: Heap out-of-bounds read in Red Hat Enterprise Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | libctf0 | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | binutils | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2019-20426 | linux-libc-dev | 7.0.0-28.28 | ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2020-14304 | linux-libc-dev | 7.0.0-28.28 | kernel: ethtool when reading eeprom of device could lead to memory leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2020-35501 | linux-libc-dev | 7.0.0-28.28 | kernel: audit not logging access to syscall open_by_handle_at for users with CAP_DAC_READ_SEARCH capability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2021-26934 | linux-libc-dev | 7.0.0-28.28 | An issue was discovered in the Linux kernel 4.18 through 5.10.16, as u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2022-41848 | linux-libc-dev | 7.0.0-28.28 | kernel: Race condition between mgslpc_ioctl and mgslpc_detach — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2022-44034 | linux-libc-dev | 7.0.0-28.28 | Kernel: A use-after-free due to race between scr24x_open() and scr24x_remove() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2022-45885 | linux-libc-dev | 7.0.0-28.28 | kernel: use-after-free due to race condition occurring in dvb_frontend.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2023-20585 | linux-libc-dev | 7.0.0-28.28 | kernel-core: hw: amd: AMD-SN-3016: IOMMU Write Buffer Vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2023-33053 | linux-libc-dev | 7.0.0-28.28 | ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2023-4010 | linux-libc-dev | 7.0.0-28.28 | kernel: usb: hcd: malformed USB descriptor leads to infinite loop in usb_giveback_urb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2023-6238 | linux-libc-dev | 7.0.0-28.28 | kernel: nvme: memory corruption via unprivileged user passthrough — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2024-0564 | linux-libc-dev | 7.0.0-28.28 | kernel: max page sharing of Kernel Samepage Merging (KSM) may cause memory deduplication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2025-22077 | linux-libc-dev | 7.0.0-28.28 | kernel: smb: client: Fix netns refcount imbalance causing leaks and use-after-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53135 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53142 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/xe/display: fix oops in suspend/shutdown without display — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53146 | linux-libc-dev | 7.0.0-28.28 | kernel: thunderbolt: Limit XDomain response copy to actual frame size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-40228 | libsystemd0 | 259.5-0ubuntu3 | systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | libsframe3 | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2025-61594 | libruby3.3 | 3.3.8-2ubuntu3.1 | uri: URI module: Credential exposure via URI + operator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2025-58767 | libruby3.3 | 3.3.8-2ubuntu3.1 | rexml: REXML denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-0537 | linux-libc-dev | 7.0.0-28.28 | ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13165 | linux-libc-dev | 7.0.0-28.28 | ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13693 | linux-libc-dev | 7.0.0-28.28 | kernel: ACPI operand cache leak in dsutils.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2018-1121 | linux-libc-dev | 7.0.0-28.28 | procps: process hiding through race condition enumerating /proc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2018-12928 | linux-libc-dev | 7.0.0-28.28 | kernel: NULL pointer dereference in hfs_ext_read_extent in hfs.ko — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2018-12929 | linux-libc-dev | 7.0.0-28.28 | kernel: use-after-free in ntfs_read_locked_inode in the ntfs.ko — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2018-12930 | linux-libc-dev | 7.0.0-28.28 | kernel: stack-based out-of-bounds write in ntfs_end_buffer_async_read in the ntfs.ko — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2018-12931 | linux-libc-dev | 7.0.0-28.28 | kernel: stack-based out-of-bounds write in ntfs_attr_find in the ntfs.ko — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2019-14899 | linux-libc-dev | 7.0.0-28.28 | VPN: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2019-15213 | linux-libc-dev | 7.0.0-28.28 | kernel: use-after-free caused by malicious USB device in drivers/media/usb/dvb-usb/dvb-usb-init.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2019-19378 | linux-libc-dev | 7.0.0-28.28 | kernel: out-of-bounds write in index_rbio_pages in fs/btrfs/raid56.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2019-19814 | linux-libc-dev | 7.0.0-28.28 | kernel: out-of-bounds write in __remove_dirty_segment in fs/f2fs/segment.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53147 | linux-libc-dev | 7.0.0-28.28 | kernel: thunderbolt: Validate XDomain request packet size before type cast — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53205 | linux-libc-dev | 7.0.0-28.28 | kernel: accel/ivpu: Add bounds checks for firmware log indices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53206 | linux-libc-dev | 7.0.0-28.28 | kernel: accel/ivpu: Add bounds check for firmware runtime memory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53207 | linux-libc-dev | 7.0.0-28.28 | kernel: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53209 | linux-libc-dev | 7.0.0-28.28 | kernel: Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53213 | linux-libc-dev | 7.0.0-28.28 | kernel: drm/vc4: fix krealloc() memory leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53216 | linux-libc-dev | 7.0.0-28.28 | kernel: net: mvpp2: limit XDP frame size to the RX buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53217 | linux-libc-dev | 7.0.0-28.28 | kernel: net: mvpp2: sync RX data at the hardware packet offset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53222 | linux-libc-dev | 7.0.0-28.28 | kernel: ptp: ocp: fix resource freeing order — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53225 | linux-libc-dev | 7.0.0-28.28 | kernel: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53226 | linux-libc-dev | 7.0.0-28.28 | kernel: gpio: rockchip: fix generic IRQ chip leak on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53229 | linux-libc-dev | 7.0.0-28.28 | kernel: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53230 | linux-libc-dev | 7.0.0-28.28 | kernel: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53232 | linux-libc-dev | 7.0.0-28.28 | kernel: net: phy: clean the sfp upstream if phy probing fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53233 | linux-libc-dev | 7.0.0-28.28 | kernel: netdev: fix double-free in netdev_nl_bind_rx_doit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53234 | linux-libc-dev | 7.0.0-28.28 | kernel: net: ibm: emac: Fix use-after-free during device removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53236 | linux-libc-dev | 7.0.0-28.28 | kernel: tcp: restrict SO_ATTACH_FILTER to priv users — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53152 | linux-libc-dev | 7.0.0-28.28 | kernel: mmc: dw_mmc-rockchip: Add missing private data for very old controllers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53154 | linux-libc-dev | 7.0.0-28.28 | kernel: mm/hugetlb: restore reservation on error in hugetlb folio copy paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53156 | linux-libc-dev | 7.0.0-28.28 | kernel: nvmem: core: fix use-after-free bugs in error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53157 | linux-libc-dev | 7.0.0-28.28 | kernel: net: phonet: free phonet_device after RCU grace period — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53158 | linux-libc-dev | 7.0.0-28.28 | kernel: misc: fastrpc: Fix NULL pointer dereference in rpmsg callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53160 | linux-libc-dev | 7.0.0-28.28 | kernel: misc: fastrpc: fix use-after-free race in fastrpc_map_create — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53161 | linux-libc-dev | 7.0.0-28.28 | kernel: misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53162 | linux-libc-dev | 7.0.0-28.28 | kernel: memcg: use round-robin victim selection in refill_stock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53177 | linux-libc-dev | 7.0.0-28.28 | kernel: bnxt_en: Fix NULL pointer dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53188 | linux-libc-dev | 7.0.0-28.28 | kernel: RDMA/core: Validate the passed in fops for ib_get_ucaps() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53189 | linux-libc-dev | 7.0.0-28.28 | kernel: mm/huge_memory: update file PMD counter before folio_put() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53195 | linux-libc-dev | 7.0.0-28.28 | kernel: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53200 | linux-libc-dev | 7.0.0-28.28 | kernel: KVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53202 | linux-libc-dev | 7.0.0-28.28 | kernel: accel/ivpu: Fix signed integer truncation in IPC receive — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53203 | linux-libc-dev | 7.0.0-28.28 | kernel: accel/ivpu: Add buffer overflow check in MS get_info_ioctl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-53204 | linux-libc-dev | 7.0.0-28.28 | kernel: firmware: stratix10-rsu: Fix NULL deref on rsu_send_msg() timeout in probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| UNKNOWN | CVE-2026-46600 | golang.org/x/net | v0.40.0 | 0.56.0 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ... — usr/bin/pebble |
| UNKNOWN | CVE-2026-39824 | golang.org/x/sys | v0.33.0 | 0.44.0 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows — usr/bin/pebble |
Grype
HIGH 3
MEDIUM 315
LOW 103
UNKNOWN 6
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GHSA-jr6h-r7vg-f9mc | ini4j | 0.5.4 | org.ini4j allows attackers to cause a Denial of Service (DoS) — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar | |
| HIGH | GHSA-q339-8rmv-2mhv | erb | 4.0.3 | 4.0.3.1 | ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/lib/ruby/gems/3.3.0/specifications/default/erb-4.0.3.gemspec |
| HIGH | GO-2026-5026 | golang.org/x/net | v0.40.0 | 0.55.0 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/pebble |
| MEDIUM | CVE-2026-27456 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35348 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56409 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56391 | gnu-coreutils | 9.7-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56391 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56131 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13757 | libp11-kit0 | 0.26.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35368 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56412 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56411 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56410 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | GHSA-46q3-7gv7-qmgg | net-imap | 0.4.19 | 0.5.15 | Net::IMAP: Command Injection via ID command argument — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec |
