You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.
Search by package name:
my-package (implicit)
name:my-package (explicit)
Search by package filename:
filename:my-package.ext
Search by package tag:
tag:latest
Search by package version:
version:1.0.0
prerelease:true (prereleases)
prerelease:false (no prereleases)
Search by package architecture:
architecture:x86_64
Search by package distribution:
distribution:el
Search by package license:
license:MIT
Search by package format:
format:deb
Search by package status:
status:in_progress
Search by package file checksum:
checksum:5afba
Search by package security status:
severity:critical
Search by package vulnerabilities:
vulnerabilities:>1
vulnerabilities:<1000
Search by # of package downloads:
downloads:>8
downloads:<100
Search by package type:
type:binary
type:source
Search by package size (bytes):
size:>50000
size:<10000
Search by dependency name/version:
dependency:log4j
dependency:log4j=1.0.0
dependency:log4j>1.0.0
Search by uploaded date:
uploaded:>"1 day ago"
uploaded:<"August 14, 2022 EST"
Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY
Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true
Search by repository:
repository:repo-name
Search by last download date:
last_downloaded:<"30 days ago"
last_downloaded:>"August 14, 2022 EST"
Search queries for all Debian-specific (and related) package types
Search by component:
deb_component:unstable
Search queries for all Maven-specific (and related) package types
Search by group ID:
maven_group_id:org.apache
Search queries for all Docker-specific (and related) package types
Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)
Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)
Search queries for all Generic-specific package types
Search by file path:
generic_filepath:path/to/file.txt
Search by directory:
generic_directory:path/to
Field type modifiers (depending on the type, you can influence behaviour)
For all queries, you can use:
~foo for negation
For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching
For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal
Need a secure and centralised artifact repository to deliver Alpine,
Cargo,
CocoaPods,
Composer,
Conan,
Conda,
CRAN,
Dart,
Debian,
Docker,
Generic,
Go,
Helm,
Hex,
HuggingFace,
LuaRocks,
Maven,
MCP,
Nix,
npm,
NuGet,
P2,
Python,
RedHat,
Ruby,
Swift,
Terraform,
Vagrant,
VSX,
Raw & More packages?
Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.
With support for all major package formats, you can trust us to manage your software supply chain.
eventstoredb-ee
24.10.15-experimental-arm64…
One-liner (summary)
Description
| Status | Completed |
|---|---|
| Checksum (MD5) | 23e850858992537b42bfaa09ec91aae0 |
| Checksum (SHA-1) | b2b0a4d645322ea49c85dae773c9c18e378f31e8 |
| Checksum (SHA-256) | 63a0ffc115650d4297b16c5e5f7d185ae371f246eebcace87892b4baaa7479e0 |
| Checksum (SHA-512) | c454e5d124113be11582cc30910bcfc7ae74630a55f4df199f702b525f485c5a2e… |
| GPG Signature | |
| GPG Fingerprint | 69f6921fcf1795d23d007088efec87a4f8f5849d |
| Storage Region | Dublin, Ireland |
| Type | Binary (contains binaries and binary artifacts) |
| Uploaded At | 1 week, 1 day ago |
| Uploaded By |
|
| Slug Id | eventstoredb-ee-gqa1 |
| Unique Id | VE6tEOy8Js4S |
| Version (Raw) | 24.10.15-experimental-arm64-8.0-jammy |
| Version (Parsed) |
|
| Orig Version (Raw) | 63a0ffc115650d4297b16c5e5f7d185ae371f246eebcace87892b4baaa7479e0 |
| Orig Version (Parsed) |
|
| docker-specific metadata | |
| Image Digest | sha256:63a0ffc115650d4297b16c5e5f7d185ae371f246eebcace87892b4baaa7479e0 |
| Config Digest | sha256:1f483d0b805beedc7571aa041ba08d225130188e053b5e07f8f979645acc2343 |
| V1 OCI Index Digest | sha256:ce8f50ff7fe6b17c81d8c96d8cc2910d81a6a1de355ec4b0d236baacc18ff54b |
| V1 Distribution (Signed) Digest | sha256:89083d6cb9475d018f8c6d241f8dd704127cedca4f8c22f5f96ff245580960e4 |
| V1 OCI Digest | sha256:1d829ab757c54177f0ec32aaf3bc65dc4d98ff4119710c7031af71269f515b49 |
| V2 Distribution List Digest | sha256:9d8fa56f6ba4e128bdc08727bbc3ce4e6ab7b76815e653be5fbd363ff5afc822 |
| V1 Distribution Digest | sha256:16cf8da90d776f76432894663f03917715b177b5bc60cf13b54c07454a82a4fd |
