We’ve disclosed 3211 vulnerabilities
by Snyk Security
How to fix?
curl to version 8.4.0 or higher.
Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity when the
onlyLoadAppFromAsar fuses are enabled.
An attacker can edit files inside the
.app bundle on macOS, which these fuses are supposed to protect against, by gaining write access to the filesystem from which the app is launched.
This is only exploitable if your app is launched from a filesystem the attacker has write access to and is specific to macOS, as these fuses are only supported on macOS.
fastapi-proxy-lib is a HTTP/WebSocket proxy for starlette/FastAPI.
Affected versions of this package are vulnerable to Information Exposure due to the shared usage of
httpx.AsyncClient in processing requests from different user clients. An attacker can exploit this to leak cookies among all user clients sharing the same
httpx.AsyncClient by sending a
set-cookie response header. This is only exploitable if the
ForwardHttpProxy is used, or if
ReverseWebSocketProxy are used for servers that may potentially send a
Affected versions of this package are vulnerable to SQL Injection via the
/system/dept/edit path. An attacker can manipulate SQL queries and gain unauthorized access to the database by injecting malicious SQL code. This is only exploitable if the application does not properly sanitize user input.
Insufficient Entropy in pubnub (pub)
Insufficient Entropy in pubnub (cocoapods)
Insufficient Entropy in github.com/pubnub/swift (swift)
Insufficient Entropy in com.pubnub:pubnub-kotlin (maven)
Insufficient Entropy in pubnub (cargo)
by Snyk Security
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.