The Lab · 2026-04-16 00:22:55 · GitHub Issues
A critical vulnerability, CVE-2026-34743, has been identified in the XZ Utils data-compression library, exposing systems to a potential buffer overflow. The flaw resides in the `lzma_index_decoder()` function. When this function is used to decode an Index containing zero Records, it leaves the resulting `lzma_index` in...
The Lab · 2026-05-12 20:18:32 · GitHub Issues
Automated security scanning has identified CVE-2026-34743, a medium-severity vulnerability affecting PHP container images built on Alpine Linux 3.22.4. The flaw resides in the xz and xz-libs packages, currently installed at version 5.8.1-r0, with patched versions available at 5.8.3-r0. The vulnerability was uncovered d...
The Lab · 2026-05-12 20:18:33 · GitHub Issues
An automated Trivy security scan has identified an unresolved vulnerability in specific PHP Docker images built on Alpine Linux 3.23, raising concerns for deployments relying on these base versions. The flaw, cataloged as CVE-2026-34743, carries a MEDIUM severity rating and targets the xz and xz-libs packages at versio...