| V2 Distribution Digest | sha256:63a0ffc115650d4297b16c5e5f7d185ae371f246eebcace87892b4baaa7479e0 |
| extended metadata | |
| Manifest Type | V2 Distribution |
| Architecture | arm64 |
| Config | |
| Created | 2026-08-18 16:31:59 UTC |
| Os | linux |
This package was uploaded with the following V2 Distribution manifest:
{
"schemaVersion": 2,
"mediaType": "application/vnd.docker.distribution.manifest.v2+json",
"config": {
"mediaType": "application/vnd.docker.container.image.v1+json",
"size": 7126,
"digest": "sha256:62cecfe97fd0247c6d8744624a3429ea2fa534626cb4fb2b4773418bfe0b7614"
},
"layers": [
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 28678455,
"digest": "sha256:4fb046881cf1ec8183c7f1b4e762da2cdec2a3b0ec8a722cfd696d4d67a097a8"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 16573047,
"digest": "sha256:c4a5d3cfb3e4ccbee0afdca7d39829c589d5c297284d3b20a61638717a5f3104"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 3548,
"digest": "sha256:4bf79f3c17e7259f6d7e6169ad5cee4aa739039b9442f0c5ec86e52c54cae6fe"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 52832971,
"digest": "sha256:27dc7e187a8c429b6d17cdffdf50c1912765d52141ccc6842e1bf301efdd149e"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 92711687,
"digest": "sha256:fbf2b6c72a124546f497cc6ba8d8d6a14ab0a514028d7c2b80791deab63a94ec"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 1826368,
"digest": "sha256:a46990bcaa5417b86c009ef939c885f9b8e987a6d126294cac1cad3ad1e7940b"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 32,
"digest": "sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 1852,
"digest": "sha256:bb67812285285668db65775da3006e1a5a4de8cae90d1ff79413ce1d7456e414"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 92715389,
"digest": "sha256:4b4c1039edb42aad9679eeccd3f21cfb57b60ca08f7360ae50806a0f22144e87"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 194,
"digest": "sha256:4009e5e658c791ff09a1fbe04d7b0b45bf3b5796063ba2958778e69d65c82d17"
}
]
}
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG RELEASE |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG LAUNCHPAD_BUILD_ARCH |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL org.opencontainers.image.version=22.04 |
32 bytes | ||
|
Digest:
sha256:4fb046881cf1ec8183c7f1b4e762da2cdec2a3b0ec8a722cfd696d4d67a097a8
Command: /bin/sh -c #(nop) ADD file:c4ec32d39509d0c1acf2ddbb89cdc1fb3ceeae66ef80238f2ba7df53758fb44a in / |
27.3 MB | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) CMD ["/bin/bash"] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV APP_UID=1654 ASPNETCORE_HTTP_PORTS=8080 DOTNET_RUNNING_IN_CONTAINER=true |
32 bytes | ||
|
Digest:
sha256:c4a5d3cfb3e4ccbee0afdca7d39829c589d5c297284d3b20a61638717a5f3104
Command: RUN /bin/sh -c apt-get update && apt-get install -y --no-install-recommends ca-certificates libc6 libgcc-s1 libicu70 libssl3 libstdc++6 tzdata zlib1g && rm -rf /var/lib/apt/lists/* # buildkit |
15.8 MB | ||
|
Digest:
sha256:4bf79f3c17e7259f6d7e6169ad5cee4aa739039b9442f0c5ec86e52c54cae6fe
Command: RUN /bin/sh -c groupadd --gid=$APP_UID app && useradd --no-log-init --uid=$APP_UID --gid=$APP_UID --create-home app # buildkit |
3.5 KB | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG DATABASE_ARCHIVE_DIR=eventstoredb-24.10.15-experimental-ee-linux-arm64.tar.gz |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG UID=1000 |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG GID=1000 |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV LANGUAGE=en_US:en DEBIAN_FRONTEND=noninteractive ACCEPT_EULA=Y |
32 bytes | ||
|
Digest:
sha256:27dc7e187a8c429b6d17cdffdf50c1912765d52141ccc6842e1bf301efdd149e
Command: RUN |3 DATABASE_ARCHIVE_DIR=eventstoredb-24.10.15-experimental-ee-linux-arm64.tar.gz UID=1000 GID=1000 /bin/sh -c apt-get update && apt-get upgrade -y && apt-get clean # buildkit |
50.4 MB | ||
|
Digest:
sha256:fbf2b6c72a124546f497cc6ba8d8d6a14ab0a514028d7c2b80791deab63a94ec
Command: COPY eventstoredb-24.10.15-experimental-ee-linux-arm64.tar.gz /opt/eventstore/ # buildkit |
88.4 MB | ||
|
Digest:
sha256:a46990bcaa5417b86c009ef939c885f9b8e987a6d126294cac1cad3ad1e7940b