| MEDIUM | CVE-2026-6845 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35352 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56392 | gnu-coreutils | 9.7-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56392 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35373 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35371 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56407 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56405 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56403 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56408 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56404 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35350 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54371 | libattr1 | 1:2.5.2-4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18508 | tar | 1.35+dfsg-4ubuntu0.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47242 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47242 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47242 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35351 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56406 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18220 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18220 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18220 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18220 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18220 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18220 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18220 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18220 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-66382 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57432 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57432 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57432 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57432 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-32777 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54369 | libacl1 | 2.3.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-32776 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35341 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35363 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-32778 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51295 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51294 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51293 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51292 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51291 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51290 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51304 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51303 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51302 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51300 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51298 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51297 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-51296 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56132 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35370 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35367 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35344 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35374 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-16517 | libarchive13t64 | 3.8.5-1ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54370 | libacl1 | 2.3.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-55655 | openssh-client | 1:10.2p1-2ubuntu3.5 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35357 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35364 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35354 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35345 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35377 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35360 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18477 | tar | 1.35+dfsg-4ubuntu0.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35359 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-12087 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-12087 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-12087 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-12087 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4046 | libc6-dev | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-4046 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-4046 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-4046 | libc-dev-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-4046 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | GO-2026-5856 | stdlib | go1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/bin/pebble |
| MEDIUM | CVE-2026-41080 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13221 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13221 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13221 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13221 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-5450 | libc6-dev | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-54696 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47021 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47059 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-66035 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-66035 | libssh2-1-dev | 1.11.1-1ubuntu0.26.04.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57433 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57433 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57433 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57433 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6238 | libc6-dev | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6238 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6238 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6238 | libc-dev-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6238 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5928 | libc6-dev | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5928 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5928 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5928 | libc-dev-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5928 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-66033 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-66033 | libssh2-1-dev | 1.11.1-1ubuntu0.26.04.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47058 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-5450 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5450 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5450 | libc-dev-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5450 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2024-52005 | git-man | 1:2.53.0-1ubuntu1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2024-52005 | git | 1:2.53.0-1ubuntu1 | /var/lib/dpkg/status | |
| MEDIUM | GHSA-j3g3-5qv5-52mj | net-imap | 0.4.19 | 0.4.20 | net-imap rubygem vulnerable to possible DoS by memory exhaustion — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec |
| MEDIUM | GHSA-8p34-64r3-mwg8 | net-imap | 0.4.19 | 0.5.15 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec |
| MEDIUM | CVE-2026-27820 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27820 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27820 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-11856 | libcurl4t64 | 8.18.0-1ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-11856 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-11856 | curl | 8.18.0-1ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | GHSA-g857-hhfv-j68w | zlib | 3.1.1 | 3.1.2 | Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption — /usr/lib/ruby/gems/3.3.0/specifications/default/zlib-3.1.1.gemspec |
| MEDIUM | CVE-2026-42258 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42258 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42258 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | GHSA-75xq-5h9v-w6px | net-imap | 0.4.19 | 0.4.24 | net-imap vulnerable to command Injection via unvalidated Symbol inputs — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec |
| MEDIUM | CVE-2026-41316 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-41316 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-41316 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-45186 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47057 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-10990 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-10990 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-10990 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-46727 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-46727 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-46727 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47240 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47240 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47240 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-5435 | libc6-dev | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3442 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47063 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54876 | openssl-provider-legacy | 3.5.5-1ubuntu3.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54876 | openssl | 3.5.5-1ubuntu3.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54876 | libssl3t64 | 3.5.5-1ubuntu3.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54876 | libssl-dev | 3.5.5-1ubuntu3.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4739 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-46968 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-5435 | libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5435 | libc-gconv-modules-extra | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5435 | libc-dev-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-5435 | libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-47241 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47241 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47241 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47010 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-66034 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-66034 | libssh2-1-dev | 1.11.1-1ubuntu0.26.04.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53910 | diffutils | 1:3.12-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-50219 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-60147 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-46917 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-66032 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-66032 | libssh2-1-dev | 1.11.1-1ubuntu0.26.04.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54696 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54696 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47027 | openjdk-21-jre-headless | 21.0.11+10-1~26.04.2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-5278 | gnu-coreutils | 9.7-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-8932 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-8932 | curl | 8.18.0-1ubuntu2.3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-56289 | patch | 2.8-2build1 | /var/lib/dpkg/status | |
| LOW | CVE-2026-56288 | patch | 2.8-2build1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | GHSA-q2mw-fvj9-vvcw | net-imap | 0.4.19 | 0.4.24 | net-imap has quadratic complexity when reading response literals — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec |
| LOW | CVE-2025-5278 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | /var/lib/dpkg/status | |
| LOW | CVE-2018-10126 | libjpeg-turbo8 | 2.1.5-4ubuntu4 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-58767 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-58767 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-58767 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2026-55654 | openssh-client | 1:10.2p1-2ubuntu3.5 | /var/lib/dpkg/status | |
| LOW | CVE-2026-8932 | libcurl4t64 | 8.18.0-1ubuntu2.3 | /var/lib/dpkg/status | |
| LOW | CVE-2024-2236 | libgcrypt20 | 1.12.0-2ubuntu1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1150 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-43857 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-43857 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-43857 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1150 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1150 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1150 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1150 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1150 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | GHSA-c4fp-cxrr-mj66 | net-imap | 0.4.19 | 0.5.15 | Net::IMAP: Denial of Service via incomplete raw argument validation — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec |
