Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CLEANSTART-2026-PX76402
  • CleanStart/kubernetes
etcd is a distributed key-value store for the data of a distributed system 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-FT20664
  • CleanStart/step
gRPC-Go is the Go language implementation of gRPC 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-GQ91083
  • CleanStart/victoriametrics-operator-fips
Previously, a channel registered in the mux's chanList is not usable until it is established 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-TF85238
  • CleanStart/cert-manager
OpenTelemetry-Go is the Go implementation of OpenTelemetry 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-XP70950
  • CleanStart/langfuse
Hono is a Web application framework that provides support for any JavaScript runtime 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-NZ56993
  • CleanStart/aws-network-policy-agent
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-DJ05320
  • CleanStart/dynatrace-operator
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2... 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-MK94759
  • CleanStart/trust-manager
Previously, a channel registered in the mux's chanList is not usable until it is established 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-XC26421
  • CleanStart/git-lfs
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-BY91066
  • CleanStart/dynatrace-operator
malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-UV76679
  • CleanStart/dynatrace-operator
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2... 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-HB08666
  • CleanStart/dynatrace-operator
source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2... 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-AJ39907
  • CleanStart/step
gRPC-Go is the Go language implementation of gRPC 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-EG40747
  • CleanStart/step-issuer
Previously, a channel registered in the mux's chanList is not usable until it is established 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-QK25151
  • CleanStart/step-issuer
Previously, a channel registered in the mux's chanList is not usable until it is established 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-RE83921
  • CleanStart/vault-k8s
Previously, a channel registered in the mux's chanList is not usable until it is established 23 hours ago
  • Fix available
  • Severity - 9.8 (Critical)