Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
filename:my-package.ext 

Search by package tag:
tag:latest 

Search by package version:
version:1.0.0  prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search by last download date:
last_downloaded:<"30 days ago" 
last_downloaded:>"August 14, 2022 EST" 

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Search queries for all Generic-specific package types

Search by file path:
generic_filepath:path/to/file.txt

Search by directory:
generic_directory:path/to

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Generic, Go, Helm, Hex, HuggingFace, LuaRocks, Maven, MCP, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, VSX, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial
 Public tetrate tetrate (Tetrate) / getistio-containers
Tetrate Istio Distro project (formerly GetIstio) container images registry

Docker logo proxyv2  dd0d092f7f6007ba3a80bbebb7e…

One-liner (summary)

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

Description

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

License

Unknown

Size

55.7 MB

Downloads

1

Tags

image arm64 linux

Status  Completed
Checksum (MD5) 0d458631c122398c89bf1fc0e4b41c47
Checksum (SHA-1) 8470c0a6ff3e2a8431e90e4e067a1324f5563a4c
Checksum (SHA-256) dd0d092f7f6007ba3a80bbebb7eca24eee783f457e00c1ca46dc5cb12d9ebaf5
Checksum (SHA-512) b02c81d546b41305fe0faae6a8860855ba91b2edc2f7ade4639b1136e28738486f…
GPG Signature
GPG Fingerprint 7490c226a7c21a19bb1d09e800b3a57eef287d7b
Storage Region  Dublin, Ireland
Type  Binary (contains binaries and binary artifacts)
Uploaded At 1 month ago
Uploaded By tetrate-ci
Slug Id proxyv2-72ht
Unique Id uk6ov5Y31u2W
Version (Raw) dd0d092f7f6007ba3a80bbebb7eca24eee783f457e00c1ca46dc5cb12d9ebaf5
Version (Parsed)
  • Type: Unknown
  docker-specific metadata
Image Digest sha256:dd0d092f7f6007ba3a80bbebb7eca24eee783f457e00c1ca46dc5cb12d9ebaf5
Config Digest sha256:401b34a84deafc8d03305383a2dffee201d1c7ae987094ed3ce8e62f774c7ee1
V1 OCI Index Digest sha256:4a6db05c7d37a3026ac6d48b896a7688ba10d429a2caed6d6fdc8be004fa8a3a
V1 Distribution (Signed) Digest sha256:0803119e2991dadbc61d849df8eb297089e6d5ca6c93a040050bb026e3d58090
V1 OCI Digest sha256:bb3789c37b2a4c379f64ee0a0e7686f4f52aa4350c8ef02117f218bcba6ecd99
V2 Distribution List Digest sha256:2511d1918fd13e85864e6e057879d22be0709578072fddde03fb634258152e0b
V1 Distribution Digest sha256:a92ea3e345638d1201ae4667fbbdacdefd9059ed5ed9ecfe9fa98c40c4c0be1b
V2 Distribution Digest sha256:dd0d092f7f6007ba3a80bbebb7eca24eee783f457e00c1ca46dc5cb12d9ebaf5
  extended metadata
Manifest Type V2 Distribution
Architecture arm64
Config
Created 2026-06-04 11:42:21 UTC
Os linux

This package was uploaded with the following V2 Distribution manifest:

{"schemaVersion":2,"mediaType":"application/vnd.docker.distribution.manifest.v2+json","config":{"mediaType":"application/vnd.docker.container.image.v1+json","size":2758,"digest":"sha256:f9cec12da2b2afbcc0779dc414828aca31cf11f1379fe099a182730470b4bd6c"},"layers":[{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":8324538,"digest":"sha256:9d7471770043bae90f0f16c78d67c4d10ec14994525e7791123857c78cf939dd"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":5046,"digest":"sha256:5117fe369a1b6810742b3eb6b868d7fb2e07c78082dd210879b7685df8a3e205"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":40539441,"digest":"sha256:e3fd15d81a43341c29f5443bf1434446a7f4c77772747377f26da8bfc0b6044e"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":9524374,"digest":"sha256:b81ddecf768ead6f89a7a317603d71f51462a1b1651e3e5a22d8129cf3e3e35b"}]}
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG MICRO
32 bytes
Digest: sha256:9d7471770043bae90f0f16c78d67c4d10ec14994525e7791123857c78cf939dd
Command: COPY /micro . # buildkit
7.9 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: WORKDIR /
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG proxy_version
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG SIDECAR=envoy
32 bytes
Digest: sha256:5117fe369a1b6810742b3eb6b868d7fb2e07c78082dd210879b7685df8a3e205
Command: COPY envoy_bootstrap.json /var/lib/istio/envoy/envoy_bootstrap_tmpl.json # buildkit
4.9 KB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG TARGETARCH
32 bytes
Digest: sha256:e3fd15d81a43341c29f5443bf1434446a7f4c77772747377f26da8bfc0b6044e
Command: COPY arm64/envoy /usr/local/bin/envoy # buildkit
38.7 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV ISTIO_META_ISTIO_PROXY_SHA=af293e34216afc2d902062b596d313fa9e1d6804
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG TARGETARCH
32 bytes
Digest: sha256:b81ddecf768ead6f89a7a317603d71f51462a1b1651e3e5a22d8129cf3e3e35b
Command: COPY arm64/pilot-agent /usr/local/bin/pilot-agent # buildkit
9.1 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/local/bin/pilot-agent"]
32 bytes
Docker logo
proxyv2
image amd64 linux
1 tetrate-ci
Docker logo
proxyv2
image arm64 linux
8928 tetrate-ci
Docker logo
proxyv2
image amd64 linux
3 tetrate-ci
Docker logo
proxyv2
image amd64 linux
2 tetrate-ci
Docker logo
proxyv2
image arm64 linux
2 tetrate-ci
Docker logo
proxyv2
image arm64 linux
2 tetrate-ci
Docker logo
proxyv2
image amd64 linux
2 tetrate-ci
Docker logo
proxyv2
image arm64 linux
23696 tetrate-ci
Docker logo
proxyv2
image arm64 linux
55.7 MB 3 months ago
2 tetrate-ci
Docker logo
proxyv2
image amd64 linux
56.3 MB 3 months ago
2 tetrate-ci
Docker logo
proxyv2
image arm64 linux
55.7 MB 1 month ago
1 tetrate-ci
Docker logo
proxyv2
new image amd64 linux
59.5 MB 19 hours ago
0 tetrate-ci
Docker logo
proxyv2
new image amd64 linux
58.5 MB 19 hours ago
0 tetrate-ci
Docker logo
proxyv2
new image arm64 linux
57.8 MB 19 hours ago
0 tetrate-ci
Docker logo
proxyv2
new image amd64 linux
132.3 MB 19 hours ago
0 tetrate-ci
Docker logo
proxyv2
new image arm64 linux
132.7 MB 19 hours ago
0 tetrate-ci
Docker logo
proxyv2
image amd64 linux
0 tetrate-ci
Docker logo
proxyv2
image amd64 linux
130.4 MB 1 day, 1 hour ago
1 tetrate-ci
Docker logo
proxyv2
image arm64 linux
130.8 MB 1 day, 1 hour ago
1 tetrate-ci
Docker logo
proxyv2
image amd64 linux
0 tetrate-ci

Last scanned

1 month ago

Scan result

Vulnerable

Vulnerability count

42

Max. severity

Critical
Target: uk6ov5Y31u2W.sbom-cyclonedx.json (redhat 9.7)
HIGH

CVE-2026-4878: libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.

Package Name: libcap
Installed Version: 2.48-10.el9
Fixed Version: 2.48-10.el9_8.1

References: www.openwall.com www.openwall.com www.openwall.com www.openwall.com www.openwall.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com linux.oracle.com linux.oracle.com nvd.nist.gov sites.google.com ubuntu.com www.cve.org
MEDIUM

CVE-2025-5278: coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

Package Name: coreutils-single
Installed Version: 8.32-39.el9
Fixed Version:

References: www.openwall.com www.openwall.com www.openwall.com access.redhat.com bugzilla.redhat.com cgit.git.savannah.gnu.org cgit.git.savannah.gnu.org debbugs.gnu.org nvd.nist.gov security-tracker.debian.org www.cve.org
MEDIUM

CVE-2026-0915: glibc: glibc: Information disclosure via zero-valued network query

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.