Command: RUN |3 DATABASE_ARCHIVE_DIR=eventstoredb-24.10.15-experimental-ee-linux-arm64.tar.gz UID=1000 GID=1000 /bin/sh -c apt update && apt install -y curl && rm -rf /var/lib/apt/lists/* # buildkit |
1.7 MB | ||
|
Digest:
sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1
Command: WORKDIR /opt/eventstore |
32 bytes | ||
|
Digest:
sha256:bb67812285285668db65775da3006e1a5a4de8cae90d1ff79413ce1d7456e414
Command: RUN |3 DATABASE_ARCHIVE_DIR=eventstoredb-24.10.15-experimental-ee-linux-arm64.tar.gz UID=1000 GID=1000 /bin/sh -c addgroup --gid ${GID} "eventstore" && adduser --disabled-password --gecos "" --ingroup "eventstore" --no-create-home --uid ${UID} "eventstore" # buildkit |
1.8 KB | ||
|
Digest:
sha256:4b4c1039edb42aad9679eeccd3f21cfb57b60ca08f7360ae50806a0f22144e87
Command: RUN |3 DATABASE_ARCHIVE_DIR=eventstoredb-24.10.15-experimental-ee-linux-arm64.tar.gz UID=1000 GID=1000 /bin/sh -c mkdir -p /var/lib/eventstore && mkdir -p /var/log/eventstore && mkdir -p /etc/eventstore && chown -R eventstore:eventstore /opt/eventstore /var/lib/eventstore /var/log/eventstore /etc/eventstore # buildkit |
88.4 MB | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: USER eventstore |
32 bytes | ||
|
Digest:
sha256:4009e5e658c791ff09a1fbe04d7b0b45bf3b5796063ba2958778e69d65c82d17
Command: RUN |3 DATABASE_ARCHIVE_DIR=eventstoredb-24.10.15-experimental-ee-linux-arm64.tar.gz UID=1000 GID=1000 /bin/sh -c echo "NodeIp: 0.0.0.0\nReplicationIp: 0.0.0.0" >> /etc/eventstore/eventstore.conf # buildkit |
194 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: VOLUME [/var/lib/eventstore] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: VOLUME [/var/log/eventstore] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE map[1112/tcp:{}] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE map[1113/tcp:{}] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE map[2113/tcp:{}] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: HEALTHCHECK &{["CMD-SHELL" "curl --fail --insecure https://localhost:2113/health/live || curl --fail http://localhost:2113/health/live || exit 1"] "5s" "5s" "0s" "0s" '\x18'} |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/opt/eventstore/eventstored"] |
32 bytes |
|
|
eventstoredb-ee |
1 |
|
|||
| Older |
|
eventstoredb-ee |
8 |
|
||
| Older |
|
eventstoredb-ee |
12 |
|
||
| Older |
|
eventstoredb-ee |
11 |
|
||
| Older |
|
eventstoredb-ee |
15 |
|
||
| Older |
|
eventstoredb-ee |
14 |
|
||
| Older |
|
eventstoredb-ee |
36 |
|
||
| Older |
|
eventstoredb-ee |
12 |
|
||
| Older |
|
eventstoredb-ee |
8 |
|
||
| Older |
|
eventstoredb-ee |
10 |
|
||
| Older |
|
eventstoredb-ee |
14 |
|
||
| Older |
|
eventstoredb-ee |
23 |
|
||
| Older |
|
eventstoredb-ee |
17 |
|
||
| Older |
|
eventstoredb-ee |
10 |
|
||
| Older |
|
eventstoredb-ee |
9 |
|
||
| Older |
|
eventstoredb-ee |
10 |
|
||
| Older |
|
eventstoredb-ee |
9 |
|
||
| Older |
|
eventstoredb-ee |
15 |
|
||
| Older |
|
eventstoredb-ee |
103 |
|
||
| Older |
|
eventstoredb-ee |
81 |
|
Last scanned
1 week, 1 day ago
Scan result
Vulnerable
Vulnerability count
13
Max. severity
High| Target: | VE6tEOy8Js4S.sbom-cyclonedx.json (ubuntu 22.04) | |
| MEDIUM |
CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devicesutil-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.Package Name: bsdutils Installed Version: 1:2.37.2-4ubuntu3.5 Fixed Version: References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devicesutil-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.Package Name: libblkid1 Installed Version: 2.37.2-4ubuntu3.5 Fixed Version: References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devicesutil-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.Package Name: libmount1 Installed Version: 2.37.2-4ubuntu3.5 Fixed Version: References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-13757: p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsingA flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.Package Name: libp11-kit0 Installed Version: 0.24.0-6build1 Fixed Version: References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devicesutil-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.Package Name: libsmartcols1 Installed Version: 2.37.2-4ubuntu3.5 Fixed