$ cat ./advisories

Advisories

Public GHSA and CVE records, plus the companion writeups when they are available in the current build.

  • containerd

    4 ghsa
  • cilium

    1 ghsa
    • Secret sync name collision enables cross-namespace L7 policy bypass

      Name collisions between Secret and ConfigMap objects let a namespace-scoped attacker overwrite synchronized SDS objects and bypass L7 network policy enforcement.

  • docker/mcp-gateway

    1 ghsa
    • Tool-name shadowing across aggregated servers

      Aggregating MCP servers into a flat namespace without per-server prefixes or collision detection lets an untrusted server shadow trusted tool names and intercept calls.

  • cert-manager

    1 ghsa
    • Direct ACME Challenge resources can bypass Issuer DNS01 solver policy and use ClusterIssuer DNS credentials

      Directly created ACME Challenge resources can supply attacker-controlled DNS01 solver config while cert-manager uses ClusterIssuer credentials.