You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.
Search by package name:
my-package (implicit)
name:my-package (explicit)
Search by package filename:
filename:my-package.ext
Search by package tag:
tag:latest
Search by package version:
version:1.0.0
prerelease:true (prereleases)
prerelease:false (no prereleases)
Search by package architecture:
architecture:x86_64
Search by package distribution:
distribution:el
Search by package license:
license:MIT
Search by package format:
format:deb
Search by package status:
status:in_progress
Search by package file checksum:
checksum:5afba
Search by package security status:
severity:critical
Search by package vulnerabilities:
vulnerabilities:>1
vulnerabilities:<1000
Search by # of package downloads:
downloads:>8
downloads:<100
Search by package type:
type:binary
type:source
Search by package size (bytes):
size:>50000
size:<10000
Search by dependency name/version:
dependency:log4j
dependency:log4j=1.0.0
dependency:log4j>1.0.0
Search by uploaded date:
uploaded:>"1 day ago"
uploaded:<"August 14, 2022 EST"
Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY
Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true
Search by repository:
repository:repo-name
Search by last download date:
last_downloaded:<"30 days ago"
last_downloaded:>"August 14, 2022 EST"
Search queries for all Debian-specific (and related) package types
Search by component:
deb_component:unstable
Search queries for all Maven-specific (and related) package types
Search by group ID:
maven_group_id:org.apache
Search queries for all Docker-specific (and related) package types
Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)
Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)
Search queries for all Generic-specific package types
Search by file path:
generic_filepath:path/to/file.txt
Search by directory:
generic_directory:path/to
Field type modifiers (depending on the type, you can influence behaviour)
For all queries, you can use:
~foo for negation
For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching
For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal
Need a secure and centralised artifact repository to deliver Alpine,
Cargo,
CocoaPods,
Composer,
Conan,
Conda,
CRAN,
Dart,
Debian,
Docker,
Generic,
Go,
Helm,
Hex,
HuggingFace,
LuaRocks,
Maven,
MCP,
Nix,
npm,
NuGet,
P2,
Python,
RedHat,
Ruby,
Swift,
Terraform,
Vagrant,
VSX,
Raw & More packages?
Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.
With support for all major package formats, you can trust us to manage your software supply chain.
kurrentdb
26.2.1
One-liner (summary)
Description
| Status | Completed |
|---|---|
| Checksum (MD5) | 9f968ffc0d6f585bb16576081325fa78 |
| Checksum (SHA-1) | 78ddb49d0a53272207c4d2cbef3628ffe130d6fe |
| Checksum (SHA-256) | f3f7de388fd9385d1be664dfda598dbf9a230d14d7066353de97352586e10bc6 |
| Checksum (SHA-512) | 3ade30d6c7de4d6566f22c85540a4126ebecc89b4c8069a69ff875fd96a28030bd… |
| GPG Signature | |
| GPG Fingerprint | 02a89004460aa252035d6b7d094442d90ad50bcd |
| Storage Region | Dublin, Ireland |
| Type | Binary (contains binaries and binary artifacts) |
| Uploaded At | 6 days, 1 hour ago |
| Uploaded By |
|
| Slug Id | kurrentdb-0w2h |
| Unique Id | RS0ejeoZpqq6 |
| Version (Raw) | 26.2.1 |
| Version (Parsed) |
|
| Orig Version (Raw) | f3f7de388fd9385d1be664dfda598dbf9a230d14d7066353de97352586e10bc6 |
| Orig Version (Parsed) |
|
| docker-specific metadata | |
| Image Digest | sha256:f3f7de388fd9385d1be664dfda598dbf9a230d14d7066353de97352586e10bc6 |
| Config Digest | sha256:e2466b5b687ca95dc73a2b39b28b8efb77fa43be7e2dced1bcee33fe9362ed22 |
| V1 OCI Index Digest | sha256:03fc4cdcc81d4d130aaf82f19a6767af32aabeb21d26637b8a6c28b936f792ed |
| V1 Distribution (Signed) Digest | sha256:c9974a06cf596a12b1c00e3175f63129d68157dc42e859ea277e2a5cb5fc0912 |
| V1 OCI Digest | sha256:ab75d8f1299c6260741d5f65938fc3221985d630c24c89d1172c2520151a431a |
| V2 Distribution List Digest | sha256:5d739517c17753d1fdc62a508dc75eee684a7a582728f1e71d1bf8d1a7271888 |
| V1 Distribution Digest | sha256:0df0a205972bed10cd40aa9e98258ced48d5530df650ee8ff9121e665d36731a |
| V2 Distribution Digest | sha256:f3f7de388fd9385d1be664dfda598dbf9a230d14d7066353de97352586e10bc6 |