| LOW | CVE-2025-1150 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1150 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-42250 | libbz2-1.0 | 1.0.8-6build2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-61594 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2026-57062 | gpgv | 2.4.8-4ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2025-61594 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-61594 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2024-56433 | passwd | 1:4.17.4-2ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2024-56433 | login.defs | 1:4.17.4-2ubuntu3 | /var/lib/dpkg/status | |
| LOW | GHSA-c2f4-jgmc-q2r5 | rexml | 3.3.9 | 3.4.2 | REXML has DoS condition when parsing malformed XML file — /usr/lib/ruby/gems/3.3.0/specifications/rexml-3.3.9.gemspec |
| LOW | CVE-2026-40228 | libudev1 | 259.5-0ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1151 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1151 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1151 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-27171 | zlib1g-dev | 1:1.3.dfsg+really1.3.1-1ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-27171 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1151 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | GHSA-j4pr-3wm6-xx2r | uri | 0.13.2 | 0.13.3 | URI Credential Leakage Bypass over CVE-2025-27221 — /usr/lib/ruby/gems/3.3.0/specifications/default/uri-0.13.2.gemspec |
| LOW | CVE-2025-1151 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1151 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1151 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1151 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-40228 | libsystemd0 | 259.5-0ubuntu3 | /var/lib/dpkg/status | |
| UNKNOWN | CVE-2026-11979 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | /var/lib/dpkg/status | |
| UNKNOWN | CVE-2021-45261 | patch | 2.8-2build1 | /var/lib/dpkg/status | |
| UNKNOWN | CVE-2025-9301 | cmake | 4.2.3-2ubuntu2 | /var/lib/dpkg/status | |
| UNKNOWN | CVE-2025-9301 | cmake-data | 4.2.3-2ubuntu2 | /var/lib/dpkg/status | |
| UNKNOWN | CVE-2018-6952 | patch | 2.8-2build1 | /var/lib/dpkg/status | |
| UNKNOWN | CVE-2019-20633 | patch | 2.8-2build1 | /var/lib/dpkg/status |
ghcr.io/openvoxproject/openvoxserver:latest-alpine (2026-07-24)
Trivy
HIGH 3
MEDIUM 5
LOW 2
UNKNOWN 1
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-41254 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
| HIGH | CVE-2026-47063 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Enhance Jar handling (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
| HIGH | CVE-2022-41404 | org.ini4j:ini4j | 0.5.4 | org.ini4j: unspecified DoS — Java | |
| MEDIUM | CVE-2026-46917 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Improve DTLS handshaking (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-46968 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-47021 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Enhance XBM image support (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-47027 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Enhance Jar file processing (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-60147 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Improve certification checking (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-47010 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Enhance JPEG handling (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-47059 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | openjdk: OpenJDK: Enhance AWT ImagingLib (Oracle CPU 2026-07) — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
| UNKNOWN | CVE-2026-62574 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
Grype
HIGH 5
MEDIUM 5
LOW 3
NVD/CPE filtered 36
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GHSA-jr6h-r7vg-f9mc | ini4j | 0.5.4 | org.ini4j allows attackers to cause a Denial of Service (DoS) — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar | |
| HIGH | GHSA-q339-8rmv-2mhv | erb | 4.0.4 | 4.0.4.1 | ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/lib/ruby/gems/3.4.0/specifications/default/erb-4.0.4.gemspec |
| HIGH | CVE-2026-41254 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-47063 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-62574 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-60147 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-47021 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-46968 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-46917 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-47027 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-47059 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
| LOW | GHSA-x2f5-4prf-w687 | json | 2.9.1 | 2.19.9 | Ruby json: JSON generator heap buffer overflow when streaming to an IO — /usr/lib/ruby/gems/3.4.0/specifications/default/json-2.9.1.gemspec |
| LOW | CVE-2026-47010 | openjdk21-jre-headless | 21.0.11_p10-r0 | 21.0.12_p8-r0 | /lib/apk/db/installed |
Filtered NVD/CPE matches (36)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-66034 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66034 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59850 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58051 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58051 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59847 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59851 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66032 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66032 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66035 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66035 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58050 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58050 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66033 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66033 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59849 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service. — /lib/apk/db/installed | |
| HIGH | CVE-2026-15370 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59848 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-5745 | libarchive | 3.8.7-r0 | A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59845 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-5704 | tar | 1.35-r5 | A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59842 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils-sha512sum | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils-fmt | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils-env | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59844 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59843 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15661 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15661 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. — /lib/apk/db/installed | |
| MEDIUM | CVE-2013-0256 | ruby-rdoc | 3.4.9-r0 | darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL. — /lib/apk/db/installed | |
| LOW | CVE-2026-59846 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. — /lib/apk/db/installed |
ghcr.io/voxpupuli/commitlint
Downloads
ghcr.io/voxpupuli/commitlint:latest (2026-07-28)
Trivy
HIGH 7
MEDIUM 7
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-14257 | brace-expansion | 5.0.7 | 5.0.8, 3.0.3, 2.1.3, 1.1.17 | brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function — Node.js |
| HIGH | CVE-2026-69152 | brace-expansion | 5.0.7 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays — Node.js |
| HIGH | CVE-2026-18446 | fast-uri | 3.1.4 | 2.4.4, 3.1.5, 4.1.2 | fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority — Node.js |
| HIGH | CVE-2026-69192 | ip-address | 10.2.0 | 10.3.1 | ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.3.0 | 4.3.1, 3.15.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — Node.js |
| HIGH | CVE-2026-56852 | golang.org/x/text | v0.38.0 | 0.39.0 | golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-39822 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | golang: Go os.Root: Symlink following vulnerability allows directory traversal — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| MEDIUM | CVE-2026-54272 | ip-address | 10.2.0 | 10.2.1 | ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification — Node.js |
| MEDIUM | CVE-2026-69198 | ip-address | 10.2.0 | 10.2.2 | ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| MEDIUM | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — Node.js |
| MEDIUM | CVE-2026-15157 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property — Node.js |
| MEDIUM | CVE-2026-16728 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length — Node.js |
| MEDIUM | CVE-2026-16729 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections — Node.js |
| MEDIUM | CVE-2026-42505 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
Grype
HIGH 10
MEDIUM 8
NVD/CPE filtered 9
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GO-2026-5026 | golang.org/x/net | v0.54.0 | 0.55.0 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/git-lfs |
| HIGH | GO-2026-5037 | stdlib | go1.26.3 | 1.25.11, 1.26.4 | (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. — /usr/bin/git-lfs |
| HIGH | GO-2026-5970 | golang.org/x/text | v0.37.0 | 0.39.0 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /usr/bin/git-lfs |
| HIGH | GO-2026-5970 | golang.org/x/text | v0.38.0 | 0.39.0 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | GHSA-rgw5-rvv9-x895 | brace-expansion | 5.0.7 | 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GO-2026-5942 | golang.org/x/net | v0.54.0 | 0.56.0 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. — /usr/bin/git-lfs |
| HIGH | GHSA-mh99-v99m-4gvg | brace-expansion | 5.0.7 | 5.0.8 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-mwp4-54f8-5fhr | ip-address | 10.2.0 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.3.0 | 4.3.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — /npm/node_modules/js-yaml/package.json |
| HIGH | GHSA-7p8r-x3mc-p8w7 | fast-uri | 3.1.4 | 3.1.5 | fast-uri vulnerable to host confusion via backslash authority introducer — /npm/node_modules/fast-uri/package.json |
| MEDIUM | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — /usr/local/lib/node_modules/npm/node_modules/tar/package.json |
| MEDIUM | GHSA-m8rv-5g2x-5cg5 | undici | 6.27.0 | 6.28.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-v3r7-h72x-cjcm | undici | 6.27.0 | 6.28.0 | undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-8xcm-r25x-g524 | undici | 6.27.0 | 6.28.0 | undici vulnerable to downstream response desynchronization via retry interceptor — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-22jq-vg5j-6vgg | ip-address | 10.2.0 | 10.2.1 | ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-4xrf-jv44-h6hh | ip-address | 10.2.0 | 10.2.2 | ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GO-2026-5039 | stdlib | go1.26.3 | 1.25.11, 1.26.4 | When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. — /usr/bin/git-lfs |
| MEDIUM | GO-2026-5856 | stdlib | go1.26.3 | 1.25.12, 1.26.5, 1.27.0-rc.2 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/bin/git-lfs |
Filtered NVD/CPE matches (9)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-58043 | node | 24.18.0 | 22.23.2, 24.18.1, 26.5.1 | A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**. — /usr/local/bin/node |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-58040 | node | 24.18.0 | 22.23.2, 24.18.1, 26.5.1 | An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. — /usr/local/bin/node |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56850 | node | 24.18.0 | 22.23.2, 24.18.1, 26.5.1 | A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**. — /usr/local/bin/node |
