Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-48702

11 дней назад

[Unknown description]

EPSS: Низкий
redhat логотип

CVE-2026-48702

около 1 месяца назад

A flaw was found in Rekor. The `Package.Unmarshal()` function, which processes Alpine Package Keep (APK) files, decompresses gzip streams without limiting the total decompressed size. A remote attacker can exploit this by crafting a malicious APK file with a high compression ratio, causing the server to consume excessive memory. This leads to a Denial of Service (DoS) through an out-of-memory (OOM) error, and can be triggered via unauthenticated API endpoints.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-48702

EPSS: Низкий
github логотип

GHSA-47q9-m4ww-924m

около 1 месяца назад

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21262-1

около 1 месяца назад

Security update for hauler

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-48702

[Unknown description]

11 дней назад
redhat логотип
CVE-2026-48702

A flaw was found in Rekor. The `Package.Unmarshal()` function, which processes Alpine Package Keep (APK) files, decompresses gzip streams without limiting the total decompressed size. A remote attacker can exploit this by crafting a malicious APK file with a high compression ratio, causing the server to consume excessive memory. This leads to a Denial of Service (DoS) through an out-of-memory (OOM) error, and can be triggered via unauthenticated API endpoints.

CVSS3: 7.5
около 1 месяца назад
debian логотип
-
github логотип
GHSA-47q9-m4ww-924m

Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic

CVSS3: 7.5
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21262-1

Security update for hauler

около 1 месяца назад

Уязвимостей на страницу