Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
filename:my-package.ext 

Search by package tag:
tag:latest 

Search by package version:
version:1.0.0  prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search by last download date:
last_downloaded:<"30 days ago" 
last_downloaded:>"August 14, 2022 EST" 

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Search queries for all Generic-specific package types

Search by file path:
generic_filepath:path/to/file.txt

Search by directory:
generic_directory:path/to

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Generic, Go, Helm, Hex, HuggingFace, LuaRocks, Maven, MCP, Nix, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, VSX, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial
 Public eventstore eventstore (Kurrent) / kurrent-latest
A certifiably-awesome public package repository curated by Kurrent, hosted by Cloudsmith.

Docker logo kurrentdb-operator  77e0337622d8097af8a6a8df01c…

One-liner (summary)

A certifiably-awesome package curated by ryan-b, hosted by Cloudsmith.

Description

A certifiably-awesome package curated by ryan-b, hosted by Cloudsmith.

License

Unknown

Size

23.6 MB

Downloads

10

Tags

image arm64 linux

Status  Completed
Checksum (MD5) 7a93a408858c2c07db3107055b62b093
Checksum (SHA-1) 4230636b4fa3c2b0d3fe853a6e70213055fa9673
Checksum (SHA-256) 77e0337622d8097af8a6a8df01ccd5f8b900c1eeb8172bebe9f5fb7d6f30c1c9
Checksum (SHA-512) 03f20f9f78ec82f70768b5a846d101cda7a1a7d380d23ac6a2d1d0228afe3b2a86…
GPG Signature
GPG Fingerprint 02a89004460aa252035d6b7d094442d90ad50bcd
Storage Region  Dublin, Ireland
Type  Binary (contains binaries and binary artifacts)
Uploaded At 3 months, 1 week ago
Uploaded By ryan-b
Slug Id kurrentdb-operator-p9tb
Unique Id JnjeLTvomT28
Version (Raw) 77e0337622d8097af8a6a8df01ccd5f8b900c1eeb8172bebe9f5fb7d6f30c1c9
Version (Parsed)
  • Type: Unknown
  docker-specific metadata
Image Digest sha256:77e0337622d8097af8a6a8df01ccd5f8b900c1eeb8172bebe9f5fb7d6f30c1c9
Config Digest sha256:655f128786bacdd50f68cf37532bf4916cbcb1d2cf55209817a04452819f27db
V1 OCI Index Digest sha256:d5904b1a154f7fefb115d912c748b54338c9463e9cdc69178213e09724c810af
V1 Distribution (Signed) Digest sha256:1b72e81d279bf3f54d1ed9e262a936e35455a6058fd17807a90365dc00f8fa6c
V2 Distribution List Digest sha256:38cb2549197f1974cb43949a245dc75a3d792236378e21668e2b531ba03991c4
V2 Distribution Digest sha256:a4fee47fa513bd3cf7158e27d583399be8bbff7da8b6060545d148fa8abf52a0
V1 Distribution Digest sha256:9381a26397933c895fe14a182f8292c71baa5795b1b4fe1537ac65af5b6c3e6f
V1 OCI Digest sha256:77e0337622d8097af8a6a8df01ccd5f8b900c1eeb8172bebe9f5fb7d6f30c1c9
  extended metadata
Manifest Type V1 OCI
Architecture arm64
Config
Created 2026-06-08 21:08:36 UTC
Os linux

This package was uploaded with the following V1 OCI manifest:

