
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Improper Validation of Specified Quantity in Input
Affected versions of this package are vulnerable to Improper Validation of Specified Quantity in Input via CSSStyleDeclaration.setProperty(), which fails to validate reserved property names. An attacker can supply a stylesheet containing a declaration named length, replacing the internal counter and triggering excessive memory allocation during cssText serialization, causing process termination.
Incorrect Authorization
Affected versions of this package are vulnerable to Incorrect Authorization via the delete_asset_queued_events, delete_dag_asset_queued_events, and related queued-events DELETE routes in airflow/api_fastapi/core_api/routes/public/assets.py. An attacker can delete a DAG’s queued asset events by sending a DELETE request to these endpoints while holding only DAG read access and the global asset-delete permission. This lets an authenticated user silently suppress asset-triggered scheduling for a DAG they can read but not edit. In affected deployments, DAG runs stop being queued from those asset events, breaking the DAG’s automatic scheduling behavior.
Improper Authentication
Affected versions of this package are vulnerable to Improper Authentication through the AadOidcIdTokenDecoderFactory and AadB2cOidcIdTokenDecoderFactory OIDC ID token decoders in the Spring Cloud Azure OAuth2 login components. An attacker can elevate privileges and sign in as an unauthorized tenant user by supplying a forged or tenant-mismatched ID token that is signed correctly but has an unvalidated iss claim and, in AAD multi-tenant flows, an inconsistent tid claim. This allows unauthorized access to applications that rely on the issuer or tenant claims to restrict which identities may authenticate.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




