← Scan another repo

github.com/chainguard-dev/apko

@ d3d5e1178103

Submitted 7/31/2026, 5:06:10 PM · Status: ok

Risk grade
F
100 / 100
Findings
137
5 critical49 high51 medium4 low28 info0 on CISA KEV0ATT&CK
Showing 137 of 137 findings

Findings

  • Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an
    Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent to the peer. Impact summary: A buffer overread can have a range of potential consequences such as unexpected appl…
    grypeCVE-2024-5535EPSS 5.6%
  • Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an
    Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent to the peer. Impact summary: A buffer overread can have a range of potential consequences such as unexpected appl…
    grypeCVE-2024-5535EPSS 5.6%
  • There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
    grypeCVE-2022-48174EPSS 3.1%
  • There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
    grypeCVE-2022-48174EPSS 3.1%
  • zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. S
    zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable t…
    grypeCVE-2022-37434EPSS 15.5%
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected private-key: Identified a Private Key, which may compromise cryptographic security and sensitive data encryption
    Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    gitleaks
  • Detected private-key: Identified a Private Key, which may compromise cryptographic security and sensitive data encryption
    Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    gitleaks
  • A security vulnerability has been identified in all supported versions
    A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers…
    grypeCVE-2023-0464EPSS 3.7%
  • A security vulnerability has been identified in all supported versions
    A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers…
    grypeCVE-2023-0464EPSS 3.7%
  • A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
    grypeCVE-2022-30065EPSS 1.2%
  • A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
    grypeCVE-2022-30065EPSS 1.2%
  • An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number
    An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 3…
    grypeCVE-2026-40200EPSS 0.2%
  • An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number
    An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 3…
    grypeCVE-2026-40200EPSS 0.2%
  • BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to c
    BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
    grypeCVE-2022-28391EPSS 3.5%
  • BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to c
    BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
    grypeCVE-2022-28391EPSS 3.5%
  • Issue summary: A signed integer overflow when sizing the destination
    Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow. Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefine…
    grypeCVE-2026-7383EPSS 0.6%
  • Issue summary: A signed integer overflow when sizing the destination
    Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow. Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefine…
    grypeCVE-2026-7383EPSS 0.6%
  • Issue summary: A specially crafted PKCS#7 or S/MIME signed message could
    Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#…
    grypeCVE-2026-45447EPSS 5.2%
  • Issue summary: A specially crafted PKCS#7 or S/MIME signed message could
    Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#…
    grypeCVE-2026-45447EPSS 5.2%
  • Issue summary: A type confusion vulnerability exists in the TimeStamp Response
    Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Imp…
    grypeCVE-2025-69420EPSS 0.8%
  • Issue summary: A type confusion vulnerability exists in the TimeStamp Response
    Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Imp…
    grypeCVE-2025-69420EPSS 0.8%
  • Issue summary: An application trying to decrypt CMS messages encrypted using
    Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds …
    grypeCVE-2025-9230EPSS 1.7%
  • Issue summary: An application trying to decrypt CMS messages encrypted using
    Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds …
    grypeCVE-2025-9230EPSS 1.7%
  • Issue summary: An uncommon configuration of clients performing DANE TLSA-based
    Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of po…
    grypeCVE-2026-28387EPSS 0.8%
  • Issue summary: An uncommon configuration of clients performing DANE TLSA-based
    Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of po…
    grypeCVE-2026-28387EPSS 0.8%
  • Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously
    Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: The out-of-bounds write can cau…
    grypeCVE-2025-69419EPSS 0.4%
  • Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously
    Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: The out-of-bounds write can cau…
    grypeCVE-2025-69419EPSS 0.4%
  • Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause
    Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of…
    grypeCVE-2024-4741EPSS 2.9%
  • Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause
    Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of…
    grypeCVE-2024-4741EPSS 2.9%
  • Issue summary: During processing of a crafted CMS EnvelopedData message
    Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resu…
    grypeCVE-2026-28389EPSS 1.0%
  • Issue summary: During processing of a crafted CMS EnvelopedData message
    Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur …
    grypeCVE-2026-28390EPSS 1.0%
  • Issue summary: During processing of a crafted CMS EnvelopedData message
    Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resu…
    grypeCVE-2026-28389EPSS 1.0%
  • Issue summary: During processing of a crafted CMS EnvelopedData message
    Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur …
    grypeCVE-2026-28390EPSS 1.0%
  • Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive
    Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms. Impact summary: The heap buffer over-read may crash the application (Denial…
    grypeCVE-2026-34180EPSS 1.0%
  • Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive
    Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms. Impact summary: The heap buffer over-read may crash the application (Denial…
    grypeCVE-2026-34180EPSS 1.0%
  • Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer
    Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. T…
    grypeCVE-2025-69421EPSS 0.8%
  • Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer
    Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. T…
    grypeCVE-2025-69421EPSS 0.8%
  • Issue summary: The POLY1305 MAC (message authentication code) implementation
    Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications on the Windows 64 platform when running on newer X86_64 processors supporting the AVX512-IFMA instructions. Impact summary: If in an …
    grypeCVE-2023-4807EPSS 0.9%
  • Issue summary: The POLY1305 MAC (message authentication code) implementation
    Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications on the Windows 64 platform when running on newer X86_64 processors supporting the AVX512-IFMA instructions. Impact summary: If in an …
    grypeCVE-2023-4807EPSS 0.9%
  • Issue summary: When a delta CRL that contains a Delta CRL Indicator extension
    Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service f…
    grypeCVE-2026-28388EPSS 1.1%
  • Issue summary: When a delta CRL that contains a Delta CRL Indicator extension
    Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service f…
    grypeCVE-2026-28388EPSS 1.1%
  • Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)
    Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key(). Impact summary: A heap buffer over-read may trigger a crash w…
    grypeCVE-2026-9076EPSS 0.6%
  • Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)
    Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key(). Impact summary: A heap buffer over-read may trigger a crash w…
    grypeCVE-2026-9076EPSS 0.6%
  • musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write vulnerability when an attacker can trigger iconv conversion of untrusted EUC-KR text to UTF-8.
    grypeCVE-2025-26519EPSS 0.3%
  • musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write vulnerability when an attacker can trigger iconv conversion of untrusted EUC-KR text to UTF-8.
    grypeCVE-2025-26519EPSS 0.3%
  • The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and
    The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing t…
    grypeCVE-2022-4450EPSS 20.4%
  • The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and
    The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing t…
    grypeCVE-2022-4450EPSS 20.4%
  • The public API function BIO_new_NDEF is a helper function used for streaming
    The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications. The function receiv…
    grypeCVE-2023-0215EPSS 4.5%
  • The public API function BIO_new_NDEF is a helper function used for streaming
    The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications. The function receiv…
    grypeCVE-2023-0215EPSS 4.5%
  • There is a type confusion vulnerability relating to X.400 address processing
    There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This …
    grypeCVE-2023-0286EPSS 59.5%
  • There is a type confusion vulnerability relating to X.400 address processing
    There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This …
    grypeCVE-2023-0286EPSS 59.5%
  • Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret st
    Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret store / mounted volume instead. (First-party socbox rule; Apache-2.0.)
    semgrepinternal/cli/testdata/melange.rsa:1
  • Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret st
    Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret store / mounted volume instead. (First-party socbox rule; Apache-2.0.)
    semgrepinternal/cli/testdata/private_packages/private_pkg_key.rsa:1

This report is public.