| LOW | CVE-2026-58039 | node | 24.18.0 | 22.23.2, 24.18.1, 26.5.1 | A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. — /usr/local/bin/node |
| LOW | CVE-2026-56847 | node | 24.18.0 | 22.23.2, 24.18.1, 26.5.1 | A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. — /usr/local/bin/node |
ghcr.io/voxpupuli/onceover
Downloads
ghcr.io/voxpupuli/onceover:latest (2026-07-24)
Trivy
CRITICAL 1
HIGH 4
MEDIUM 2
LOW 2
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-42257 | net-imap | 0.3.9 | ~> 0.4.24, ~> 0.5.14, >= 0.6.4 | net-imap: Net::IMAP: Arbitrary IMAP command injection via CRLF sequences in unvalidated input — Ruby |
| HIGH | CVE-2026-41316 | erb | 4.0.2 | ~> 4.0.3.1, ~> 4.0.4.1, ~> 6.0.1.1, >= 6.0.4 | erb: ERB: Arbitrary code execution via deserialization bypass — Ruby |
| HIGH | CVE-2026-42245 | net-imap | 0.3.9 | ~> 0.4.24, ~> 0.5.14, >= 0.6.4 | ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses — Ruby |
| HIGH | CVE-2026-42246 | net-imap | 0.3.9 | ~> 0.3.10, ~> 0.4.24, ~> 0.5.14, >= 0.6.4 | net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS — Ruby |
| HIGH | CVE-2026-42258 | net-imap | 0.3.9 | ~> 0.4.24, ~> 0.5.14, >= 0.6.4 | ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments — Ruby |
| MEDIUM | CVE-2026-47240 | net-imap | 0.3.9 | ~> 0.5.15, >= 0.6.4.1 | net-imap: Net::IMAP: Command injection via non-synchronizing literals — Ruby |
| MEDIUM | CVE-2026-47242 | net-imap | 0.3.9 | ~> 0.5.15, >= 0.6.4.1 | Net::IMAP implements Internet Message Access Protocol (IMAP) client fu ... — Ruby |
| LOW | CVE-2026-71847 | json | 2.21.1 | 2.21.2 | Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, ... — Ruby |
| LOW | CVE-2026-47241 | net-imap | 0.3.9 | ~> 0.5.15, >= 0.6.4.1 | net-imap: rubygem-net-imap: Net::IMAP: Denial of Service via malformed command input — Ruby |
Grype
HIGH 2
MEDIUM 4
LOW 2
NVD/CPE filtered 53
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GHSA-q339-8rmv-2mhv | erb | 4.0.2 | 4.0.3.1 | ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/local/lib/ruby/gems/3.2.0/specifications/default/erb-4.0.2.gemspec |
| HIGH | GHSA-vcgp-9326-pqcp | net-imap | 0.3.9 | 0.3.10 | net-imap vulnerable to STARTTLS stripping via invalid response timing — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
| MEDIUM | GHSA-75xq-5h9v-w6px | net-imap | 0.3.9 | 0.4.24 | net-imap vulnerable to command Injection via unvalidated Symbol inputs — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
| MEDIUM | GHSA-8p34-64r3-mwg8 | net-imap | 0.3.9 | 0.5.15 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
| MEDIUM | GHSA-hm49-wcqc-g2xg | net-imap | 0.3.9 | 0.4.24 | net-imap vulnerable to command Injection via "raw" arguments to multiple commands — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
| MEDIUM | GHSA-46q3-7gv7-qmgg | net-imap | 0.3.9 | 0.5.15 | Net::IMAP: Command Injection via ID command argument — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
| LOW | GHSA-q2mw-fvj9-vvcw | net-imap | 0.3.9 | 0.4.24 | net-imap has quadratic complexity when reading response literals — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
| LOW | GHSA-c4fp-cxrr-mj66 | net-imap | 0.3.9 | 0.5.15 | Net::IMAP: Denial of Service via incomplete raw argument validation — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
Filtered NVD/CPE matches (53)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-11856 | curl | 8.20.0-r0 | Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-11564 | curl | 8.20.0-r0 | libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-8925 | curl | 8.20.0-r0 | The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-9079 | curl | 8.20.0-r0 | libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-8924 | curl | 8.20.0-r0 | A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-10536 | curl | 8.20.0-r0 | A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-8926 | curl | 8.20.0-r0 | When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-8927 | curl | 8.20.0-r0 | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`. — /lib/apk/db/installed | |
| HIGH | CVE-2026-7210 | python3 | 3.12.13-r0 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch. — /lib/apk/db/installed | |
| HIGH | CVE-2026-9546 | curl | 8.20.0-r0 | A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` suppresses the header, the option failed to clear the internal state. As a result the previous referrer string was erroneously reused and sent in subsequent requests, potentially leaking sensitive information to unintended servers. — /lib/apk/db/installed | |
| HIGH | CVE-2026-8932 | curl | 8.20.0-r0 | libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key. — /lib/apk/db/installed | |
| HIGH | CVE-2026-12064 | curl | 8.20.0-r0 | When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error. — /lib/apk/db/installed | |
| HIGH | CVE-2026-9547 | curl | 8.20.0-r0 | When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack. — /lib/apk/db/installed | |
| HIGH | CVE-2026-8286 | curl | 8.20.0-r0 | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. — /lib/apk/db/installed | |
| HIGH | CVE-2026-32631 | git | 2.52.0-r0 | Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's NTLM hash. The NTLM hash can be obtained by tricking users into cloning a malicious repository, or checking out a malicious branch, that accesses an attacker-controlled server. By default, NTLM authentication does not need any user interaction. By brute-forcing the NTLMv2 hash (which is expensive, but possible), credentials can be extracted. This issue has been fixed in version 2.53.0.windows.3. — /lib/apk/db/installed | |
| HIGH | CVE-2026-9080 | curl | 8.20.0-r0 | Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed. — /lib/apk/db/installed | |
| HIGH | CVE-2026-4786 | python3 | 3.12.13-r0 | Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. — /lib/apk/db/installed | |
| HIGH | CVE-2026-9545 | curl | 8.20.0-r0 | In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11824 | sqlite-libs | 3.51.2-r0 | SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11822 | sqlite-libs | 3.51.2-r0 | SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11940 | python3 | 3.12.13-r0 | tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330. — /lib/apk/db/installed | |
| HIGH | CVE-2026-15308 | python3 | 3.12.13-r0 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data. — /lib/apk/db/installed | |
| HIGH | CVE-2026-6100 | python3 | 3.12.13-r0 | Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable. — /lib/apk/db/installed | |
| HIGH | CVE-2026-4224 | python3 | 3.12.13-r0 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11352 | curl | 8.20.0-r0 | An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11586 | curl | 8.20.0-r0 | By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11972 | python3 | 3.12.13-r0 | When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer. — /lib/apk/db/installed | |
| HIGH | CVE-2026-3644 | python3 | 3.12.13-r0 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output(). — /lib/apk/db/installed | |
| HIGH | CVE-2026-9669 | python3 | 3.12.13-r0 | bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data. — /lib/apk/db/installed | |
| HIGH | CVE-2026-3298 | python3 | 3.12.13-r0 | The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-6019 | python3 | 3.12.13-r0 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-0864 | python3 | 3.12.13-r0 | When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-3446 | python3 | 3.12.13-r0 | When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use "validate=True" to enable stricter processing of base64 data. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-13837 | python3 | 3.12.13-r0 | When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-2297 | python3 | 3.12.13-r0 | The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-4360 | python3 | 3.12.13-r0 | In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-12003 | python3 | 3.12.13-r0 | To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree. On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\..', which results in a landmark of '..\..\Modules\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install. Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive. Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources. Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory. The landmark detection involving VPATH is a fallback for when a more specific landmark - .\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15367 | python3 | 3.12.13-r0 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-8458 | curl | 8.20.0-r0 | libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15366 | python3 | 3.12.13-r0 | The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-8328 | python3 | 3.12.13-r0 | The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-3276 | python3 | 3.12.13-r0 | unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-12781 | python3 | 3.12.13-r0 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alternative base64 alphabet" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues. This behavior can only be insecure if your application uses an alternate base64 alphabet (without "+/"). If your application does not use the "altchars" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet. The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 alphabet they are expecting or verify that their application would not be affected if the b64decode() functions accepted "+" or "/" outside of altchars. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-1502 | python3 | 3.12.13-r0 | CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-7774 | python3 | 3.12.13-r0 | tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process. — /lib/apk/db/installed | |
| LOW | CVE-2026-4519 | python3 | 3.12.13-r0 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open(). — /lib/apk/db/installed | |
| LOW | CVE-2026-6879 | python3 | 3.12.13-r0 | `Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end of the sibling list, such as with `[last()]` or `[last()-N]`; `.//item[1]` short-circuits after the first match. — /lib/apk/db/installed | |
| LOW | CVE-2025-13462 | python3 | 3.12.13-r0 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations. — /lib/apk/db/installed | |
| UNKNOWN | CVE-2026-3479 | python3 | 3.12.13-r0 | DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals. — /lib/apk/db/installed |
ghcr.io/voxpupuli/r10k-webhook
Downloads
ghcr.io/voxpupuli/r10k-webhook:latest (2026-08-07)
Trivy
CRITICAL 1
HIGH 37
MEDIUM 47
LOW 21
UNKNOWN 9
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-54906 | concurrent-ruby | 1.3.6 | >= 1.3.7 | concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Synchronization flaw in ReadWriteLock allows unauthorized lock release and denial of service — Ruby |
| HIGH | CVE-2026-45186 | libexpat | 2.7.5-r0 | 2.8.1-r0 | libexpat: denial of service via crafted XML input — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-56408 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat before 2.8.2 has an integer overflow in copyString. — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-55199 | libssh2 | 1.11.1-r1 | 1.11.1-r3 | libssh2: libssh2: Denial of Service via crafted SSH_MSG_EXT_INFO message — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-55200 | libssh2 | 1.11.1-r1 | 1.11.1-r3 | libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-7598 | libssh2 | 1.11.1-r1 | 1.11.1-r2 | libssh2: integer overflow via large username or password arguments — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-45447 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-54904 | concurrent-ruby | 1.3.6 | >= 1.3.7 | concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Denial of Service due to infinite loop in AtomicReference#update — Ruby |