Package Name: glibc
Installed Version: 2.34-231.el9_7.2
Fixed Version: 2.34-231.el9_7.10

References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov sourceware.org ubuntu.com www.cve.org www.openwall.com
MEDIUM

CVE-2026-4046: glibc: glibc: Denial of Service via iconv() function with specific character sets

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.

Package Name: glibc
Installed Version: 2.34-231.el9_7.2
Fixed Version: 2.34-270.el9_8

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org inbox.sourceware.org linux.oracle.com linux.oracle.com nvd.nist.gov packages.fedoraproject.org sourceware.org sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-4437: glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.

Package Name: glibc
Installed Version: 2.34-231.el9_7.2
Fixed Version: 2.34-270.el9_8

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org nvd.nist.gov sourceware.org www.cve.org www.openwall.com
MEDIUM

CVE-2026-5435: glibc: glibc: Out-of-bounds write via TSIG record processing

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

Package Name: glibc
Installed Version: 2.34-231.el9_7.2
Fixed Version:

References: access.redhat.com inbox.sourceware.org inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Package Name: glibc
Installed Version: 2.34-231.el9_7.2
Fixed Version:

References: access.redhat.com inbox.sourceware.org nvd.nist.gov nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

Package Name: glibc
Installed Version: 2.34-231.el9_7.2
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-6238: glibc: glibc: Application crash or uninitialized memory read via crafted DNS response

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in a DNS response when processing LOC, CERT, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

Package Name: glibc
Installed Version: 2.34-231.el9_7.2
Fixed Version:

References: access.redhat.com inbox.sourceware.org inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-4046: glibc: glibc: Denial of Service via iconv() function with specific character sets

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.

Package Name: glibc-common
Installed Version: 2.34-231.el9_7.2
Fixed Version: 2.34-270.el9_8

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org inbox.sourceware.org linux.oracle.com linux.oracle.com nvd.nist.gov packages.fedoraproject.org sourceware.org sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-4437: glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.

Package Name: glibc-common
Installed Version: 2.34-231.el9_7.2
Fixed Version: 2.34-270.el9_8

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org nvd.nist.gov sourceware.org www.cve.org www.openwall.com
MEDIUM

CVE-2026-5435: glibc: glibc: Out-of-bounds write via TSIG record processing

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

Package Name: glibc-common
Installed Version: 2.34-231.el9_7.2
Fixed Version:

References: access.redhat.com inbox.sourceware.org inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Package Name: glibc-common
Installed Version: 2.34-231.el9_7.2
Fixed Version:

References: access.redhat.com inbox.sourceware.org nvd.nist.gov nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

Package Name: glibc-common
Installed Version: 2.34-231.el9_7.2
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-6238: glibc: glibc: Application crash or uninitialized memory read via crafted DNS response

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in a DNS response when processing LOC, CERT, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

Package Name: glibc-common
Installed Version: 2.34-231.el9_7.2
Fixed Version:

References: access.redhat.com inbox.sourceware.org inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-4046: glibc: glibc: Denial of Service via iconv() function with specific character sets

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.

Package Name: glibc-minimal-langpack
Installed Version: 2.34-231.el9_7.2
Fixed Version: 2.34-270.el9_8

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org inbox.sourceware.org linux.oracle.com linux.oracle.com nvd.nist.gov packages.fedoraproject.org sourceware.org sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-4437: glibc: glibc: Incorrect DNS response parsing via crafted DNS server response

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.

Package Name: glibc-minimal-langpack
Installed Version: 2.34-231.el9_7.2
Fixed Version: 2.34-270.el9_8

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org nvd.nist.gov sourceware.org www.cve.org www.openwall.com
MEDIUM

CVE-2026-5435: glibc: glibc: Out-of-bounds write via TSIG record processing

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

Package Name: glibc-minimal-langpack
Installed Version: 2.34-231.el9_7.2
Fixed Version:

References: access.redhat.com inbox.sourceware.org inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org
MEDIUM

CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Package Name: glibc-minimal-langpack
Installed Version: 2.34-231.el9_7.2
Fixed Version:

References: access.redhat.com inbox.sourceware.org nvd.nist.gov nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

Package Name: glibc-minimal-langpack
Installed Version: 2.34-231.el9_7.2
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-6238: glibc: glibc: Application crash or uninitialized memory read via crafted DNS response

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in a DNS response when processing LOC, CERT, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

Package Name: glibc-minimal-langpack
Installed Version: 2.34-231.el9_7.2
Fixed Version:

References: access.redhat.com inbox.sourceware.org inbox.sourceware.org nvd.nist.gov sourceware.org sourceware.org www.cve.org
LOW

CVE-2025-15281: glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

Package Name: glibc
Installed Version: 2.34-231.el9_7.2
Fixed Version: 2.34-231.el9_7.10

References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov sourceware.org ubuntu.com www.cve.org www.openwall.com
LOW

CVE-2026-0861: glibc: Integer overflow in memalign leads to heap corruption

Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this. The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument. This limits the malicious inputs for the alignment for memalign to the range [1<<62+ 1, 1<<63] and exactly 1<<63 for posix_memalign and aligned_alloc. Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice. An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.

Package Name: glibc
Installed Version: 2.34-231.el9_7.2
Fixed Version: 2.34-231.el9_7.10

References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov sourceware.org sourceware.org ubuntu.com www.cve.org
LOW

CVE-2026-4438: glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

Package Name: glibc
Installed Version: 2.34-231.el9_7.2
Fixed Version: 2.34-270.el9_8

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org nvd.nist.gov sourceware.org www.cve.org www.openwall.com
LOW

CVE-2026-4438: glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

Package Name: glibc-common
Installed Version: 2.34-231.el9_7.2
Fixed Version: 2.34-270.el9_8

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org nvd.nist.gov sourceware.org www.cve.org www.openwall.com
LOW

CVE-2026-4438: glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

Package Name: glibc-minimal-langpack
Installed Version: 2.34-231.el9_7.2
Fixed Version: 2.34-270.el9_8

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org nvd.nist.gov sourceware.org www.cve.org www.openwall.com
LOW

CVE-2021-46195: gcc: uncontrolled recursion in libiberty/rust-demangle.c

GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.

Package Name: libgcc
Installed Version: 11.5.0-11.el9
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com errata.almalinux.org gcc.gnu.org gcc.gnu.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
LOW

CVE-2022-27943: binutils: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack exhaustion in demangle_const

libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

Package Name: libgcc
Installed Version: 11.5.0-11.el9
Fixed Version:

References: access.redhat.com gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org gcc.gnu.org lists.fedoraproject.org nvd.nist.gov sourceware.org www.cve.org
LOW

CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

Package Name: ncurses-base
Installed Version: 6.2-12.20210508.el9
Fixed Version:

References: access.redhat.com lists.fedoraproject.org lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org
LOW

CVE-2023-50495: ncurses: segmentation fault via _nc_wrap_entry()

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

Package Name: ncurses-libs
Installed Version: 6.2-12.20210508.el9
Fixed Version:

References: access.redhat.com lists.fedoraproject.org lists.fedoraproject.org lists.gnu.org lists.gnu.org nvd.nist.gov security.netapp.com ubuntu.com www.cve.org
LOW

CVE-2022-41409: pcre2: negative repeat value in a pcre2test subject line leads to inifinite loop

Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.

Package Name: pcre2
Installed Version: 10.40-6.el9
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
LOW

CVE-2022-41409: pcre2: negative repeat value in a pcre2test subject line leads to inifinite loop

Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.

Package Name: pcre2-syntax
Installed Version: 10.40-6.el9
Fixed Version:

References: access.redhat.com github.com github.com github.com nvd.nist.gov www.cve.org
Target: usr/local/bin/pilot-agent
CRITICAL

CVE-2026-33186: google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, "deny" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback "allow" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific "deny" rules for canonical paths but allows other requests by default (a fallback "allow" rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not start with a leading slash is immediately rejected with a `codes.Unimplemented` error, preventing it from reaching authorization interceptors or handlers with a non-canonical path string. While upgrading is the most secure and recommended path, users can mitigate the vulnerability using one of the following methods: Use a validating interceptor (recommended mitigation); infrastructure-level normalization; and/or policy hardening.

