Alpine Alpineproject Alpine

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Alpineproject Alpine.

By the Year

In 2026 there have been 0 vulnerabilities in Alpineproject Alpine. Alpine did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 3 6.27
2021 1 5.90
2020 1 7.50

It may take a day or so for new Alpine vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Alpineproject Alpine Security Vulnerabilities

Alpine <1.10.4 AuthFilter Bypass via SwagURI Path Contamination
CVE-2022-23554 5.4 - Medium - December 28, 2022

Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the user is accessing the swagger endpoint. By accessing a URL with a path such as /api/foo;%2fapi%2fswagger the contains condition will hold and will return from the authentication filter without aborting the request. Note that the principal object will not be assigned and therefore the issue wont allow user impersonation. This issue has been fixed in version 1.10.4. There are no known workarounds.

Incorrect Comparison

Alpine URL Access Filter Bypass (pre 1.10.4)
CVE-2022-23553 7.5 - High - December 28, 2022

Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds.

Alpine <2.25 DoS via LIST/LSUB before STARTTLS
CVE-2021-46853 5.9 - Medium - November 03, 2022

Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS.

In Alpine before 2.25, untagged responses
CVE-2021-38370 5.9 - Medium - August 10, 2021

In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.

Command Injection

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH
CVE-2020-14929 7.5 - High - June 19, 2020

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Alpineproject Alpine or by Alpineproject? Click the Watch button to subscribe.

subscribe