| HIGH | CVE-2026-54297 | faraday | 2.14.2 | ~> 1.10.6, >= 2.14.3 | faraday: Faraday: Denial of Service via crafted nested query strings — Ruby |
| HIGH | CVE-2026-45363 | jwt | 2.10.2 | ~> 2.10.3, >= 3.2.0 | ruby-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verification — Ruby |
| HIGH | CVE-2026-27145 | stdlib | v1.26.2 | 1.25.11, 1.26.4 | crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-33811 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-33814 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39820 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/mail: golang: Go net/mail: Denial of Service via crafted email inputs — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39822 | stdlib | v1.26.2 | 1.25.12, 1.26.5, 1.27.0-rc.2 | golang: Go os.Root: Symlink following vulnerability allows directory traversal — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39836 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-42499 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/mail: golang: net/mail: Denial of Service via pathological email address parsing — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-42504 | stdlib | v1.26.2 | 1.25.11, 1.26.4 | mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39828 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions — usr/sbin/webhook-go |
| HIGH | CVE-2026-39829 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters — usr/sbin/webhook-go |
| HIGH | CVE-2026-39830 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses — usr/sbin/webhook-go |
| HIGH | CVE-2026-39831 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check — usr/sbin/webhook-go |
| HIGH | CVE-2026-39832 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions — usr/sbin/webhook-go |
| HIGH | CVE-2026-39835 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate — usr/sbin/webhook-go |
| HIGH | CVE-2026-42508 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey — usr/sbin/webhook-go |
| HIGH | CVE-2026-46595 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation — usr/sbin/webhook-go |
| HIGH | CVE-2026-46597 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs — usr/sbin/webhook-go |
| HIGH | CVE-2026-25681 | golang.org/x/net | v0.51.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting — usr/sbin/webhook-go |
| HIGH | CVE-2026-27136 | golang.org/x/net | v0.51.0 | 0.55.0 | golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass — usr/sbin/webhook-go |
| HIGH | CVE-2026-33814 | golang.org/x/net | v0.51.0 | 0.53.0 | net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame — usr/sbin/webhook-go |
| HIGH | CVE-2026-39821 | golang.org/x/net | v0.51.0 | 0.55.0 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/sbin/webhook-go |
| HIGH | CVE-2026-56852 | golang.org/x/text | v0.34.0 | 0.39.0 | golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input — usr/sbin/webhook-go |
| HIGH | CVE-2026-6276 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-5773 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-45447 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-6276 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-33630 | c-ares | 1.34.6-r0 | 1.34.8-r0 | c-ares: c-ares: Use-after-free / double-free in query-completion handling — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-5773 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-42506 | golang.org/x/net | v0.51.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-54905 | concurrent-ruby | 1.3.6 | >= 1.3.7 | concurrent-ruby: Concurrent-ruby: Incorrect write lock granting leading to broken mutual exclusion — Ruby |
| MEDIUM | CVE-2026-39823 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-39825 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-39826 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-42505 | stdlib | v1.26.2 | 1.25.12, 1.26.5, 1.27.0-rc.2 | crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-42507 | stdlib | v1.26.2 | 1.25.11, 1.26.4 | net/textproto: golang: Golang net/textproto: Misleading error messages via input injection — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-40898 | github.com/quic-go/quic-go | v0.59.0 | 0.59.1 | github.com/quic-go/quic-go: quic-go: Denial of Service via excessive memory allocation in HTTP/3 trailers — usr/sbin/webhook-go |
| MEDIUM | GHSA-gxhx-2686-5h9g | github.com/slack-go/slack | v0.18.0 | 0.23.1 | slack-go `SecretsVerifier` accepts empty signing secret without precondition — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-45445 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: AES-OCB IV Ignored on EVP_Cipher() Path — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-42764 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: NULL pointer dereference in QUIC server initial packet handling — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-34183 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-34182 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-42502 | golang.org/x/net | v0.51.0 | 0.55.0 | golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-7168 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-7009 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: Curl: Certificate validation bypass due to OCSP stapling flaw — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-6429 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Credential leak via reused proxy connection during HTTP redirects — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-6253 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-39827 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-39833 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-39834 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-46598 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-5545 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-4873 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: curl: Information disclosure due to incorrect TLS connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-25680 | golang.org/x/net | v0.51.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-45445 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: AES-OCB IV Ignored on EVP_Cipher() Path — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-42764 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: NULL pointer dereference in QUIC server initial packet handling — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-34183 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-34182 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-4873 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: curl: Information disclosure due to incorrect TLS connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-5545 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-6253 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-6429 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Credential leak via reused proxy connection during HTTP redirects — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56412 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56411 | libexpat | 2.7.5-r0 | 2.8.2-r0 | expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56410 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56409 | libexpat | 2.7.5-r0 | 2.8.2-r0 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56407 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Arbitrary code execution due to integer overflow — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56406 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56405 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56404 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56403 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56132 | libexpat | 2.7.5-r0 | 2.8.2-r0 | expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56131 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-50219 | libexpat | 2.7.5-r0 | 2.8.2-r0 | expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-7009 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: Curl: Certificate validation bypass due to OCSP stapling flaw — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-7168 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42767 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42768 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42769 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42770 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: FFC-DH Peer Validation Uses Attacker-Supplied q — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-45446 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-7383 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-9076 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42766 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Possible NULL Dereference in Password-Based CMS Decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-34181 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-34180 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-9076 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-7383 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-45446 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-34180 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-34181 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42766 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Possible NULL Dereference in Password-Based CMS Decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42767 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42768 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42769 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42770 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: FFC-DH Peer Validation Uses Attacker-Supplied q — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-41080 | libexpat | 2.7.5-r0 | 2.8.1-r0 | libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| UNKNOWN | CVE-2026-53587 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| UNKNOWN | GO-2026-5932 | golang.org/x/crypto | v0.48.0 | The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues — usr/sbin/webhook-go | |
| UNKNOWN | CVE-2026-53586 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| UNKNOWN | CVE-2026-53585 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| UNKNOWN | CVE-2026-53584 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| UNKNOWN | CVE-2026-53583 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| UNKNOWN | CVE-2026-39824 | golang.org/x/sys | v0.43.0 | 0.44.0 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-46600 | golang.org/x/net | v0.51.0 | 0.56.0 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ... — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-39824 | golang.org/x/sys | v0.41.0 | 0.44.0 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows — usr/sbin/webhook-go |
Grype
CRITICAL 3
HIGH 33
MEDIUM 35
LOW 7
UNKNOWN 6
NVD/CPE filtered 41
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-34182 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-34182 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-7598 | libssh2 | 1.11.1-r1 | 1.11.1-r2 | /lib/apk/db/installed |
| HIGH | CVE-2026-45445 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-45445 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | GO-2026-5037 | stdlib | go1.26.2 | 1.25.11, 1.26.4 | (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-9076 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9076 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | GO-2026-4971 | stdlib | go1.26.2 | 1.25.10, 1.26.3 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | GHSA-c32j-vqhx-rx3x | jwt | 2.10.2 | 2.10.3 | ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351 — /usr/lib/ruby/gems/3.4.0/specifications/jwt-2.10.2.gemspec |
| HIGH | GHSA-98m9-hrrm-r99r | faraday | 2.14.2 | 2.14.3 | Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters — /usr/lib/ruby/gems/3.4.0/specifications/faraday-2.14.2.gemspec |
