← All images

caddy

Updated: 2026-04-29 05:50 UTC  |  Commit: d48be5a

PackageVersionSeverityCVEFix VersionDescription
github.com/jackc/pgx/v5v5.8.0CRITICALGHSA-9jj7-4m8r-rfcm5.9.0Memory-safety vulnerability in github.com/jackc/pgx/v5.
google.golang.org/grpcv1.79.2CRITICALGHSA-p77j-4mvh-x3m31.79.3gRPC-Go has an authorization bypass via missing leading slash in :path
go.opentelemetry.io/otelv1.40.0HIGHGHSA-mh2q-q3fh-24751.41.0OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
go.opentelemetry.io/otel/sdkv1.40.0HIGHGHSA-hfvc-g4fc-pqhx1.43.0opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttpv0.16.0MEDIUMGHSA-w8rr-5gcm-pp580.19.0opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpv1.40.0MEDIUMGHSA-w8rr-5gcm-pp581.43.0opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.40.0MEDIUMGHSA-w8rr-5gcm-pp581.43.0opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
github.com/jackc/pgx/v5v5.8.0LOWGHSA-j88v-2chj-qfwx5.9.2pgx: SQL Injection via placeholder confusion with dollar quoted string literals