Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-4hq8-gpf5-8p68
  • Go/github.com/containers/podman
  • Go/github.com/containers/podman/v2
  • Go/github.com/containers/podman/v3
  • Go/github.com/containers/podman/v4
  • Go/github.com/containers/podman/v5
  • ... 1 more
Podman: Malformed Image can trick podman run into leaking host environment variables into the container 11 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-w7c2-w76w-5hmj
  • Go/github.com/cilium/cilium
  • Go/github.com/cilium/ciliumCilium
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces 11 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-w3rp-4cm2-4wgc
  • Go/github.com/ixofoundation/ixo-blockchain
  • Go/github.com/ixofoundation/ixo-blockchain/v3
  • Go/github.com/ixofoundation/ixo-blockchain/v4
  • Go/github.com/ixofoundation/ixo-blockchain/v5
  • Go/github.com/ixofoundation/ixo-blockchain/v6
  • ... 2 more
ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass 12 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-9993-rfwp-rhwf
  • Go/github.com/zitadel/zitadel
ZITADEL: MFA bypass via session reuse in Login V2 13 hours ago
  • Fix available
  • Severity - 8.2 (High)
GHSA-fgmf-7rf8-m6vf
  • Go/github.com/zitadel/zitadel
ZITADEL: Actions V1 sandbox escape: host file read via require() 13 hours ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-xcw9-qmmf-vqxj
  • Go/github.com/amir20/dozzle
Dozzle label filters do not restrict container event and statistics streams 13 hours ago
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-fx76-2j3w-2mx6
  • Go/github.com/containers/podman/v5
podman quadlet install --replace does not fully replace the old file 15 hours ago
  • Fix available
  • Severity - 4.2 (Medium)
GHSA-9wh6-9hq7-9688
  • Go/github.com/klever-io/klever-go
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS yesterday
  • Fix available
  • Severity - 7.0 (High)
GHSA-7c7c-373r-gfjj
  • Go/github.com/klever-io/klever-go
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery yesterday
  • Fix available
  • Severity - 8.4 (High)
GHSA-26r5-4mm2-px5c
  • Go/github.com/klever-io/klever-go
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace yesterday
  • Fix available
  • Severity - 7.1 (High)
GHSA-97cv-x867-6xhm
  • Go/github.com/klever-io/klever-go
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller yesterday
  • Fix available
  • Severity - 8.7 (High)
GHSA-4fwh-wrm6-97xm
  • Go/github.com/klever-io/klever-go
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS) yesterday
  • Fix available
  • Severity - 7.5 (High)
GHSA-9v8p-frvj-2pcm
  • Go/github.com/klever-io/klever-go
Klever-Go: /log controls global node logging yesterday
  • Fix available
  • Severity - 8.6 (High)
GHSA-8fcf-v89g-xpg6
  • Go/Traefik
Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle 2 days ago
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-992g-9cr3-vm5x
  • Go/github.com/hatchet-dev/hatchet
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter 2 days ago
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-9q4h-f4x5-ffq8
  • Go/github.com/hatchet-dev/hatchet
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher 2 days ago
  • Fix available
  • Severity - 3.1 (Low)