| HIGH | GO-2026-5970 | golang.org/x/text | v0.34.0 | 0.39.0 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /usr/sbin/webhook-go |
| HIGH | CVE-2026-45186 | libexpat | 2.7.5-r0 | 2.8.1-r0 | /lib/apk/db/installed |
| HIGH | GHSA-h8w8-99g7-qmvj | concurrent-ruby | 1.3.6 | 1.3.7 | Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN` — /usr/lib/ruby/gems/3.4.0/specifications/concurrent-ruby-1.3.6.gemspec |
| HIGH | CVE-2026-34181 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-34181 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-41080 | libexpat | 2.7.5-r0 | 2.8.1-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-6276 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-6276 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-45447 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-45447 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-55200 | libssh2 | 1.11.1-r1 | 1.11.1-r3 | /lib/apk/db/installed |
| HIGH | GHSA-q339-8rmv-2mhv | erb | 4.0.4 | 4.0.4.1 | ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/lib/ruby/gems/3.4.0/specifications/default/erb-4.0.4.gemspec |
| HIGH | CVE-2026-42764 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-42764 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-34183 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-34183 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-34180 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-34180 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-55199 | libssh2 | 1.11.1-r1 | 1.11.1-r3 | /lib/apk/db/installed |
| HIGH | GO-2026-4918 | stdlib | go1.26.2 | 1.25.10, 1.26.3 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | GO-2026-5026 | golang.org/x/net | v0.51.0 | 0.55.0 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/sbin/webhook-go |
| HIGH | CVE-2026-7383 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-7383 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-5773 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-5773 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-45446 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-42766 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-45446 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-50219 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-7009 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-7009 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56410 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56411 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56406 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56409 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56412 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56404 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56408 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56403 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56405 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56407 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56131 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56132 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-42766 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-6253 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-6253 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-42767 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-42767 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-6429 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-6429 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-7168 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-7168 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-5545 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-4873 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-4873 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | GO-2026-5039 | stdlib | go1.26.2 | 1.25.11, 1.26.4 | When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. — /usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | GO-2026-5856 | stdlib | go1.26.2 | 1.25.12, 1.26.5, 1.27.0-rc.2 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-42769 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-42769 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-5545 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-42770 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-42770 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-42768 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-42768 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| LOW | GHSA-x2f5-4prf-w687 | json | 2.9.1 | 2.19.9 | Ruby json: JSON generator heap buffer overflow when streaming to an IO — /usr/lib/ruby/gems/3.4.0/specifications/default/json-2.9.1.gemspec |
| LOW | GHSA-6wx8-w4f5-wwcr | concurrent-ruby | 1.3.6 | 1.3.7 | Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption — /usr/lib/ruby/gems/3.4.0/specifications/concurrent-ruby-1.3.6.gemspec |
| LOW | GHSA-wv3x-4vxv-whpp | concurrent-ruby | 1.3.6 | 1.3.7 | Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity — /usr/lib/ruby/gems/3.4.0/specifications/concurrent-ruby-1.3.6.gemspec |
| UNKNOWN | CVE-2026-33630 | c-ares | 1.34.6-r0 | 1.34.8-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-53583 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-53584 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-53585 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-53586 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-53587 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | /lib/apk/db/installed |
Filtered NVD/CPE matches (41)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-11856 | curl | 8.19.0-r0 | Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-8925 | curl | 8.19.0-r0 | The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-9079 | curl | 8.19.0-r0 | libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-8924 | curl | 8.19.0-r0 | A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-10536 | curl | 8.19.0-r0 | A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-8927 | curl | 8.19.0-r0 | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-8926 | curl | 8.19.0-r0 | When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-11564 | curl | 8.19.0-r0 | libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer. — /lib/apk/db/installed | |
| HIGH | CVE-2026-8286 | curl | 8.19.0-r0 | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66035 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication. — /lib/apk/db/installed | |
| HIGH | CVE-2026-32631 | git | 2.52.0-r0 | Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's NTLM hash. The NTLM hash can be obtained by tricking users into cloning a malicious repository, or checking out a malicious branch, that accesses an attacker-controlled server. By default, NTLM authentication does not need any user interaction. By brute-forcing the NTLMv2 hash (which is expensive, but possible), credentials can be extracted. This issue has been fixed in version 2.53.0.windows.3. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66032 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59851 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users. — /lib/apk/db/installed | |
| HIGH | CVE-2026-9080 | curl | 8.19.0-r0 | Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59847 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58051 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59850 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions. — /lib/apk/db/installed | |
| HIGH | CVE-2026-9545 | curl | 8.19.0-r0 | In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59849 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service. — /lib/apk/db/installed | |
| HIGH | CVE-2026-9547 | curl | 8.19.0-r0 | When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack. — /lib/apk/db/installed | |
| HIGH | CVE-2026-12064 | curl | 8.19.0-r0 | When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58050 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66033 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs. — /lib/apk/db/installed | |
| HIGH | CVE-2026-15370 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66034 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region. — /lib/apk/db/installed | |
| HIGH | CVE-2026-8932 | curl | 8.19.0-r0 | libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key. — /lib/apk/db/installed | |
| HIGH | CVE-2026-9546 | curl | 8.19.0-r0 | A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` suppresses the header, the option failed to clear the internal state. As a result the previous referrer string was erroneously reused and sent in subsequent requests, potentially leaking sensitive information to unintended servers. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11586 | curl | 8.19.0-r0 | By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11352 | curl | 8.19.0-r0 | An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59848 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59845 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-8458 | curl | 8.19.0-r0 | libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59842 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59844 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59843 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15661 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. — /lib/apk/db/installed | |
| LOW | CVE-2026-59846 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. — /lib/apk/db/installed |
ghcr.io/voxpupuli/r10k
Downloads
ghcr.io/voxpupuli/r10k:latest (2026-08-07)
Trivy
HIGH 8
MEDIUM 5
UNKNOWN 1
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-27145 | stdlib | v1.26.2 | 1.25.11, 1.26.4 | crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-33811 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-33814 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39820 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/mail: golang: Go net/mail: Denial of Service via crafted email inputs — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39822 | stdlib | v1.26.2 | 1.25.12, 1.26.5, 1.27.0-rc.2 | golang: Go os.Root: Symlink following vulnerability allows directory traversal — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39836 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-42499 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/mail: golang: net/mail: Denial of Service via pathological email address parsing — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-42504 | stdlib | v1.26.2 | 1.25.11, 1.26.4 | mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-39823 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-39825 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-39826 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-42505 | stdlib | v1.26.2 | 1.25.12, 1.26.5, 1.27.0-rc.2 | crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-42507 | stdlib | v1.26.2 | 1.25.11, 1.26.4 | net/textproto: golang: Golang net/textproto: Misleading error messages via input injection — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-39824 | golang.org/x/sys | v0.43.0 | 0.44.0 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows — usr/local/bin/supercronic-linux-amd64 |
Grype
HIGH 4
MEDIUM 2
LOW 1
NVD/CPE filtered 22
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GHSA-q339-8rmv-2mhv | erb | 4.0.4 | 4.0.4.1 | ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/lib/ruby/gems/3.4.0/specifications/default/erb-4.0.4.gemspec |
| HIGH | GO-2026-4918 | stdlib | go1.26.2 | 1.25.10, 1.26.3 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | GO-2026-5037 | stdlib | go1.26.2 | 1.25.11, 1.26.4 | (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | GO-2026-4971 | stdlib | go1.26.2 | 1.25.10, 1.26.3 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). — /usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | GO-2026-5856 | stdlib | go1.26.2 | 1.25.12, 1.26.5, 1.27.0-rc.2 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | GO-2026-5039 | stdlib | go1.26.2 | 1.25.11, 1.26.4 | When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. — /usr/local/bin/supercronic-linux-amd64 |
