
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Open Redirect
renovate is a dependency updater.
Affected versions of this package are vulnerable to Open Redirect in the GitLab pagination handling, which follows the URL given in a Link header and attaches the GitLab credentials to the next-page request without confining the follow to the original origin. An attacker operating or having compromised a GitLab server can capture those credentials by returning a Link header pointing at a host they control, which the paginated requests then reach with the credentials attached. This requires the platform to be configured as GitLab against that server, whether for the hosted repository or for dependencies resolved from it, and the exposure is reduced by the fact that a compromised server already receives those credentials on the initial requests.
Authorization Bypass Through User-Controlled Key
apache-airflow-providers-akeyless is a Provider package apache-airflow-providers-akeyless for Apache Airflow
Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key in the Akeyless secrets backend. An attacker can access secrets belonging to other teams by supplying a specially crafted Variable key containing a path separator, which causes the backend to resolve secrets outside the intended team scope.
Note: This is only exploitable if the deployment is configured for multiple teams using the Akeyless secrets backend.
Denial of Service (DoS)
Affected versions of this package are vulnerable to Denial of Service (DoS) in the HTTP/2 flow-control process. An attacker can exhaust system memory by sending data faster than it is consumed by the application, causing unbounded buffering and potential service disruption.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




