Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.7
CVE-2026-92791
- EPSS 0.51%
- Veröffentlicht 16.09.2026 20:32:46
- Zuletzt bearbeitet 24.09.2026 21:08:55
Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag par...
9.1
CVE-2026-75625
- EPSS 0.2%
- Veröffentlicht 18.08.2026 17:56:54
- Zuletzt bearbeitet 24.09.2026 20:06:30
Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or malici...
7.5
CVE-2022-47747
- EPSS 0.8%
- Veröffentlicht 20.01.2023 17:15:10
- Zuletzt bearbeitet 03.04.2025 16:15:29
kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.
1