| LOW | GHSA-x2f5-4prf-w687 | json | 2.9.1 | 2.19.9 | Ruby json: JSON generator heap buffer overflow when streaming to an IO — /usr/lib/ruby/gems/3.4.0/specifications/default/json-2.9.1.gemspec |
Filtered NVD/CPE matches (22)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-15370 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66033 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58050 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66035 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66032 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59851 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59847 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58051 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59850 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59849 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66034 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59845 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59848 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59842 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59844 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59843 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15661 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. — /lib/apk/db/installed | |
| LOW | CVE-2026-59846 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. — /lib/apk/db/installed |
ghcr.io/voxpupuli/renovate
Downloads
ghcr.io/voxpupuli/renovate:latest (2026-08-07)
Trivy
HIGH 3
MEDIUM 6
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-14257 | brace-expansion | 5.0.7 | 5.0.8, 3.0.3, 2.1.3, 1.1.17 | brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function — Node.js |
| HIGH | CVE-2026-69152 | brace-expansion | 5.0.7 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays — Node.js |
| HIGH | CVE-2026-69192 | ip-address | 10.2.0 | 10.3.1 | ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| MEDIUM | CVE-2026-54272 | ip-address | 10.2.0 | 10.2.1 | ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification — Node.js |
| MEDIUM | CVE-2026-69198 | ip-address | 10.2.0 | 10.2.2 | ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| MEDIUM | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — Node.js |
| MEDIUM | CVE-2026-15157 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property — Node.js |
| MEDIUM | CVE-2026-16728 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length — Node.js |
| MEDIUM | CVE-2026-16729 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections — Node.js |
Grype
HIGH 3
MEDIUM 6
NVD/CPE filtered 4
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GHSA-rgw5-rvv9-x895 | brace-expansion | 5.0.7 | 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-mh99-v99m-4gvg | brace-expansion | 5.0.7 | 5.0.8 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-mwp4-54f8-5fhr | ip-address | 10.2.0 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-4xrf-jv44-h6hh | ip-address | 10.2.0 | 10.2.2 | ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-22jq-vg5j-6vgg | ip-address | 10.2.0 | 10.2.1 | ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-8xcm-r25x-g524 | undici | 6.27.0 | 6.28.0 | undici vulnerable to downstream response desynchronization via retry interceptor — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-v3r7-h72x-cjcm | undici | 6.27.0 | 6.28.0 | undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-m8rv-5g2x-5cg5 | undici | 6.27.0 | 6.28.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — /usr/local/lib/node_modules/npm/node_modules/tar/package.json |
Filtered NVD/CPE matches (4)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed |
ghcr.io/voxpupuli/semantic-release
Downloads
ghcr.io/voxpupuli/semantic-release:latest (2026-07-29)
Trivy
HIGH 18
MEDIUM 19
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 3.15.0 | 4.3.1, 3.15.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — Node.js |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.3.0 | 4.3.1, 3.15.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — Node.js |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.3.0 | 4.3.1, 3.15.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — Node.js |
| HIGH | CVE-2026-69192 | ip-address | 10.2.0 | 10.3.1 | ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| HIGH | CVE-2026-69192 | ip-address | 10.2.0 | 10.3.1 | ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| HIGH | CVE-2026-18446 | fast-uri | 3.1.4 | 2.4.4, 3.1.5, 4.1.2 | fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority — Node.js |
| HIGH | CVE-2026-69152 | brace-expansion | 5.0.7 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays — Node.js |
| HIGH | CVE-2026-69152 | brace-expansion | 5.0.7 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays — Node.js |
| HIGH | CVE-2026-14257 | brace-expansion | 5.0.7 | 5.0.8, 3.0.3, 2.1.3, 1.1.17 | brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function — Node.js |
| HIGH | CVE-2026-14257 | brace-expansion | 5.0.7 | 5.0.8, 3.0.3, 2.1.3, 1.1.17 | brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function — Node.js |
| HIGH | CVE-2026-69152 | brace-expansion | 2.1.3 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays — Node.js |
| HIGH | CVE-2026-69152 | brace-expansion | 2.1.3 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays — Node.js |
| HIGH | CVE-2026-69152 | brace-expansion | 1.1.17 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays — Node.js |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.3.0 | 4.3.1, 3.15.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — Node.js |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.3.0 | 4.3.1, 3.15.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — Node.js |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.3.0 | 4.3.1, 3.15.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — Node.js |
| HIGH | CVE-2026-56852 | golang.org/x/text | v0.38.0 | 0.39.0 | golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-39822 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | golang: Go os.Root: Symlink following vulnerability allows directory traversal — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| MEDIUM | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — Node.js |
| MEDIUM | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — Node.js |
| MEDIUM | CVE-2026-15157 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property — Node.js |
| MEDIUM | CVE-2026-15157 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property — Node.js |
| MEDIUM | CVE-2026-16728 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length — Node.js |
| MEDIUM | CVE-2026-16728 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length — Node.js |
| MEDIUM | CVE-2026-16729 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections — Node.js |
| MEDIUM | CVE-2026-16729 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections — Node.js |
| MEDIUM | CVE-2026-42505 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| MEDIUM | CVE-2026-69198 | ip-address | 10.2.0 | 10.2.2 | ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| MEDIUM | CVE-2026-69198 | ip-address | 10.2.0 | 10.2.2 | ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| MEDIUM | CVE-2026-54272 | ip-address | 10.2.0 | 10.2.1 | ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification — Node.js |
| MEDIUM | CVE-2026-54272 | ip-address | 10.2.0 | 10.2.1 | ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification — Node.js |
| MEDIUM | CVE-2025-25289 | @octokit/request-error | 3.0.3 | 5.1.1, 6.1.7 | @octokit/request-error: @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js |
| MEDIUM | CVE-2025-25289 | @octokit/request-error | 2.1.0 | 5.1.1, 6.1.7 | @octokit/request-error: @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js |
| MEDIUM | CVE-2025-25290 | @octokit/request | 6.2.8 | 9.2.1, 8.4.1 | octokit/request: @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js |
| MEDIUM | CVE-2025-25290 | @octokit/request | 5.6.3 | 9.2.1, 8.4.1 | octokit/request: @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js |
| MEDIUM | CVE-2025-25288 | @octokit/plugin-paginate-rest | 6.1.2 | 11.4.1, 9.2.2 | octokit/plugin-paginate-rest: @octokit/plugin-paginate-rest has a Regular Expression in iterator that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js |
| MEDIUM | CVE-2025-25288 | @octokit/plugin-paginate-rest | 2.21.3 | 11.4.1, 9.2.2 | octokit/plugin-paginate-rest: @octokit/plugin-paginate-rest has a Regular Expression in iterator that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js |
Grype
HIGH 21
MEDIUM 20
NVD/CPE filtered 9
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GHSA-7p8r-x3mc-p8w7 | fast-uri | 3.1.4 | 3.1.5 | fast-uri vulnerable to host confusion via backslash authority introducer — /npm/node_modules/fast-uri/package.json |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 3.15.0 | 3.15.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — /npm/node_modules/js-yaml/package.json |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.3.0 | 4.3.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — /npm/node_modules/@eslint/eslintrc/node_modules/js-yaml/package.json |
| HIGH | GHSA-mwp4-54f8-5fhr | ip-address | 10.2.0 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| HIGH | GHSA-mwp4-54f8-5fhr | ip-address | 10.2.0 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass — /npm/node_modules/npm/node_modules/ip-address/package.json |
| HIGH | GHSA-mh99-v99m-4gvg | brace-expansion | 5.0.7 | 5.0.8 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-mh99-v99m-4gvg | brace-expansion | 5.0.7 | 5.0.8 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — /npm/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GO-2026-5942 | golang.org/x/net | v0.54.0 | 0.56.0 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. — /usr/bin/git-lfs |
| HIGH | GHSA-rgw5-rvv9-x895 | brace-expansion | 5.0.7 | 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — /npm/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-rgw5-rvv9-x895 | brace-expansion | 5.0.7 | 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-rgw5-rvv9-x895 | brace-expansion | 2.1.3 | 2.1.4 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — /npm/node_modules/@typescript-eslint/typescript-estree/node_modules/brace-expansion/package.json |
| HIGH | GHSA-rgw5-rvv9-x895 | brace-expansion | 2.1.3 | 2.1.4 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — /npm/node_modules/replace-in-file/node_modules/brace-expansion/package.json |
| HIGH | GHSA-rgw5-rvv9-x895 | brace-expansion | 1.1.17 | 1.1.18 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — /npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.3.0 | 4.3.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — /npm/node_modules/cosmiconfig/node_modules/js-yaml/package.json |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.3.0 | 4.3.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — /npm/node_modules/xo/node_modules/js-yaml/package.json |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.3.0 | 4.3.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — /npm/node_modules/eslint-plugin-unicorn/node_modules/js-yaml/package.json |
| HIGH | GHSA-5p4m-2wfm-xmqj | js-yaml | 4.3.0 | 4.3.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported — /npm/node_modules/eslint/node_modules/js-yaml/package.json |
| HIGH | GO-2026-5970 | golang.org/x/text | v0.38.0 | 0.39.0 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | GO-2026-5970 | golang.org/x/text | v0.37.0 | 0.39.0 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /usr/bin/git-lfs |
| HIGH | GO-2026-5037 | stdlib | go1.26.3 | 1.25.11, 1.26.4 | (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. — /usr/bin/git-lfs |