| extended metadata | |
| Manifest Type | V2 Distribution |
| Architecture | amd64 |
| Config | |
| Created | 2026-10-05 16:03:25 UTC |
| Os | linux |
This package was uploaded with the following V2 Distribution manifest:
{
"schemaVersion": 2,
"mediaType": "application/vnd.docker.distribution.manifest.v2+json",
"config": {
"mediaType": "application/vnd.docker.container.image.v1+json",
"size": 6952,
"digest": "sha256:b5095b24ea2c0cee26781313c177d0eb7c50685e4f3d5dd4835fa8a43658c198"
},
"layers": [
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 30630248,
"digest": "sha256:8e14801291b4460216bf22d63410b92922d16fd0fdfdc50a58224a35c8469045"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 16779051,
"digest": "sha256:cc5f75342e9df50121ed06b98a4c3c1ef540823947e47b876b2bead3d4de22af"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 3568,
"digest": "sha256:371202940c24d6658420d820bcc0cdb5df77c67038777ad559a9206eac8041f4"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 38047670,
"digest": "sha256:3b37617299edb21cad23d450806964014405f7d6a3bbd826b371735288b08bd1"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 2760782,
"digest": "sha256:f1655864467075c74a80e1883a2415085c1602c7f9aceadd6929bae396f923f6"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 1330,
"digest": "sha256:246243b8b62c7df0c922168af62cbfbf6c9515dccf912752927787238d048a35"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 146109793,
"digest": "sha256:d097b18c6cc773074ad6566c9a598409a828c2e9d801abc0fa4a48421736ffb3"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 32,
"digest": "sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 192,
"digest": "sha256:f3d636c78a3e8aca67de1f66554164ef31c123a54390c48aa667ab5c8113951a"
},
{
"mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
"size": 191,
"digest": "sha256:4ed2d959f36cb26ac6eb8dcf018e692ab40d3dc6ca114aaa0f24f04f39206d91"
}
]
}
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG RELEASE |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG LAUNCHPAD_BUILD_ARCH |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL org.opencontainers.image.version=24.04 |
32 bytes | ||
|
Digest:
sha256:8e14801291b4460216bf22d63410b92922d16fd0fdfdc50a58224a35c8469045
Command: /bin/sh -c #(nop) ADD file:7121eb4a5ba391efb4ba9a38c532d1c5dc2d22d276f04e062f357eea36ee62c4 in / |
29.2 MB | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) CMD ["/bin/bash"] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV APP_UID=1654 ASPNETCORE_HTTP_PORTS=8080 DOTNET_RUNNING_IN_CONTAINER=true |
32 bytes | ||
|
Digest:
sha256:cc5f75342e9df50121ed06b98a4c3c1ef540823947e47b876b2bead3d4de22af
Command: RUN /bin/sh -c apt-get update && apt-get install -y --no-install-recommends ca-certificates libc6 libgcc-s1 libicu74 libssl3t64 libstdc++6 tzdata tzdata-legacy && rm -rf /var/lib/apt/lists/* # buildkit |
16.0 MB | ||
|
Digest:
sha256:371202940c24d6658420d820bcc0cdb5df77c67038777ad559a9206eac8041f4
Command: RUN /bin/sh -c groupadd --gid=$APP_UID app && useradd --no-log-init --uid=$APP_UID --gid=$APP_UID --create-home app # buildkit |
3.5 KB | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG DATABASE_ARCHIVE_DIR=kurrentdb-26.2.1-linux-x64.tar.gz |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG UID=1001 |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG GID=1001 |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV LANGUAGE=en_US:en DEBIAN_FRONTEND=noninteractive ACCEPT_EULA=Y |
32 bytes | ||
|
Digest:
sha256:3b37617299edb21cad23d450806964014405f7d6a3bbd826b371735288b08bd1
Command: RUN |3 DATABASE_ARCHIVE_DIR=kurrentdb-26.2.1-linux-x64.tar.gz UID=1001 GID=1001 /bin/sh -c apt-get update && apt-get upgrade -y && apt-get clean # buildkit |
36.3 MB | ||
|
Digest:
sha256:f1655864467075c74a80e1883a2415085c1602c7f9aceadd6929bae396f923f6
Command: RUN |3 DATABASE_ARCHIVE_DIR=kurrentdb-26.2.1-linux-x64.tar.gz UID=1001 GID=1001 /bin/sh -c apt update && apt install -y adduser curl && rm -rf /var/lib/apt/lists/* # buildkit |
2.6 MB | ||
|
Digest:
sha256:246243b8b62c7df0c922168af62cbfbf6c9515dccf912752927787238d048a35
Command: RUN |3 DATABASE_ARCHIVE_DIR=kurrentdb-26.2.1-linux-x64.tar.gz UID=1001 GID=1001 /bin/sh -c addgroup --gid ${GID} "kurrent" && adduser --disabled-password --gecos "" --ingroup "kurrent" --no-create-home --uid ${UID} "kurrent" # buildkit |
