Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MINI-w39c-2f6g-5j25
  • MinimOS/contour-1.32
See record for full details 2 days ago
  • No fix available
MINI-6mmv-h25v-qrcm
  • MinimOS/contour-1.31
See record for full details 2 days ago
  • No fix available
CLEANSTART-2026-EG39405
  • CleanStart/trino
Netty is an asynchronous, event-driven network application framework 11 Jun
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-BM78291
  • CleanStart/dex
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU 11 Jun
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-SQ76279
  • CleanStart/dex
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU 11 Jun
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-XC13942
  • CleanStart/mountpoint-s3-csi-driver
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service 11 Jun
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-VN16911
  • CleanStart/wave
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label 10 Jun
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-CP20786
  • CleanStart/nats-streaming
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU 10 Jun
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-GZ11549
  • CleanStart/certificate-transparency-trillian-ctserver
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations 10 Jun
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-EU52554
  • CleanStart/gostatsd
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files 10 Jun
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-RF77222
  • CleanStart/wave
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label 10 Jun
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-LA96053
  • CleanStart/wave
ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label 10 Jun
  • Fix available
  • Severity - 9.8 (Critical)
RHSA-2026:23264
  • Red Hat:hummingbird:1/golang1.26
  • Red Hat:hummingbird:1/golang1.26-docs
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update 09 Jun
  • Fix available
  • Severity - 8.2 (High)
RHSA-2026:23262
  • Red Hat:hummingbird:1/golang1.25
  • Red Hat:hummingbird:1/golang1.25-docs
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update 09 Jun
  • Fix available
  • Severity - 8.2 (High)
MINI-649c-24fp-h598
  • MinimOS/logto-1.39
See record for full details 09 Jun
  • Fix available
CLEANSTART-2026-NT30039
  • CleanStart/spire-server-fips
Security fixes for CVE-2025-61727, CVE-2025-61729, CVE-2025-61732, CVE-2025-68121, CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-33811, CVE-2026-33814, CVE-2026-33816, CVE-2026-34986, CVE-2026-39820, CVE-2026-39821, CVE-2026-39823, CVE-2026-39824, CVE-2026-39825, CVE-2026-39826, CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-39836, CVE-2026-41889, CVE-2026-42499, CVE-2026-42502, CVE-2026-42506, CVE-2026-42508, CVE-2026-4659, CVE-2026-46595, CVE-2026-46597, ghsa-273p-m2cw-6833, ghsa-4c4x-jm2x-pf9j, ghsa-4qg8-fj49-pxjh, ghsa-846p-jg2w-w324, ghsa-fcv2-xgw5-pqxf, ghsa-fphv-w9fq-2525, ghsa-jqc5-w2xx-5vq4, ghsa-whqx-f9j3-ch6m, ghsa-xmrv-pmrh-hhx2 applied in versions: 1.13.3-r0, 1.14.1-r0, 1.14.1-r1, 1.14.1-r2, 1.14.5-r0, 1.14.5-r1 08 Jun
  • Fix available