Version: References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devicesutil-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.Package Name: libuuid1 Installed Version: 2.37.2-4ubuntu3.5 Fixed Version: References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devicesutil-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.Package Name: mount Installed Version: 2.37.2-4ubuntu3.5 Fixed Version: References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-27456: util-linux: TOCTOU in the mount program when setting up loop devicesutil-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.Package Name: util-linux Installed Version: 2.37.2-4ubuntu3.5 Fixed Version: References: cve.mitre.org access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: gcc-12-base Installed Version: 12.3.0-1ubuntu1~22.04.3 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: libgcc-s1 Installed Version: 12.3.0-1ubuntu1~22.04.3 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2024-2236: libgcrypt: vulnerable to Marvin AttackA timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.Package Name: libgcrypt20 Installed Version: 1.9.4-3ubuntu3.2 Fixed Version: References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org dev.gnupg.org errata.almalinux.org errata.rockylinux.org github.com gitlab.com linux.oracle.com linux.oracle.com lists.gnupg.org nvd.nist.gov www.cve.org |
|
| LOW |
CVE-2025-5222: icu: Stack buffer overflow in the SRBRoot::addTag functionA stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.Package Name: libicu70 Installed Version: 70.1-2 Fixed Version: References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com lists.debian.org nvd.nist.gov unicode-org.atlassian.net www.cve.org |
|
| LOW |
CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().Package Name: libncurses6 Installed Version: 6.3-2ubuntu0.2 Fixed Version: References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().Package Name: libncursesw6 Installed Version: 6.3-2ubuntu0.2 Fixed Version: References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2022-41409: pcre2: negative repeat value in a pcre2test subject line leads to inifinite loopInteger overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.Package Name: libpcre2-8-0 Installed Version: 10.39-3ubuntu0.1 Fixed Version: References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org |
|
| LOW |
CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_constlibiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.Package Name: libstdc++6 Installed Version: 12.3.0-1ubuntu1~22.04.3 Fixed Version: References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org |
|
| LOW |
CVE-2026-40228: systemd: systemd-journald: Unintended output to user terminals via logger commandIn systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.Package Name: libsystemd0 Installed Version: 249.11-0ubuntu3.22 Fixed Version: References: www.openwall.com access.redhat.com nvd.nist.gov www.cve.org www.openwall.com |
|
| LOW |
CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().Package Name: libtinfo6 Installed Version: 6.3-2ubuntu0.2 Fixed Version: References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2026-40228: systemd: systemd-journald: Unintended output to user terminals via logger commandIn systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.Package Name: libudev1 Installed Version: 249.11-0ubuntu3.22 Fixed Version: References: www.openwall.com access.redhat.com nvd.nist.gov www.cve.org www.openwall.com |
|
| LOW |
CVE-2022-4899: zstd: mysql: buffer overrun in util.cA vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.Package Name: libzstd1 Installed Version: 1.4.8+dfsg-3build1 Fixed Version: References: access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com github.com github.com linux.oracle.com linux.oracle.com lists.fedoraproject.org lists.fedoraproject.org lists.fedoraproject.org lists.fedoraproject.org lists.fedoraproject.org lists.fedoraproject.org nvd.nist.gov security.netapp.com security.netapp.com www.cve.org |
|
| LOW |
