Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CLEANSTART-2026-NA25366
  • CleanStart/loki
Security fix for ghsa-xmrv-pmrh-hhx2 applied in: loki 3.7.1-r0 yesterday
  • Fix available
CLEANSTART-2026-US79386
  • CleanStart/loki
Security fix for ghsa-hfvc-g4fc-pqhx applied in: loki 3.7.1-r0 yesterday
  • Fix available
CLEANSTART-2026-QC55250
  • CleanStart/loki
Security fix for ghsa-w8rr-5gcm-pp58 applied in: loki 3.7.1-r0 yesterday
  • Fix available
CLEANSTART-2026-EI91095
  • CleanStart/loki
Security fix for ghsa-78h2-9frx-2jm8 applied in: loki 3.7.1-r0 yesterday
  • Fix available
CLEANSTART-2026-DU50032
  • CleanStart/loki
OpenTelemetry-Go is the Go implementation of OpenTelemetry yesterday
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-ZA34964
  • CleanStart/loki
OpenTelemetry-Go is the Go implementation of OpenTelemetry yesterday
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-NH53620
  • CleanStart/loki
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web To... yesterday
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-OJ26404
  • CleanStart/loki
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation wou... yesterday
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-ZW28198
  • CleanStart/loki
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation yesterday
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-UN89941
  • CleanStart/loki
When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty pa... yesterday
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-HX71601
  • CleanStart/loki
in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it yesterday
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-WU91498
  • CleanStart/loki
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh yesterday
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-SR68419
  • CleanStart/loki
Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh yesterday
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-TA77263
  • CleanStart/loki
malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop yesterday
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-WW85548
  • CleanStart/loki
incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs yesterday
  • Fix available
  • Severity - 9.8 (Critical)
CLEANSTART-2026-UP76614
  • CleanStart/loki
RSA and DSA public key parsers did not enforce size limits on key parameters yesterday
  • Fix available
  • Severity - 9.8 (Critical)