Package Name: google.golang.org/grpc
Installed Version: v1.75.1
Fixed Version: 1.79.3

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com nvd.nist.gov www.cve.org
HIGH

CVE-2025-15558: docker/cli: Docker CLI for Windows: Privilege escalation via malicious plugin binaries

Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are executed when a victim user opens Docker Desktop or invokes Docker CLI plugin features, and allow privilege-escalation if the docker CLI is executed as a privileged user. This issue affects Docker CLI: through 29.1.5 and Windows binaries acting as a CLI-plugin manager using the github.com/docker/cli/cli-plugins/manager https://pkg.go.dev/github.com/docker/cli@v29.1.5+incompatible/cli-plugins/manager  package, such as Docker Compose. This issue does not impact non-Windows binaries, and projects not using the plugin-manager code.

Package Name: github.com/docker/cli
Installed Version: v28.3.3+incompatible
Fixed Version: 29.2.0

References: access.redhat.com docs.docker.com docs.docker.com github.com github.com github.com github.com github.com nvd.nist.gov www.cve.org www.zerodayinitiative.com www.zerodayinitiative.com
HIGH

CVE-2026-34986: github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reachable by calling cipher.KeyUnwrap() directly with any ciphertext parameter less than 16 bytes long, but calling this function directly is less common. Panics can lead to denial of service. This vulnerability is fixed in 4.1.4 and 3.0.5.

Package Name: github.com/go-jose/go-jose/v4
Installed Version: v4.1.2
Fixed Version: 4.1.4

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov pkg.go.dev www.cve.org
HIGH

CVE-2026-29181: github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Denial of Service via crafted multi-value baggage headers

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.

Package Name: go.opentelemetry.io/otel
Installed Version: v1.37.0
Fixed Version: 1.41.0

References: access.redhat.com github.com github.com github.com github.com github.com nvd.nist.gov www.cve.org
HIGH

CVE-2026-24051: OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking

OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.

Package Name: go.opentelemetry.io/otel/sdk
Installed Version: v1.37.0
Fixed Version: 1.40.0

References: github.com github.com github.com nvd.nist.gov pkg.go.dev
HIGH

CVE-2026-39883: github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/Solaris

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.

Package Name: go.opentelemetry.io/otel/sdk
Installed Version: v1.37.0
Fixed Version: 1.43.0

References: github.com access.redhat.com github.com github.com nvd.nist.gov www.cve.org
HIGH

CVE-2026-25679: net/url: Incorrect parsing of IPv6 host literals in net/url

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.8, 1.26.1

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org go.dev go.dev groups.google.com linux.oracle.com linux.oracle.com nvd.nist.gov pkg.go.dev www.cve.org
HIGH

CVE-2026-32280: crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.9, 1.26.2

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org go.dev go.dev groups.google.com linux.oracle.com linux.oracle.com nvd.nist.gov pkg.go.dev www.cve.org
HIGH

CVE-2026-32281: crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.9, 1.26.2

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org go.dev go.dev groups.google.com nvd.nist.gov pkg.go.dev www.cve.org
HIGH

CVE-2026-32283: crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.9, 1.26.2

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org go.dev go.dev groups.google.com linux.oracle.com linux.oracle.com nvd.nist.gov pkg.go.dev www.cve.org
HIGH

CVE-2026-33811: net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.10, 1.26.3

References: access.redhat.com go.dev go.dev groups.google.com linux.oracle.com linux.oracle.com nvd.nist.gov pkg.go.dev www.cve.org
HIGH

CVE-2026-33814: When processing HTTP/2 SETTINGS frames, transport will enter an infini ...

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.10, 1.26.3

References: github.com go-review.googlesource.com go-review.googlesource.com go.dev go.dev go.dev groups.google.com linux.oracle.com linux.oracle.com nvd.nist.gov pkg.go.dev ubuntu.com www.cve.org
HIGH

CVE-2026-39820: Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.10, 1.26.3

References: go.dev go.dev groups.google.com linux.oracle.com linux.oracle.com nvd.nist.gov pkg.go.dev
HIGH

CVE-2026-39823: CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ...

CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.10, 1.26.3

References: go.dev go.dev groups.google.com linux.oracle.com linux.oracle.com nvd.nist.gov pkg.go.dev
HIGH

CVE-2026-39825: ReverseProxy can forward queries containing parameters not visible to ...

ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query "a1=x&a2=x&...&a10000=x&hidden=y" can forward the parameter "hidden=y" while hiding it from the proxy's Rewrite function.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.10, 1.26.3

References: go.dev go.dev groups.google.com linux.oracle.com linux.oracle.com nvd.nist.gov pkg.go.dev
HIGH

CVE-2026-39836: ELSA-2026-22112: go-toolset:ol8 security update (IMPORTANT)

The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.10, 1.26.3

References: go.dev go.dev groups.google.com linux.oracle.com linux.oracle.com nvd.nist.gov pkg.go.dev
HIGH

CVE-2026-42499: Pathological inputs could cause DoS through consumePhrase when parsing ...

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.10, 1.26.3

References: go.dev go.dev groups.google.com linux.oracle.com linux.oracle.com nvd.nist.gov pkg.go.dev
HIGH

CVE-2026-42504: Decoding a maliciously-crafted MIME header containing many invalid enc ...

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.11, 1.26.4

References: go.dev go.dev groups.google.com nvd.nist.gov pkg.go.dev
MEDIUM

CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped in html/template

Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow "url=" by setting htmlmetacontenturlescape=0.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.8, 1.26.1

References: access.redhat.com go.dev go.dev groups.google.com nvd.nist.gov pkg.go.dev www.cve.org
MEDIUM

CVE-2026-27145: *x509.Certificate).VerifyHostname previously called matchHostnames in ...

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.11, 1.26.4

References: go.dev go.dev groups.google.com nvd.nist.gov pkg.go.dev
MEDIUM

CVE-2026-32282: golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.9, 1.26.2

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org go.dev go.dev groups.google.com linux.oracle.com linux.oracle.com nvd.nist.gov pkg.go.dev www.cve.org
MEDIUM

CVE-2026-32288: archive/tar: golang: Go's archive/tar package: Denial of Service via maliciously-crafted archive

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.9, 1.26.2

References: access.redhat.com go.dev go.dev groups.google.com nvd.nist.gov pkg.go.dev www.cve.org
MEDIUM

CVE-2026-32289: html/template: golang: html/template: Cross-Site Scripting (XSS) via improper context and brace depth tracking in JS template literals

Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.9, 1.26.2

References: access.redhat.com go.dev go.dev groups.google.com nvd.nist.gov pkg.go.dev www.cve.org
MEDIUM

CVE-2026-39826: html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping

If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.10, 1.26.3

References: access.redhat.com go.dev go.dev groups.google.com linux.oracle.com linux.oracle.com nvd.nist.gov pkg.go.dev www.cve.org
MEDIUM

CVE-2026-42507: net/textproto: golang: Golang net/textproto: Misleading error messages via input injection

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.11, 1.26.4

References: access.redhat.com go.dev go.dev groups.google.com nvd.nist.gov pkg.go.dev www.cve.org
LOW

CVE-2026-27139: os: FileInfo can escape from a Root in golang os module

On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.

Package Name: stdlib
Installed Version: v1.24.13
Fixed Version: 1.25.8, 1.26.1

References: access.redhat.com go.dev go.dev groups.google.com nvd.nist.gov pkg.go.dev www.cve.org

These instructions assume you have setup the repository first (or read it).

To pull proxyv2 @ reference/tag sha256:dd0d092f7f6007ba3a80bbebb7eca24eee783f457e00c1ca46dc5cb12d9ebaf5:

docker pull containers.istio.tetratelabs.com/proxyv2@sha256:dd0d092f7f6007ba3a80bbebb7eca24eee783f457e00c1ca46dc5cb12d9ebaf5

You can also pull the latest version of this image (if it exists):

docker pull containers.istio.tetratelabs.com/proxyv2:latest

To refer to this image after pulling in a Dockerfile, specify the following:

FROM containers.istio.tetratelabs.com/proxyv2@sha256:dd0d092f7f6007ba3a80bbebb7eca24eee783f457e00c1ca46dc5cb12d9ebaf5
Top