1.3 KB | ||
|
Digest:
sha256:d097b18c6cc773074ad6566c9a598409a828c2e9d801abc0fa4a48421736ffb3
Command: COPY --chown=kurrent:kurrent kurrentdb-26.2.1-linux-x64.tar.gz /opt/kurrentdb/ # buildkit |
139.3 MB | ||
|
Digest:
sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1
Command: WORKDIR /opt/kurrentdb |
32 bytes | ||
|
Digest:
sha256:f3d636c78a3e8aca67de1f66554164ef31c123a54390c48aa667ab5c8113951a
Command: RUN |3 DATABASE_ARCHIVE_DIR=kurrentdb-26.2.1-linux-x64.tar.gz UID=1001 GID=1001 /bin/sh -c mkdir -p /var/lib/kurrentdb && mkdir -p /var/log/kurrentdb && mkdir -p /etc/kurrentdb && chown -R kurrent:kurrent /var/lib/kurrentdb /var/log/kurrentdb /etc/kurrentdb # buildkit |
192 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: USER kurrent |
32 bytes | ||
|
Digest:
sha256:4ed2d959f36cb26ac6eb8dcf018e692ab40d3dc6ca114aaa0f24f04f39206d91
Command: RUN |3 DATABASE_ARCHIVE_DIR=kurrentdb-26.2.1-linux-x64.tar.gz UID=1001 GID=1001 /bin/sh -c echo "NodeIp: 0.0.0.0\nReplicationIp: 0.0.0.0" >> /etc/kurrentdb/kurrentdb.conf # buildkit |
191 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: VOLUME [/var/lib/kurrentdb] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: VOLUME [/var/log/kurrentdb] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE map[1112/tcp:{}] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE map[1113/tcp:{}] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: EXPOSE map[2113/tcp:{}] |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: HEALTHCHECK &{["CMD-SHELL" "curl --fail --insecure https://localhost:2113/health/live || curl --fail http://localhost:2113/health/live || exit 1"] "5s" "5s" "0s" "0s" '\x18'} |
32 bytes | ||
|
Digest:
sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/opt/kurrentdb/kurrentd"] |
32 bytes |
| Newer |
|
kurrentdb |
29 |
|
||
|
|
kurrentdb |
30 |
|
|||
| Older |
|
kurrentdb |
44 |
|
||
| Older |
|
kurrentdb |
28 |
|
||
| Older |
|
kurrentdb |
69 |
|
||
| Older |
|
kurrentdb |
154 |
|
||
| Older |
|
kurrentdb |
655 |
|
||
| Older |
|
kurrentdb |
578 |
|
||
| Older |
|
kurrentdb |
30962 |
|
||
| Older |
|
kurrentdb |
17221 |
|
||
| Older |
|
kurrentdb |
5524 |
|
||
| Older |
|
kurrentdb |
5127 |
|
||
| Older |
|
kurrentdb |
19 |
|
||
| Older |
|
kurrentdb |
777 |
|
||
| Older |
|
kurrentdb |
16 |
|
||
| Older |
|
kurrentdb |
13740 |
|
||
| Older |
|
kurrentdb |
20 |
|
||
| Older |
|
kurrentdb |
4442 |
|
||
| Older |
|
kurrentdb |
480 |
|
||
| Older |
|
kurrentdb |
11055 |
|
Last scanned
6 days, 1 hour ago
Scan result
Vulnerable
Vulnerability count
11
Max. severity
High| Target: | RS0ejeoZpqq6.sbom-cyclonedx.json (ubuntu 24.04) | |
| MEDIUM |
CVE-2026-18374: glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode stringPassing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.Package Name: libc-bin Installed Version: 2.39-0ubuntu8.9 Fixed Version: References: www.openwall.com access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org www.cve.org |
|
| MEDIUM |
CVE-2026-89092: glibc: nscd stack overflow leads to degraded DNS resolutionThe nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of this bug needs a system that has nscd enabled and using an untrusted DNS server for name resolution, with the compromised DNS server being capable of processing records large enough to result in a stack overflow in an nscd thread stack. During experimentation, bind 9 was unable to handle large records, but that could change in future or with a different name server. In typical installations, nscd is executed in an isolated context as its own user without a shell, due to which any compromise of that service is isolated. There is a remote possibility of nscd cache corruption if an attacker manages to get the stack pointer into a desired point in the heap, potentially resulting in other caches in nscd being overwritten with corrupt data through the stack overflow, until the buggy code path eventually results in a crash. Finally, a crash in nscd may result in performance degradation when resolving names, but it does not result in a denial of service.Package Name: libc-bin Installed Version: 2.39-0ubuntu8.9 Fixed Version: References: www.openwall.com access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org www.cve.org |