CVE-2023-29383: shadow: Improper input validation in shadow-utils package utility chfnIn Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is not possible to exploit this directly (e.g., adding a new user fails because \n is in the block list), it is possible to misrepresent the /etc/passwd file when viewed. Use of \r manipulations and Unicode characters to work around blocking of the : character make it possible to give the impression that a new user has been added. In other words, an adversary may be able to convince a system administrator to take the system offline (an indirect, social-engineered denial of service) by demonstrating that "cat /etc/passwd" shows a rogue user account.Package Name: login Installed Version: 1:4.8.1-2ubuntu2.2 Fixed Version: References: access.redhat.com github.com github.com lists.debian.org nvd.nist.gov www.cve.org www.trustwave.com www.trustwave.com |
|
| LOW |
CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromiseshadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.Package Name: login Installed Version: 1:4.8.1-2ubuntu2.2 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org |
|
| LOW |
CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().Package Name: ncurses-base Installed Version: 6.3-2ubuntu0.2 Fixed Version: References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().Package Name: ncurses-bin Installed Version: 6.3-2ubuntu0.2 Fixed Version: References: access.redhat.com lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org |
|
| LOW |
CVE-2023-29383: shadow: Improper input validation in shadow-utils package utility chfnIn Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is not possible to exploit this directly (e.g., adding a new user fails because \n is in the block list), it is possible to misrepresent the /etc/passwd file when viewed. Use of \r manipulations and Unicode characters to work around blocking of the : character make it possible to give the impression that a new user has been added. In other words, an adversary may be able to convince a system administrator to take the system offline (an indirect, social-engineered denial of service) by demonstrating that "cat /etc/passwd" shows a rogue user account.Package Name: passwd Installed Version: 1:4.8.1-2ubuntu2.2 Fixed Version: References: access.redhat.com github.com github.com lists.debian.org nvd.nist.gov www.cve.org www.trustwave.com www.trustwave.com |
|
| LOW |
CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromiseshadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.Package Name: passwd Installed Version: 1:4.8.1-2ubuntu2.2 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org |
|
| Target: | opt/eventstore/EventStore.ClusterNode.deps.json | |
| HIGH |
CVE-2025-6965: sqlite: Integer Truncation in SQLiteThere exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.Package Name: SQLitePCLRaw.lib.e_sqlite3 Installed Version: 2.1.6 Fixed Version: References: seclists.org seclists.org seclists.org seclists.org seclists.org www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com cert-portal.siemens.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org www.oracle.com www.sqlite.org |
|
| MEDIUM |
CVE-2026-40894: OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headersOpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application. This vulnerability is fixed in 1.15.3.Package Name: OpenTelemetry.Api Installed Version: 1.4.0-rc.1 Fixed Version: 1.15.3 References: github.com github.com github.com github.com github.com github.com github.com github.com github.com nvd.nist.gov |
|
| Target: | opt/eventstore/EventStore.TestClient.deps.json | |
| HIGH |
CVE-2025-6965: sqlite: Integer Truncation in SQLiteThere exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.Package Name: SQLitePCLRaw.lib.e_sqlite3 Installed Version: 2.1.6 Fixed Version: References: seclists.org seclists.org seclists.org seclists.org seclists.org www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com cert-portal.siemens.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org www.oracle.com www.sqlite.org |
|
| MEDIUM |
