Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-48702

Опубликовано: 27 июл. 2026
Источник: ubuntu
Приоритет: medium

Описание

[Unknown description]

РелизСтатусПримечание
devel

not-affected

1.5.2-1
esm-apps/resolute

needs-triage

jammy

DNE

noble

DNE

resolute

needs-triage

upstream

released

1.5.2-1

Показывать по

Связанные уязвимости

CVSS3: 7.5
redhat
около 1 месяца назад

A flaw was found in Rekor. The `Package.Unmarshal()` function, which processes Alpine Package Keep (APK) files, decompresses gzip streams without limiting the total decompressed size. A remote attacker can exploit this by crafting a malicious APK file with a high compression ratio, causing the server to consume excessive memory. This leads to a Denial of Service (DoS) through an out-of-memory (OOM) error, and can be triggered via unauthenticated API endpoints.

debian

Описание отсутствует

CVSS3: 7.5
github
около 1 месяца назад

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic

suse-cvrf
около 1 месяца назад

Security update for hauler