
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Improper Handling of Syntactically Invalid Structure
msgpack5 is an A msgpack v5 implementation for node.js and the browser, with extension points
Affected versions of this package are vulnerable to Improper Handling of Syntactically Invalid Structure via the tryDecode function in lib/decoder.js, which does not reject the reserved MessagePack byte 0xc1 before attempting to process it. An attacker can send a message containing this reserved byte to trigger an unhandled error that crashes the stream, causing a denial of service.
Insertion of Sensitive Information into Log File
pydantic-ai is an AI Agent Framework, the Pydantic way
Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File via the OpenTelemetry instrumentation layer, specifically in record_exception and related span-recording helpers, when the include_content setting is disabled. Exception events recorded on model request spans and realtime spans include the full exception message and stack trace, which can contain content the setting is intended to withhold - such as tool retry payloads, model request/response echoes, validation error arguments, and user-supplied data. An authenticated attacker with access to the exported trace data can read sensitive content that should have been suppressed.
Protection Mechanism Failure
org.asynchttpclient:async-http-client is a maven plugin for the Async Http Client (AHC) classes.
Affected versions of this package are vulnerable to Protection Mechanism Failure due to improper handling of the scheme when processing Set-Cookie headers. An attacker can overwrite, plant, or delete secure cookies by sending crafted HTTP responses over plaintext connections, which can result in session fixation, CSRF token manipulation, or removal of critical cookies. This is only exploitable if a plaintext host under the same site is able to set cookies for the target domain.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




