Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CLEANSTART-2026-NA25366
  • CleanStart/loki
Security fix for ghsa-xmrv-pmrh-hhx2 applied in: loki 3.7.1-r0 2 days ago
  • Fix available
CLEANSTART-2026-US79386
  • CleanStart/loki
Security fix for ghsa-hfvc-g4fc-pqhx applied in: loki 3.7.1-r0 2 days ago
  • Fix available
CLEANSTART-2026-QC55250
  • CleanStart/loki
Security fix for ghsa-w8rr-5gcm-pp58 applied in: loki 3.7.1-r0 2 days ago
  • Fix available
CLEANSTART-2026-EI91095
  • CleanStart/loki
Security fix for ghsa-78h2-9frx-2jm8 applied in: loki 3.7.1-r0 2 days ago
  • Fix available
CLEANSTART-2026-DU50032
  • CleanStart/loki
OpenTelemetry-Go is the Go implementation of OpenTelemetry 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-ZA34964
  • CleanStart/loki
OpenTelemetry-Go is the Go implementation of OpenTelemetry 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-NH53620
  • CleanStart/loki
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web To... 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-OJ26404
  • CleanStart/loki
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation wou... 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-ZW28198
  • CleanStart/loki
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-UN89941
  • CleanStart/loki
When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty pa... 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-HX71601
  • CleanStart/loki
in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-WU91498
  • CleanStart/loki
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-SR68419
  • CleanStart/loki
Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-TA77263
  • CleanStart/loki
malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-WW85548
  • CleanStart/loki
incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-UP76614
  • CleanStart/loki
RSA and DSA public key parsers did not enforce size limits on key parameters 2 days ago
  • Fix available
  • Severity - 9.8 (Critical)