Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CLEANSTART-2026-NA25366
  • CleanStart/loki
Security fix for ghsa-xmrv-pmrh-hhx2 applied in: loki 3.7.1-r0 14 hours ago
  • Fix available
CLEANSTART-2026-US79386
  • CleanStart/loki
Security fix for ghsa-hfvc-g4fc-pqhx applied in: loki 3.7.1-r0 14 hours ago
  • Fix available
CLEANSTART-2026-QC55250
  • CleanStart/loki
Security fix for ghsa-w8rr-5gcm-pp58 applied in: loki 3.7.1-r0 14 hours ago
  • Fix available
CLEANSTART-2026-EI91095
  • CleanStart/loki
Security fix for ghsa-78h2-9frx-2jm8 applied in: loki 3.7.1-r0 14 hours ago
  • Fix available
CLEANSTART-2026-DU50032
  • CleanStart/loki
OpenTelemetry-Go is the Go implementation of OpenTelemetry 14 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-ZA34964
  • CleanStart/loki
OpenTelemetry-Go is the Go implementation of OpenTelemetry 14 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-NH53620
  • CleanStart/loki
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web To... 14 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-OJ26404
  • CleanStart/loki
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation wou... 14 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-ZW28198
  • CleanStart/loki
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation 14 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-UN89941
  • CleanStart/loki
When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty pa... 14 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-HX71601
  • CleanStart/loki
in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it 14 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-WU91498
  • CleanStart/loki
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh 14 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-SR68419
  • CleanStart/loki
Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh 14 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-TA77263
  • CleanStart/loki
malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop 14 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-WW85548
  • CleanStart/loki
incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs 14 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-UP76614
  • CleanStart/loki
RSA and DSA public key parsers did not enforce size limits on key parameters 14 hours ago
  • Fix available
  • Severity - 9.8 (Critical)