| HIGH | GO-2026-5026 | golang.org/x/net | v0.54.0 | 0.55.0 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/git-lfs |
| MEDIUM | GHSA-8xcm-r25x-g524 | undici | 6.27.0 | 6.28.0 | undici vulnerable to downstream response desynchronization via retry interceptor — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-v3r7-h72x-cjcm | undici | 6.27.0 | 6.28.0 | undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields — /npm/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-v3r7-h72x-cjcm | undici | 6.27.0 | 6.28.0 | undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-m8rv-5g2x-5cg5 | undici | 6.27.0 | 6.28.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property — /npm/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-m8rv-5g2x-5cg5 | undici | 6.27.0 | 6.28.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — /npm/node_modules/npm/node_modules/tar/package.json |
| MEDIUM | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — /usr/local/lib/node_modules/npm/node_modules/tar/package.json |
| MEDIUM | GHSA-8xcm-r25x-g524 | undici | 6.27.0 | 6.28.0 | undici vulnerable to downstream response desynchronization via retry interceptor — /npm/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-22jq-vg5j-6vgg | ip-address | 10.2.0 | 10.2.1 | ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-22jq-vg5j-6vgg | ip-address | 10.2.0 | 10.2.1 | ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks — /npm/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-4xrf-jv44-h6hh | ip-address | 10.2.0 | 10.2.2 | ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks — /npm/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-4xrf-jv44-h6hh | ip-address | 10.2.0 | 10.2.2 | ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GO-2026-5039 | stdlib | go1.26.3 | 1.25.11, 1.26.4 | When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. — /usr/bin/git-lfs |
| MEDIUM | GO-2026-5856 | stdlib | go1.26.3 | 1.25.12, 1.26.5, 1.27.0-rc.2 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/bin/git-lfs |
| MEDIUM | GHSA-xx4v-prfh-6cgc | @octokit/request-error | 3.0.3 | 5.1.1 | @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/semantic-release-github-pullrequest/node_modules/@octokit/request-error/package.json |
| MEDIUM | GHSA-xx4v-prfh-6cgc | @octokit/request-error | 2.1.0 | 5.1.1 | @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/@octokit/rest/node_modules/@octokit/request-error/package.json |
| MEDIUM | GHSA-h5c3-5r3r-rr8q | @octokit/plugin-paginate-rest | 6.1.2 | 9.2.2 | @octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/semantic-release-github-pullrequest/node_modules/@octokit/plugin-paginate-rest/package.json |
| MEDIUM | GHSA-h5c3-5r3r-rr8q | @octokit/plugin-paginate-rest | 2.21.3 | 9.2.2 | @octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/@octokit/rest/node_modules/@octokit/plugin-paginate-rest/package.json |
| MEDIUM | GHSA-rmvr-2pp2-xj38 | @octokit/request | 6.2.8 | 8.4.1 | @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/semantic-release-github-pullrequest/node_modules/@octokit/request/package.json |
| MEDIUM | GHSA-rmvr-2pp2-xj38 | @octokit/request | 5.6.3 | 8.4.1 | @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/@octokit/rest/node_modules/@octokit/request/package.json |
Filtered NVD/CPE matches (9)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-58043 | node | 24.18.0 | 22.23.2, 24.18.1, 26.5.1 | A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**. — /usr/local/bin/node |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-58040 | node | 24.18.0 | 22.23.2, 24.18.1, 26.5.1 | An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. — /usr/local/bin/node |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56850 | node | 24.18.0 | 22.23.2, 24.18.1, 26.5.1 | A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**. — /usr/local/bin/node |
| LOW | CVE-2026-58039 | node | 24.18.0 | 22.23.2, 24.18.1, 26.5.1 | A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. — /usr/local/bin/node |
| LOW | CVE-2026-56847 | node | 24.18.0 | 22.23.2, 24.18.1, 26.5.1 | A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. — /usr/local/bin/node |
ghcr.io/voxpupuli/voxbox
Downloads
ghcr.io/voxpupuli/voxbox:latest (2026-08-06)
Trivy
No confirmed findings.
Grype
NVD/CPE filtered 57
No confirmed findings.
Filtered NVD/CPE matches (57)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-11856 | curl | 8.20.0-r0 | Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-11564 | curl | 8.20.0-r0 | libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-8925 | curl | 8.20.0-r0 | The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-9079 | curl | 8.20.0-r0 | libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-8924 | curl | 8.20.0-r0 | A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-10536 | curl | 8.20.0-r0 | A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-8926 | curl | 8.20.0-r0 | When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user. — /lib/apk/db/installed | |
| CRITICAL | CVE-2026-8927 | curl | 8.20.0-r0 | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11940 | python3 | 3.12.13-r0 | tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330. — /lib/apk/db/installed | |
| HIGH | CVE-2026-9546 | curl | 8.20.0-r0 | A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` suppresses the header, the option failed to clear the internal state. As a result the previous referrer string was erroneously reused and sent in subsequent requests, potentially leaking sensitive information to unintended servers. — /lib/apk/db/installed | |
| HIGH | CVE-2026-8932 | curl | 8.20.0-r0 | libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key. — /lib/apk/db/installed | |
| HIGH | CVE-2026-12064 | curl | 8.20.0-r0 | When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error. — /lib/apk/db/installed | |
| HIGH | CVE-2026-9547 | curl | 8.20.0-r0 | When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack. — /lib/apk/db/installed | |
| HIGH | CVE-2026-8286 | curl | 8.20.0-r0 | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. — /lib/apk/db/installed | |
| HIGH | CVE-2026-32631 | git | 2.52.0-r0 | Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's NTLM hash. The NTLM hash can be obtained by tricking users into cloning a malicious repository, or checking out a malicious branch, that accesses an attacker-controlled server. By default, NTLM authentication does not need any user interaction. By brute-forcing the NTLMv2 hash (which is expensive, but possible), credentials can be extracted. This issue has been fixed in version 2.53.0.windows.3. — /lib/apk/db/installed | |
| HIGH | CVE-2026-9080 | curl | 8.20.0-r0 | Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed. — /lib/apk/db/installed | |
| HIGH | CVE-2026-4786 | python3 | 3.12.13-r0 | Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. — /lib/apk/db/installed | |
| HIGH | CVE-2026-9545 | curl | 8.20.0-r0 | In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11822 | sqlite-libs | 3.51.2-r0 | SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11824 | sqlite-libs | 3.51.2-r0 | SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5. — /lib/apk/db/installed | |
| HIGH | CVE-2026-7210 | python3 | 3.12.13-r0 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch. — /lib/apk/db/installed | |
| HIGH | CVE-2026-15308 | python3 | 3.12.13-r0 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data. — /lib/apk/db/installed | |
| HIGH | CVE-2026-6100 | python3 | 3.12.13-r0 | Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable. — /lib/apk/db/installed | |
| HIGH | CVE-2026-4224 | python3 | 3.12.13-r0 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11352 | curl | 8.20.0-r0 | An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11586 | curl | 8.20.0-r0 | By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages. — /lib/apk/db/installed | |
| HIGH | CVE-2026-11972 | python3 | 3.12.13-r0 | When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer. — /lib/apk/db/installed | |
| HIGH | CVE-2026-3644 | python3 | 3.12.13-r0 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output(). — /lib/apk/db/installed | |
| HIGH | CVE-2026-9669 | python3 | 3.12.13-r0 | bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data. — /lib/apk/db/installed | |
| HIGH | CVE-2026-3298 | python3 | 3.12.13-r0 | The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-3446 | python3 | 3.12.13-r0 | When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use "validate=True" to enable stricter processing of base64 data. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-6019 | python3 | 3.12.13-r0 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-13837 | python3 | 3.12.13-r0 | When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-12003 | python3 | 3.12.13-r0 | To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree. On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\..', which results in a landmark of '..\..\Modules\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install. Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive. Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources. Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory. The landmark detection involving VPATH is a fallback for when a more specific landmark - .\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-2297 | python3 | 3.12.13-r0 | The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-4360 | python3 | 3.12.13-r0 | In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-0864 | python3 | 3.12.13-r0 | When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-1502 | python3 | 3.12.13-r0 | CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-12781 | python3 | 3.12.13-r0 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alternative base64 alphabet" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues. This behavior can only be insecure if your application uses an alternate base64 alphabet (without "+/"). If your application does not use the "altchars" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet. The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 alphabet they are expecting or verify that their application would not be affected if the b64decode() functions accepted "+" or "/" outside of altchars. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-3276 | python3 | 3.12.13-r0 | unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-8328 | python3 | 3.12.13-r0 | The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-7774 | python3 | 3.12.13-r0 | tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15366 | python3 | 3.12.13-r0 | The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-8458 | curl | 8.20.0-r0 | libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15367 | python3 | 3.12.13-r0 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| LOW | CVE-2026-4519 | python3 | 3.12.13-r0 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open(). — /lib/apk/db/installed | |
| LOW | CVE-2022-3219 | gnupg-dirmngr | 2.4.9-r0 | GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB. — /lib/apk/db/installed | |
| LOW | CVE-2022-3219 | gnupg-gpgconf | 2.4.9-r0 | GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB. — /lib/apk/db/installed | |
| LOW | CVE-2022-3219 | gnupg-keyboxd | 2.4.9-r0 | GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB. — /lib/apk/db/installed | |
| LOW | CVE-2022-3219 | gpg | 2.4.9-r0 | GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB. — /lib/apk/db/installed | |
| LOW | CVE-2026-6879 | python3 | 3.12.13-r0 | `Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end of the sibling list, such as with `[last()]` or `[last()-N]`; `.//item[1]` short-circuits after the first match. — /lib/apk/db/installed | |
| LOW | CVE-2025-13462 | python3 | 3.12.13-r0 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations. — /lib/apk/db/installed | |
| UNKNOWN | CVE-2026-3479 | python3 | 3.12.13-r0 | DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals. — /lib/apk/db/installed |