CVE-2026-40894: OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headersOpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application. This vulnerability is fixed in 1.15.3.Package Name: OpenTelemetry.Api Installed Version: 1.4.0-rc.1 Fixed Version: 1.15.3 References: github.com github.com github.com github.com github.com github.com github.com github.com github.com nvd.nist.gov |
|
| Target: | opt/eventstore/plugins/EventStore.Auth.StreamPolicyPlugin/EventStore.Auth.StreamPolicyPlugin.deps.json | |
| HIGH |
CVE-2025-6965: sqlite: Integer Truncation in SQLiteThere exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.Package Name: SQLitePCLRaw.lib.e_sqlite3 Installed Version: 2.1.6 Fixed Version: References: seclists.org seclists.org seclists.org seclists.org seclists.org www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com cert-portal.siemens.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org www.oracle.com www.sqlite.org |
|
| MEDIUM |
CVE-2026-40894: OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headersOpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application. This vulnerability is fixed in 1.15.3.Package Name: OpenTelemetry.Api Installed Version: 1.4.0-rc.1 Fixed Version: 1.15.3 References: github.com github.com github.com github.com github.com github.com github.com github.com github.com nvd.nist.gov |
|
| Target: | opt/eventstore/plugins/EventStore.AutoScavengePlugin/EventStore.AutoScavenge.deps.json | |
| HIGH |
CVE-2025-6965: sqlite: Integer Truncation in SQLiteThere exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.Package Name: SQLitePCLRaw.lib.e_sqlite3 Installed Version: 2.1.6 Fixed Version: References: seclists.org seclists.org seclists.org seclists.org seclists.org www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com cert-portal.siemens.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org www.oracle.com www.sqlite.org |
|
| MEDIUM |
CVE-2026-40894: OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headersOpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application. This vulnerability is fixed in 1.15.3.Package Name: OpenTelemetry.Api Installed Version: 1.4.0-rc.1 Fixed Version: 1.15.3 References: github.com github.com github.com github.com github.com github.com github.com github.com github.com nvd.nist.gov |
|
| Target: | opt/eventstore/plugins/EventStore.ConnectedSubsystemsPlugin/EventStore.POC.ConnectedSubsystemsPlugin.deps.json | |
| HIGH |
CVE-2025-6965: sqlite: Integer Truncation in SQLiteThere exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.Package Name: SQLitePCLRaw.lib.e_sqlite3 Installed Version: 2.1.6 Fixed Version: References: seclists.org seclists.org seclists.org seclists.org seclists.org www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com cert-portal.siemens.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org www.oracle.com www.sqlite.org |
|
| MEDIUM |
CVE-2026-40894: OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headersOpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application. This vulnerability is fixed in 1.15.3.Package Name: OpenTelemetry.Api Installed Version: 1.4.0-rc.1 Fixed Version: 1.15.3 References: github.com github.com github.com github.com github.com github.com github.com github.com github.com nvd.nist.gov |
|
| Target: | opt/eventstore/plugins/EventStore.TcpPlugin/EventStore.TcpPlugin.deps.json | |
| HIGH |
CVE-2025-6965: sqlite: Integer Truncation in SQLiteThere exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.Package Name: SQLitePCLRaw.lib.e_sqlite3 Installed Version: 2.1.6 Fixed Version: References: seclists.org seclists.org seclists.org seclists.org seclists.org www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com cert-portal.siemens.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org www.oracle.com www.sqlite.org |
|
| MEDIUM |
CVE-2026-40894: OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headersOpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application. This vulnerability is fixed in 1.15.3.Package Name: OpenTelemetry.Api Installed Version: 1.4.0-rc.1 Fixed Version: 1.15.3 References: github.com github.com github.com github.com github.com github.com github.com github.com github.com nvd.nist.gov |
|
Package statistics are no longer available on cloudsmith.io. Please visit our new web app to access this feature.
