
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Malicious Package
eslint-prettier-js is a malicious package. This package contains malicious code, and its content was removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.
Allocation of Resources Without Limits or Throttling
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the JWE.deserialize() method (jwcrypto/jwe.py:555), which calls raw_jwe.split('.') on the input before checking that the compact serialization has the required five segments . An attacker can trigger a MemoryError and pressure or interrupt the worker by submitting a compact JWE string containing millions of period delimiters, forcing an unbounded list allocation before the len(data) != 5 check runs. The same pattern is present in the JWS deserializer, and exploitation is constrained where the application caps the maximum token size before deserialization.
Origin Validation Error
io.vertx:vertx-core is a tool-kit for building reactive applications on the JVM.
Affected versions of this package are vulnerable to Origin Validation Error in the DefaultRedirectHandler, which forwards request headers, including Authorization, Cookie, Proxy-Authorization, and custom headers such as X-API-Token, across cross-origin redirects without comparing the scheme, host, and port of the origin. An attacker controlling a redirect destination can capture bearer tokens, basic-auth credentials, session cookies, and API keys attached to the original request by returning a redirect to a host they control. This requires the attacker to cause a Vert.x HttpClient request to be redirected to that host, such as through a webhook dispatcher or image proxy that follows redirects.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




