
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Improper Handling of Syntactically Invalid Structure
msgpack5 is an A msgpack v5 implementation for node.js and the browser, with extension points
Affected versions of this package are vulnerable to Improper Handling of Syntactically Invalid Structure via the tryDecode function in lib/decoder.js, which does not reject the reserved MessagePack byte 0xc1 before attempting to process it. An attacker can send a message containing this reserved byte to trigger an unhandled error that crashes the stream, causing a denial of service.
Insertion of Sensitive Information into Log File
pydantic-ai is an AI Agent Framework, the Pydantic way
Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the otel_message_parts method in messages.py, where RetryPromptPart content is included in OpenTelemetry traces regardless of the include_content instrumentation setting. An authenticated attacker with access to the telemetry/tracing backend can read message content that was intended to be suppressed by the include_content flag.
Protection Mechanism Failure
org.asynchttpclient:async-http-client is a maven plugin for the Async Http Client (AHC) classes.
Affected versions of this package are vulnerable to Protection Mechanism Failure due to improper handling of the scheme when processing Set-Cookie headers. An attacker can overwrite, plant, or delete secure cookies by sending crafted HTTP responses over plaintext connections, which can result in session fixation, CSRF token manipulation, or removal of critical cookies. This is only exploitable if a plaintext host under the same site is able to set cookies for the target domain.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