You can embed a badge in another website that shows this or the latest version of this package.
To embed the badge for this specific package version, use the following:
[](https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-ee/63a0ffc115650d4297b16c5e5f7d185ae371f246eebcace87892b4baaa7479e0/a=arm64;xpo=linux/)
|This version of 'eventstoredb-ee' @ Cloudsmith|
.. |This version of 'eventstoredb-ee' @ Cloudsmith| image:: https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-ee/24.10.15-experimental-arm64-8.0-jammy/a=arm64;xpo=linux/?render=true
:target: https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-ee/63a0ffc115650d4297b16c5e5f7d185ae371f246eebcace87892b4baaa7479e0/a=arm64;xpo=linux/
image::https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-ee/24.10.15-experimental-arm64-8.0-jammy/a=arm64;xpo=linux/?render=true[link="https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-ee/63a0ffc115650d4297b16c5e5f7d185ae371f246eebcace87892b4baaa7479e0/a=arm64;xpo=linux/",title="This version of 'eventstoredb-ee' @ Cloudsmith"]
<a href="https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-ee/63a0ffc115650d4297b16c5e5f7d185ae371f246eebcace87892b4baaa7479e0/a=arm64;xpo=linux/"><img src="https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-ee/24.10.15-experimental-arm64-8.0-jammy/a=arm64;xpo=linux/?render=true" alt="This version of 'eventstoredb-ee' @ Cloudsmith" /></a>
rendered as:
To embed the badge for the latest package version, use the following:
[](https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-ee/latest/a=arm64;xpo=linux/)
|Latest version of 'eventstoredb-ee' @ Cloudsmith|
.. |Latest version of 'eventstoredb-ee' @ Cloudsmith| image:: https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-ee/latest/a=arm64;xpo=linux/?render=true&show_latest=true
:target: https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-ee/latest/a=arm64;xpo=linux/
image::https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-ee/latest/a=arm64;xpo=linux/?render=true&show_latest=true[link="https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-ee/latest/a=arm64;xpo=linux/",title="Latest version of 'eventstoredb-ee' @ Cloudsmith"]
<a href="https://cloudsmith.io/~eventstore/repos/eventstore-preview/packages/detail/docker/eventstoredb-ee/latest/a=arm64;xpo=linux/"><img src="https://dkr-api.cloudsmith.com/v1/badges/version/eventstore/eventstore-preview/docker/eventstoredb-ee/latest/a=arm64;xpo=linux/?render=true&show_latest=true" alt="Latest version of 'eventstoredb-ee' @ Cloudsmith" /></a>
rendered as:
These instructions assume you have setup the repository first (or read it).
To pull eventstoredb-ee @ reference/tag 4c9f3bee-6307-4816-ac38-77fe49306a95:
docker pull docker.eventstore.com/eventstore-preview/eventstoredb-ee:4c9f3bee-6307-4816-ac38-77fe49306a95
You can also pull the latest version of this image (if it exists):
docker pull docker.eventstore.com/eventstore-preview/eventstoredb-ee:latest
To refer to this image after pulling in a Dockerfile, specify the following:
FROM docker.eventstore.com/eventstore-preview/eventstoredb-ee:4c9f3bee-6307-4816-ac38-77fe49306a95
Note: You should replace 4c9f3bee-6307-4816-ac38-77fe49306a95 with an alternative reference to pull, such as: 24.10.15-experimental-arm64-8.0-jammy.