Количество 114
Количество 114
SUSE-SU-2025:1018-1
Security update for buildah
SUSE-SU-2025:1017-1
Security update for buildah
SUSE-SU-2025:1014-1
Security update for buildah
SUSE-SU-2025:0813-1
Security update for buildah
ROS-20250624-15
Уязвимость consul
RLSA-2025:7462
Important: podman security update
RLSA-2025:7391
Important: podman security update
ELSA-2025-7462
ELSA-2025-7462: podman security update (IMPORTANT)
ELSA-2025-7391
ELSA-2025-7391: podman security update (IMPORTANT)
CVE-2025-30204
golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This issue is fixed in 5.2.2 and 4.5.2.
CVE-2025-30204
golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This issue is fixed in 5.2.2 and 4.5.2.
CVE-2025-30204
golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This issue is fixed in 5.2.2 and 4.5.2.
CVE-2025-30204
jwt-go allows excessive memory allocation during header parsing
CVE-2025-30204
golang-jwt is a Go implementation of JSON Web Tokens. Starting in vers ...
SUSE-SU-2025:1038-1
Security update for podman
SUSE-SU-2025:1037-1
Security update for podman
SUSE-SU-2025:1036-1
Security update for podman
SUSE-RU-2025:02093-1
Recommended update for podman
SUSE-RU-2025:02092-1
Recommended update for podman
SUSE-RU-2025:02091-1
Recommended update for podman
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
SUSE-SU-2025:1018-1 Security update for buildah | больше 1 года назад | |||
SUSE-SU-2025:1017-1 Security update for buildah | больше 1 года назад | |||
SUSE-SU-2025:1014-1 Security update for buildah | больше 1 года назад | |||
SUSE-SU-2025:0813-1 Security update for buildah | больше 1 года назад | |||
ROS-20250624-15 Уязвимость consul | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
RLSA-2025:7462 Important: podman security update | 10 месяцев назад | |||
RLSA-2025:7391 Important: podman security update | 10 месяцев назад | |||
ELSA-2025-7462 ELSA-2025-7462: podman security update (IMPORTANT) | около 1 года назад | |||
ELSA-2025-7391 ELSA-2025-7391: podman security update (IMPORTANT) | около 1 года назад | |||
CVE-2025-30204 golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This issue is fixed in 5.2.2 and 4.5.2. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-30204 golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This issue is fixed in 5.2.2 and 4.5.2. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-30204 golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This issue is fixed in 5.2.2 and 4.5.2. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-30204 jwt-go allows excessive memory allocation during header parsing | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-30204 golang-jwt is a Go implementation of JSON Web Tokens. Starting in vers ... | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
SUSE-SU-2025:1038-1 Security update for podman | больше 1 года назад | |||
SUSE-SU-2025:1037-1 Security update for podman | больше 1 года назад | |||
SUSE-SU-2025:1036-1 Security update for podman | больше 1 года назад | |||
SUSE-RU-2025:02093-1 Recommended update for podman | около 1 года назад | |||
SUSE-RU-2025:02092-1 Recommended update for podman | около 1 года назад | |||
SUSE-RU-2025:02091-1 Recommended update for podman | около 1 года назад |
Уязвимостей на страницу