Where
-Infinity
0
EOL
Nov 1, 2025

End of life: 11/1/2025, Latest version: 3.19.7

First published (updated )
EOL
Nov 1, 2025

End of life: 11/1/2025, Latest version: 3.19.7

First published (updated )
EOL
Apr 1, 2026

End of life: 4/1/2026, Latest version: 3.20.6

First published (updated )
EOL
Apr 1, 2026

End of life: 4/1/2026, Latest version: 3.20.6

First published (updated )
EOL
Nov 1, 2026

End of life: 11/1/2026, Latest version: 3.21.3

First published (updated )
EOL
Nov 1, 2026

End of life: 11/1/2026, Latest version: 3.21.3

First published (updated )
EOL
May 9, 2025

End of life: 5/9/2025, Latest version: 3.18.12

First published (updated )
EOL
May 9, 2025

End of life: 5/9/2025, Latest version: 3.18.12

First published (updated )
EOL
Nov 22, 2024

End of life: 11/22/2024, Latest version: 3.17.10

First published (updated )
EOL
Nov 22, 2024

End of life: 11/22/2024, Latest version: 3.17.10

First published (updated )
EOL
May 23, 2024

End of life: 5/23/2024, Latest version: 3.16.9

First published (updated )
EOL
May 23, 2024

End of life: 5/23/2024, Latest version: 3.16.9

First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.

First published (updated )
EOL
May 1, 2023

End of life: 5/1/2023, Latest version: 3.14.10

First published (updated )
EOL
May 1, 2023

End of life: 5/1/2023, Latest version: 3.14.10

First published (updated )
EOL
May 1, 2022

End of life: 5/1/2022, Latest version: 3.12.12

First published (updated )
EOL
May 1, 2022

End of life: 5/1/2022, Latest version: 3.12.12

First published (updated )
EOL
May 1, 2021

End of life: 5/1/2021, Latest version: 3.10.9

First published (updated )
EOL
May 1, 2021

End of life: 5/1/2021, Latest version: 3.10.9

First published (updated )
Severity
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key.

First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the root user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the root user.

First published (updated )
Severity
8.8
Input Validation
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code Execution. This attack appear to be exploitable via A specially crafted APK-file can cause apk to write arbitrary data to an attacker-specified file, due to bugs in handling long link target name and the way a regular file is extracted.. This vulnerability appears to have been fixed in 2.6.10, 2.7.6, and 2.10.1.

First published (updated )
EOL
Nov 1, 2019

End of life: 11/1/2019, Latest version: 3.7.3

First published (updated )
EOL
Nov 1, 2019

End of life: 11/1/2019, Latest version: 3.7.3

First published (updated )
Severity
7.8
Buffer Overflow
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution, by crafting a malicious APKINDEX.tar.gz file with a bad pax header block.

First published (updated )
Severity
7.8
Buffer Overflow
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution by crafting a malicious APKINDEX.tar.gz file.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203