VulnSea

github.com/apache/yunikorn-k8shim vulnerabilities

CVEs whose affected-version data names the github.com/apache/yunikorn-k8shim package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-97146Medium· 4.8
today

Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a secondary label on the pod. If the pod has the label 'app=yunikorn' the checks limiting the user annotation content are not run

Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a secondary label on the pod. If the pod has the label 'app=yunikorn' the checks limiting the user annotation content are not run. The label …

▾ SunlitApache Software Foundation · github.com/apache/yunikorn-k8shimvia NVD
CVE-2026-92393Low· 2.0
today

Apache YuniKorn 1.9.0 and earlier does not implement label and user annotation checks for workload UPDATE action bypassing all checks. Workloads in YuniKorn are defined as the following Kubernetes objects: "deployments", "replicasets", "…

Apache YuniKorn 1.9.0 and earlier does not implement label and user annotation checks for workload UPDATE action bypassing all checks. Workloads in YuniKorn are defined as the following Kubernetes objects: "deployments", "replicasets", "…

▾ SunlitApache Software Foundation · github.com/apache/yunikorn-k8shimvia NVD
CVE-2026-78243Low· 2.1
today

Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user spe…

Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user spe…

▾ SunlitApache Software Foundation · github.com/apache/yunikorn-k8shimvia NVD
github.com/apache/yunikorn-k8shim vulnerabilities (CVEs) · VulnSea