Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CLEANSTART-2026-VU62737
  • CleanStart/consul-k8s-fips
excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate 26 Feb
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-RD09851
  • CleanStart/prometheus-operator
net/url package does not set a limit on the number of query parameters in a query 25 Feb
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-UK11127
  • CleanStart/spark-operator
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succ... 25 Feb
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-WK32717
  • CleanStart/spark-operator
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succ... 25 Feb
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-PM90259
  • CleanStart/kyverno-policy-reporter-fips
Cancelling a query (e 25 Feb
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-OO47906
  • CleanStart/kafka
Security fixes for GHSA-vc5p-v9hr-52mj applied in versions: 4.1.1-r0 25 Feb
  • Fix available
CLEANSTART-2026-ZS11519
  • CleanStart/kafka-fips
Security fixes for GHSA-vc5p-v9hr-52mj applied in versions: 4.1.1-r0 25 Feb
  • Fix available
CLEANSTART-2026-DS30740
  • CleanStart/argo-workflows-fips
go-git is a highly extensible git implementation library written in pure Go 25 Feb
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-DC27717
  • CleanStart/pritunl
OpenVPN version 2 25 Feb
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-DN18334
  • CleanStart/kubernetes-csi-driver-nfs-fips
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succ... 25 Feb
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-XK29348
  • CleanStart/kubernetes-csi-external-snapshotter-fips
Security fixes for GHSA-f6x5-jh6r-wrfv, GHSA-j5w8-q4qc-rx2x applied in versions: 8.4.0-r0 25 Feb
  • Fix available
CLEANSTART-2026-YQ79300
  • CleanStart/argo-cd
Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate 24 Feb
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-SP64433
  • CleanStart/thingsboard
Security fixes for GHSA-6rw7-vpxm-498p, GHSA-73rr-hh4g-fpgx, GHSA-8qq5-rm4j-mr97 applied in versions: 4.2.1.1-r1 24 Feb
  • Fix available
CLEANSTART-2026-LM41397
  • CleanStart/npm
node-tar is a full-featured Tar for Node 24 Feb
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-LN12820
  • CleanStart/nodejs
vulnerability has been identified in Node 19 Feb
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-KN34553
  • CleanStart/nodejs
vulnerability has been identified in Node 19 Feb
  • Fix available
  • Severity - 9.8 (Critical)