{"schemaVersion":2,"mediaType":"application/vnd.oci.image.manifest.v1+json","config":{"mediaType":"application/vnd.oci.image.config.v1+json","digest":"sha256:50262da76eb1f63a67c441d7f5390b7e86ae56834f710cd3a0a1f491f4e26570","size":7187},"layers":[{"mediaType":"application/vnd.oci.image.layer.v1.tar+gzip","digest":"sha256:49a08e075efe34803649ef4d545559f295c0c8248b6f8519126669f9cbd943cf","size":10251985},{"mediaType":"application/vnd.oci.image.layer.v1.tar+gzip","digest":"sha256:9c09a3af1386bec4ef9449118f2fc22de2b98c35b9fad53406d250e9e43c2f41","size":130210},{"mediaType":"application/vnd.oci.image.layer.v1.tar+gzip","digest":"sha256:7aee80ec2c993152223f6dcfa2b07864460b9f65ee9bea1a4f88945c9cf015ef","size":1823},{"mediaType":"application/vnd.oci.image.layer.v1.tar+gzip","digest":"sha256:847b5d1d7bb0f38b8f37ff867562e634eeb3fb58ab5bc862c5772e7c7cf281e0","size":14374351}],"annotations":{"org.opencontainers.image.base.digest":"sha256:6758fb0b2574856b3dda1e28d7dcaa58121c15f2d9bdbdc4fed831ee6821ba42","org.opencontainers.image.base.name":"registry.access.redhat.com/ubi8/ubi-micro:latest","org.opencontainers.image.created":"2026-06-08T21:08:36.782279038Z"}}
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL maintainer="Red Hat, Inc."
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL vendor="Red Hat, Inc."
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL url="https://catalog.redhat.com/en/search?searchType=containers"
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL com.redhat.component="ubi8-micro-container"
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL name="ubi8/ubi-micro"
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL version="8.10"
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL cpe="cpe:/a:redhat:enterprise_linux:8::appstream"
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL distribution-scope="public"
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL com.redhat.license_terms="https://www.redhat.com/en/about/red-hat-end-user-license-agreements#UBI"
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL summary="ubi8 micro image"
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL description="Very small image which doesn't install the package manager."
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL io.k8s.description="Very small image which doesn't install the package manager."
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL io.k8s.display-name="Red Hat Universal Base Image 8 Micro"
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL io.openshift.expose-services=""
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) COPY dir:fd9799a78718081100369429361cd6a5689036a5311244f4191139a2c7fe43d8 in /
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) COPY file:67f65df33ff6c09984969b192c50b78072a88c5655e380e734315d0229c75aa1 in /etc/yum.repos.d/
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) CMD /bin/sh
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) COPY file:518c885a82749a6265363266bee66395b7dce67072656837d42700d947fc7945 in /usr/share/buildinfo/content-sets.json
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) COPY file:518c885a82749a6265363266bee66395b7dce67072656837d42700d947fc7945 in /root/buildinfo/content_manifests/content-sets.json
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) COPY file:41239c9dec87ddd49d6a854a89049a5b371b208b1c94bff88b9cd971834e9337 in /usr/share/buildinfo/labels.json
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) COPY file:41239c9dec87ddd49d6a854a89049a5b371b208b1c94bff88b9cd971834e9337 in /root/buildinfo/labels.json
32 bytes
Digest: sha256:49a08e075efe34803649ef4d545559f295c0c8248b6f8519126669f9cbd943cf
Command: /bin/sh -c #(nop) LABEL "architecture"="aarch64" "vcs-type"="git" "vcs-ref"="068c05e269b913edf886cd5332d22c7278c3193a" "org.opencontainers.image.revision"="068c05e269b913edf886cd5332d22c7278c3193a" "build-date"="2026-05-27T05:19:43Z" "org.opencontainers.image.created"="2026-05-27T05:19:43Z" "release"="1779859061"org.opencontainers.image.revision=068c05e269b913edf886cd5332d22c7278c3193a,org.opencontainers.image.created=2026-05-27T05:19:43Z
9.8 MB
Digest: sha256:9c09a3af1386bec4ef9449118f2fc22de2b98c35b9fad53406d250e9e43c2f41
Command: /bin/sh -c #(nop) COPY file:2a9b5096747a1f9b8ffcbb32a1d3f214fd1c45fa1ab9590aabe89592c8bf36c8 in /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
127.2 KB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG TARGETOS
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG TARGETARCH TARGETOS
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) WORKDIR /
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) USER 65532:65532
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ENTRYPOINT ["/kurrentdb-operator"]
32 bytes
Digest: sha256:7aee80ec2c993152223f6dcfa2b07864460b9f65ee9bea1a4f88945c9cf015ef
Command: /bin/sh -c #(nop) COPY dir:05ab044aa020e1c6d8062ef11ab8b8aa542ca205af43568ba9cf16464d3a4877 in /licenses
1.8 KB
Digest: sha256:847b5d1d7bb0f38b8f37ff867562e634eeb3fb58ab5bc862c5772e7c7cf281e0
Command: /bin/sh -c #(nop) COPY file:5fb6c118be90d22e348c67af031fd0019abd8aa93ccabf3300d2f31b69220fb6 in /kurrentdb-operator
13.7 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL "release"="566ef03e" "name"="kurrentdb-operator" "maintainer"="Kurrent, Inc" "vendor"="Kurrent, Inc" "summary"="The KurrentDB Operator." "description"="Deploys and manages KurrentDB within Kubernetes." "version"="1.6.0"
32 bytes
Docker logo
kurrentdb-operator
image amd64 linux
161 ryan-b
Docker logo
kurrentdb-operator
image arm64 linux
13.3 MB 11 months ago
19 ryan-b
Docker logo
kurrentdb-operator
image amd64 linux
118 ryan-b
Docker logo
kurrentdb-operator
image arm64 linux
20 ryan-b
Docker logo
kurrentdb-operator
image amd64 linux
82 ryan-b
Docker logo
kurrentdb-operator
image amd64 linux
29.2 MB 1 year ago
100 ryan-b
Docker logo
kurrentdb-operator
image arm64 linux
178 chris-channing
Docker logo
kurrentdb-operator
image amd64 linux
105 chris-channing
Docker logo
kurrentdb-operator
image amd64 linux
198 chris-channing
Docker logo
kurrentdb-operator
image arm64 linux
87 chris-channing
Docker logo
kurrentdb-operator
image arm64 linux
10 ryan-b
Docker logo
kurrentdb-operator
image amd64 linux
10 ryan-b
Docker logo
kurrentdb-operator
image amd64 linux
119 ryan-b
Docker logo
kurrentdb-operator
image amd64 linux
408 ryan-b
Docker logo
kurrentdb-operator
image amd64 linux
21.8 MB 10 months ago
62 ryan-b
Docker logo
kurrentdb-operator
image arm64 linux
30 ryan-b
Docker logo
kurrentdb-operator
image arm64 linux
19 ryan-b
Docker logo
kurrentdb-operator
image amd64 linux
18 ryan-b
Docker logo
kurrentdb-operator
image amd64 linux
14.8 MB 11 months ago
214 ryan-b
Docker logo
kurrentdb-operator
image arm64 linux
23 ryan-b

