Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-75625 | 1 Uber | 1 Kraken | 2026-08-18 | 9 Critical |
| Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or malicious peers can supply substituted content with forged CRC32 corrections that passes per-piece checks, poisoning the cache with attacker-chosen container image layers or manifests that are re-seeded and executed by other hosts. | ||||
| CVE-2022-47747 | 1 Uber | 1 Kraken | 2025-04-03 | 7.5 High |
| kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs. | ||||
Page 1 of 1.