|
| MEDIUM |
CVE-2026-18374: glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode stringPassing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.Package Name: libc6 Installed Version: 2.39-0ubuntu8.9 Fixed Version: References: www.openwall.com access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org www.cve.org |
|
| MEDIUM |
CVE-2026-89092: glibc: nscd stack overflow leads to degraded DNS resolutionThe nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of this bug needs a system that has nscd enabled and using an untrusted DNS server for name resolution, with the compromised DNS server being capable of processing records large enough to result in a stack overflow in an nscd thread stack. During experimentation, bind 9 was unable to handle large records, but that could change in future or with a different name server. In typical installations, nscd is executed in an isolated context as its own user without a shell, due to which any compromise of that service is isolated. There is a remote possibility of nscd cache corruption if an attacker manages to get the stack pointer into a desired point in the heap, potentially resulting in other caches in nscd being overwritten with corrupt data through the stack overflow, until the buggy code path eventually results in a crash. Finally, a crash in nscd may result in performance degradation when resolving names, but it does not result in a denial of service.Package Name: libc6 Installed Version: 2.39-0ubuntu8.9 Fixed Version: References: www.openwall.com access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org www.cve.org |
|
| MEDIUM |
CVE-2026-86145: pcre2: PCRE2: Out-of-bounds write allows arbitrary code execution via crafted regular expressionsPCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).Package Name: libpcre2-8-0 Installed Version: 10.42-4ubuntu2.1 Fixed Version: References: www.openwall.com access.redhat.com github.com github.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-89161: pcre2: PCRE2: Memory corruption vulnerability in pcre2_jit_matchIn PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.Package Name: libpcre2-8-0 Installed Version: 10.42-4ubuntu2.1 Fixed Version: References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-18477: tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escapeA TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.Package Name: tar Installed Version: 1.35+dfsg-3ubuntu0.4 Fixed Version: References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-18508: tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwriteA flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.Package Name: tar Installed Version: 1.35+dfsg-3ubuntu0.4 Fixed Version: References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org |
|
| MEDIUM |
CVE-2026-85091: zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ...zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.Package Name: zlib1g Installed Version: 1:1.3.dfsg-3.1ubuntu2.2 Fixed Version: References: gist.github.com github.com github.com www.cve.org www.vulncheck.com |
|
| LOW |
CVE-2025-5222: icu: Stack buffer overflow in the SRBRoot::addTag functionA stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.Package Name: libicu74 Installed Version: 74.2-1ubuntu3.1 Fixed Version: References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com lists.debian.org nvd.nist.gov unicode-org.atlassian.net www.cve.org |
|
| LOW |
CVE-2026-40228: systemd: systemd-journald: Unintended output to user terminals via logger commandIn systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.Package Name: libsystemd0 Installed Version: 255.4-1ubuntu8.17 Fixed Version: References: www.openwall.com access.redhat.com nvd.nist.gov www.cve.org www.openwall.com |
|
| LOW |
CVE-2026-40228: systemd: systemd-journald: Unintended output to user terminals via logger commandIn systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.Package Name: libudev1 Installed Version: 255.4-1ubuntu8.17 Fixed Version: References: www.openwall.com access.redhat.com nvd.nist.gov www.cve.org www.openwall.com |