Last scanned

3 months, 1 week ago

Scan result

Vulnerable

Vulnerability count

21

Max. severity

Medium
Target: JnjeLTvomT28.sbom-cyclonedx.json (redhat 8.10)
MEDIUM

CVE-2025-5278: coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

Package Name: coreutils-single
Installed Version: 8.30-17.el8_10
Fixed Version:

References: www.openwall.com www.openwall.com www.openwall.com access.redhat.com bugzilla.redhat.com cgit.git.savannah.gnu.org cgit.git.savannah.gnu.org debbugs.gnu.org nvd.nist.gov security-tracker.debian.org www.cve.org
MEDIUM

CVE-2026-4437: glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.

Package Name: glibc
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org nvd.nist.gov sourceware.org www.cve.org www.openwall.com
MEDIUM

CVE-2026-5435: glibc: glibc: Out-of-bounds write via TSIG record processing

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

Package Name: glibc
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com inbox.sourceware.org inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Package Name: glibc
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com inbox.sourceware.org nvd.nist.gov nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

Package Name: glibc
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-4437: glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.

Package Name: glibc-common
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org nvd.nist.gov sourceware.org www.cve.org www.openwall.com
MEDIUM

CVE-2026-5435: glibc: glibc: Out-of-bounds write via TSIG record processing

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

Package Name: glibc-common
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com inbox.sourceware.org inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Package Name: glibc-common
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com inbox.sourceware.org nvd.nist.gov nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

Package Name: glibc-common
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-4437: glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.

