github.com/defenseunicorns/zarf
The Airgap Native Package Manager for Kubernetes
Activity
- Latest release
- 1w ago
- Total releases
- 70
- Cadence
- ~13 days
- Last 12 months
- 28
Reach
- Stars
- 2.0k
Details
- First release
- Jun 30, 2021
| Version | Released | |
|---|---|---|
v0.85.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.85.0
minor
Dependencies (67)
+ 59 more |
|
v0.85.0-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.85.0-rc1
pre
Dependencies (67)
+ 59 more |
|
v0.84.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.84.0
minor
Dependencies (66)
+ 58 more |
|
v0.84.0-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.84.0-rc1
pre
Dependencies (66)
+ 58 more |
|
v0.83.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.83.0
minor
Dependencies (67)
+ 59 more |
|
v0.83.0-rc2
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.83.0-rc2
pre
Dependencies (67)
+ 59 more |
|
v0.83.0-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.83.0-rc1
pre
Dependencies (67)
+ 59 more |
|
v0.82.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.82.0
minor
Dependencies (67)
+ 59 more |
|
v0.82.0-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.82.0-rc1
pre
Dependencies (67)
+ 59 more |
|
v0.81.1
patch
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.81.1
patch
Dependencies (67)
+ 59 more |
|
v0.81.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.81.0
minor
Dependencies (67)
+ 59 more |
|
v0.81.0-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.81.0-rc1
pre
Dependencies (67)
+ 59 more |
|
v0.80.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.80.0
minor
Dependencies (67)
+ 59 more |
|
v0.80.0-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.80.0-rc1
pre
Dependencies (67)
+ 59 more |
|
v0.79.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.79.0
minor
Dependencies (67)
+ 59 more |
|
v0.79.0-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.79.0-rc1
pre
Dependencies (67)
+ 59 more |
|
v0.78.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.78.0
minor
Dependencies (67)
+ 59 more |
|
v0.77.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.77.0
minor
Dependencies (67)
+ 59 more |
|
v0.77.0-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.77.0-rc1
pre
Dependencies (67)
+ 59 more |
|
v0.76.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.76.0
minor
Dependencies (68)
+ 60 more |
|
v0.76.0-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.76.0-rc1
pre
Dependencies (68)
+ 60 more |
|
v0.75.1
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.75.1
minor
Dependencies (66)
+ 58 more |
|
v0.75.1-rc2
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.75.1-rc2
pre
Dependencies (66)
+ 58 more |
|
v0.75.1-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.75.1-rc1
pre
Dependencies (66)
+ 58 more |
|
v0.74.1
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.74.1
minor
Dependencies (65)
+ 57 more |
|
v0.65.1
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.65.1
minor
Dependencies (67)
+ 59 more |
|
v0.63.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.63.0
minor
Dependencies (65)
+ 57 more |
|
v0.63.0-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.63.0-rc1
pre
Dependencies (65)
+ 57 more |
|
v0.62.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.62.0
minor
Dependencies (64)
+ 56 more |
|
v0.61.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.61.0
minor
Dependencies (63)
+ 55 more |
|
v0.60.0-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.60.0-rc1
pre
Dependencies (63)
+ 55 more |
|
v0.59.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.59.0
minor
Dependencies (63)
+ 55 more |
|
v0.58.0-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.58.0-rc1
pre
Dependencies (63)
+ 55 more |
|
v0.58.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.58.0
minor
Dependencies (63)
+ 55 more |
|
v0.55.6
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.55.6
minor
Dependencies (63)
+ 55 more |
|
v0.54.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.54.0
minor
Dependencies (65)
+ 57 more |
|
v0.51.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.51.0
minor
Dependencies (64)
+ 56 more |
|
v0.49.1
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.49.1
minor
Dependencies (64)
+ 56 more |
|
v0.46.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.46.0
minor
Dependencies (62)
+ 54 more |
|
v0.39.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.39.0
minor
Dependencies (61)
+ 53 more |
|
v0.38.3
patch
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.38.3
patch
Dependencies (61)
+ 53 more |
|
v0.38.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.38.0
minor
Dependencies (59)
+ 51 more |
|
v0.35.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.35.0
minor
Dependencies (58)
+ 50 more |
|
v0.32.5
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.32.5
minor
Dependencies (52)
+ 44 more |
|
v0.31.2
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.31.2
minor
Dependencies (51)
+ 43 more |
|
v0.31.0-rc1
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.31.0-rc1
pre
Dependencies (50)
+ 42 more |
|
v0.30.1
patch
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.30.1
patch
Dependencies (51)
+ 43 more |
|
v0.30.0
minor
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.30.0
minor
Dependencies (51)
+ 43 more |
|
v0.30.0-rc2
pre
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.30.0-rc2
pre
Dependencies (51)
+ 43 more |
|
v0.29.1
patch
1 CVE
CVE-2026-40090
GO-2026-5542
GHSA-pj97-4p9w-gx3q
Jul 23, 2026
Path traversal via malicious package name in github.com/zarf-dev/zarf A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path. References Updated Jul 23, 2026 · Source: OSV.dev |
v0.29.1
patch
Dependencies (48)
+ 40 more |