|
| LOW |
CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromiseshadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.Package Name: login Installed Version: 1:4.13+dfsg1-4ubuntu3.2 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org |
|
| LOW |
CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromiseshadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.Package Name: passwd Installed Version: 1:4.13+dfsg1-4ubuntu3.2 Fixed Version: References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org |
|
| Target: | opt/kurrentdb/KurrentDB.deps.json | |
| HIGH |
CVE-2025-6965: sqlite: Integer Truncation in SQLiteThere exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.Package Name: SQLitePCLRaw.lib.e_sqlite3 Installed Version: 2.1.11 Fixed Version: References: seclists.org seclists.org seclists.org seclists.org seclists.org www.openwall.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cert-portal.siemens.com cert-portal.siemens.com creativecommons.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov ubuntu.com ubuntu.com www.cve.org www.oracle.com www.sqlite.org |
|
Package statistics are no longer available on cloudsmith.io. Please visit our new web app to access this feature.
You can embed a badge in another website that shows this or the latest version of this package.
To embed the badge for this specific package version, use the following:
[](https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/f3f7de388fd9385d1be664dfda598dbf9a230d14d7066353de97352586e10bc6/a=amd64;xpo=linux/)
|This version of 'kurrentdb' @ Cloudsmith|
.. |This version of 'kurrentdb' @ Cloudsmith| image:: https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/26.2.1/a=amd64;xpo=linux/?render=true
:target: https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/f3f7de388fd9385d1be664dfda598dbf9a230d14d7066353de97352586e10bc6/a=amd64;xpo=linux/
image::https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/26.2.1/a=amd64;xpo=linux/?render=true[link="https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/f3f7de388fd9385d1be664dfda598dbf9a230d14d7066353de97352586e10bc6/a=amd64;xpo=linux/",title="This version of 'kurrentdb' @ Cloudsmith"]
<a href="https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/f3f7de388fd9385d1be664dfda598dbf9a230d14d7066353de97352586e10bc6/a=amd64;xpo=linux/"><img src="https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/26.2.1/a=amd64;xpo=linux/?render=true" alt="This version of 'kurrentdb' @ Cloudsmith" /></a>
rendered as:
To embed the badge for the latest package version, use the following:
[](https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/latest/a=amd64;xpo=linux/)
|Latest version of 'kurrentdb' @ Cloudsmith|
.. |Latest version of 'kurrentdb' @ Cloudsmith| image:: https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/latest/a=amd64;xpo=linux/?render=true&show_latest=true
:target: https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/latest/a=amd64;xpo=linux/
image::https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/latest/a=amd64;xpo=linux/?render=true&show_latest=true[link="https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/latest/a=amd64;xpo=linux/",title="Latest version of 'kurrentdb' @ Cloudsmith"]
<a href="https://cloudsmith.io/~eventstore/repos/kurrent-latest/packages/detail/docker/kurrentdb/latest/a=amd64;xpo=linux/"><img src="https://api-dkr.cloudsmith.com/v1/badges/version/eventstore/kurrent-latest/docker/kurrentdb/latest/a=amd64;xpo=linux/?render=true&show_latest=true" alt="Latest version of 'kurrentdb' @ Cloudsmith" /></a>
rendered as:
These instructions assume you have setup the repository first (or read it).
To pull kurrentdb @ reference/tag 26.2.1:
docker pull docker.eventstore.com/kurrent-latest/kurrentdb:26.2.1
You can also pull the latest version of this image (if it exists):
docker pull docker.eventstore.com/kurrent-latest/kurrentdb:latest
To refer to this image after pulling in a Dockerfile, specify the following:
FROM docker.eventstore.com/kurrent-latest/kurrentdb:26.2.1
Note: You should replace 26.2.1 with an alternative reference to pull, such as: 7bffc341-d4e0-4564-bc81-011c9ac40222 and 26.2.1-x64-10.0-noble.