Package Name: glibc-minimal-langpack
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org nvd.nist.gov sourceware.org www.cve.org www.openwall.com
MEDIUM

CVE-2026-5435: glibc: glibc: Out-of-bounds write via TSIG record processing

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

Package Name: glibc-minimal-langpack
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com inbox.sourceware.org inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Package Name: glibc-minimal-langpack
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com inbox.sourceware.org nvd.nist.gov nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

Package Name: glibc-minimal-langpack
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org
LOW

CVE-2026-4438: glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

Package Name: glibc
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org nvd.nist.gov sourceware.org www.cve.org www.openwall.com
LOW

CVE-2026-4438: glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

Package Name: glibc-common
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org nvd.nist.gov sourceware.org www.cve.org www.openwall.com
LOW

CVE-2026-4438: glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

Package Name: glibc-minimal-langpack
Installed Version: 2.28-251.el8_10.37
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org nvd.nist.gov sourceware.org www.cve.org www.openwall.com
LOW

CVE-2018-20657: libiberty: Memory leak in demangle_template function resulting in a denial of service

The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.

Package Name: libgcc
Installed Version: 8.5.0-28.el8_10
Fixed Version:

References: www.securityfocus.com access.redhat.com access.redhat.com gcc.gnu.org linux.oracle.com linux.oracle.com nvd.nist.gov support.f5.com www.cve.org
LOW

CVE-2019-14250: binutils: integer overflow in simple-object-elf.c leads to a heap-based buffer overflow

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.

Package Name: libgcc
Installed Version: 8.5.0-28.el8_10
Fixed Version:

References: lists.opensuse.org lists.opensuse.org lists.opensuse.org lists.opensuse.org lists.opensuse.org www.securityfocus.com access.redhat.com gcc.gnu.org gcc.gnu.org nvd.nist.gov security.gentoo.org security.netapp.com ubuntu.com ubuntu.com ubuntu.com usn.ubuntu.com usn.ubuntu.com www.cve.org
LOW

CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

Package Name: libgcc
Installed Version: 8.5.0-28.el8_10
Fixed Version:

References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org
LOW

CVE-2018-19211: ncurses: Null pointer dereference at function _nc_parse_entry in parse_entry.c

In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.

Package Name: ncurses-base
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: access.redhat.com bugzilla.redhat.com nvd.nist.gov ubuntu.com www.cve.org
LOW

CVE-2020-19185: ncurses: Heap buffer overflow in one_one_mapping function in progs/dump_entry.c:1373

Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Package Name: ncurses-base
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: seclists.org seclists.org seclists.org access.redhat.com github.com nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com www.cve.org
LOW

CVE-2020-19186: ncurses: Buffer overflow in _nc_find_entry function in tinfo/comp_hash.c:66

Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Package Name: ncurses-base
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: seclists.org seclists.org seclists.org access.redhat.com github.com nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com www.cve.org
LOW

CVE-2020-19187: ncurses: Heap buffer overflow in fmt_entry function in progs/dump_entry.c:1100

Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Package Name: ncurses-base
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: seclists.org seclists.org seclists.org access.redhat.com github.com nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com www.cve.org
LOW

CVE-2020-19188: ncurses: Stack buffer overflow in fmt_entry function in progs/dump_entry.c:1116

Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Package Name: ncurses-base
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: seclists.org seclists.org seclists.org access.redhat.com github.com nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com www.cve.org
LOW

CVE-2020-19189: ncurses: Heap buffer overflow in postprocess_terminfo function in tinfo/parse_entry.c:997

Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Package Name: ncurses-base
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: seclists.org seclists.org seclists.org access.redhat.com github.com lists.debian.org nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com ubuntu.com www.cve.org
LOW

CVE-2020-19190: ncurses: Heap buffer overflow in _nc_find_entry in tinfo/comp_hash.c:70

Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Package Name: ncurses-base
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: seclists.org seclists.org seclists.org access.redhat.com github.com nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com www.cve.org
LOW

CVE-2021-39537: ncurses: heap-based buffer overflow in _nc_captoinfo() in captoinfo.c

An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

Package Name: ncurses-base
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: cvsweb.netbsd.org seclists.org seclists.org seclists.org seclists.org access.redhat.com lists.debian.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com ubuntu.com ubuntu.com www.cve.org
LOW

CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

Package Name: ncurses-base
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: access.redhat.com lists.fedoraproject.org lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org
LOW

CVE-2018-19211: ncurses: Null pointer dereference at function _nc_parse_entry in parse_entry.c

In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.

Package Name: ncurses-libs
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: access.redhat.com bugzilla.redhat.com nvd.nist.gov ubuntu.com www.cve.org
LOW

CVE-2020-19185: ncurses: Heap buffer overflow in one_one_mapping function in progs/dump_entry.c:1373

Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Package Name: ncurses-libs
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: seclists.org seclists.org seclists.org access.redhat.com github.com nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com www.cve.org
LOW

CVE-2020-19186: ncurses: Buffer overflow in _nc_find_entry function in tinfo/comp_hash.c:66

Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Package Name: ncurses-libs
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: seclists.org seclists.org seclists.org access.redhat.com github.com nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com www.cve.org
LOW

CVE-2020-19187: ncurses: Heap buffer overflow in fmt_entry function in progs/dump_entry.c:1100

Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Package Name: ncurses-libs
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: seclists.org seclists.org seclists.org access.redhat.com github.com nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com www.cve.org
LOW

CVE-2020-19188: ncurses: Stack buffer overflow in fmt_entry function in progs/dump_entry.c:1116

Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Package Name: ncurses-libs
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: seclists.org seclists.org seclists.org access.redhat.com github.com nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com www.cve.org
LOW

CVE-2020-19189: ncurses: Heap buffer overflow in postprocess_terminfo function in tinfo/parse_entry.c:997

Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Package Name: ncurses-libs
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: seclists.org seclists.org seclists.org access.redhat.com github.com lists.debian.org nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com ubuntu.com www.cve.org
LOW

CVE-2020-19190: ncurses: Heap buffer overflow in _nc_find_entry in tinfo/comp_hash.c:70

Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Package Name: ncurses-libs
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: seclists.org seclists.org seclists.org access.redhat.com github.com nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com www.cve.org
LOW

CVE-2021-39537: ncurses: heap-based buffer overflow in _nc_captoinfo() in captoinfo.c

An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.

Package Name: ncurses-libs
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: cvsweb.netbsd.org seclists.org seclists.org seclists.org seclists.org access.redhat.com lists.debian.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com support.apple.com support.apple.com support.apple.com ubuntu.com ubuntu.com www.cve.org
LOW

CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

Package Name: ncurses-libs
Installed Version: 6.1-10.20180224.el8
Fixed Version:

References: access.redhat.com lists.fedoraproject.org lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org
LOW

CVE-2022-41409: pcre2: negative repeat value in a pcre2test subject line leads to inifinite loop

Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.

Package Name: pcre2
Installed Version: 10.32-3.el8_6
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
Target: kurrentdb-operator
MEDIUM

CVE-2025-47914: golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages

SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.

Package Name: golang.org/x/crypto
Installed Version: v0.42.0
Fixed Version: 0.45.0

References: access.redhat.com go.dev go.dev go.googlesource.com groups.google.com nvd.nist.gov pkg.go.dev www.cve.org
MEDIUM

CVE-2025-58181: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

Package Name: golang.org/x/crypto
Installed Version: v0.42.0
Fixed Version: 0.45.0

References: access.redhat.com github.com github.com go.dev go.dev groups.google.com groups.google.com nvd.nist.gov pkg.go.dev ubuntu.com www.cve.org

These instructions assume you have setup the repository first (or read it).

To pull kurrentdb-operator @ reference/tag sha256:77e0337622d8097af8a6a8df01ccd5f8b900c1eeb8172bebe9f5fb7d6f30c1c9:

docker pull docker.eventstore.com/kurrent-latest/kurrentdb-operator@sha256:77e0337622d8097af8a6a8df01ccd5f8b900c1eeb8172bebe9f5fb7d6f30c1c9

You can also pull the latest version of this image (if it exists):

docker pull docker.eventstore.com/kurrent-latest/kurrentdb-operator:latest

To refer to this image after pulling in a Dockerfile, specify the following:

FROM docker.eventstore.com/kurrent-latest/kurrentdb-operator@sha256:77e0337622d8097af8a6a8df01ccd5f8b900c1eeb8172bebe9f5fb7d6f30c1c9
Top