
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Malicious Package
express-nodejs is a malicious package. This package contains malicious code, and its content was removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.
Symlink Attack
BuildStream is an A framework for modelling build pipelines in YAML
Affected versions of this package are vulnerable to Symlink Attack in the tar source plugin when handling archive extraction. An attacker can modify or overwrite arbitrary files on the host system by supplying a malicious tarball containing symlinks during the source fetching process. This is only exploitable if the environment is running on Python versions earlier than 3.12 and the user explicitly fetches an untrusted archive.
Regular Expression Denial of Service (ReDoS)
org.webjars.npm:brace-expansion is a WebJar for brace-expansion.
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the expand_ function, which implements a Bash quirk where a brace group followed by a comma set (e.g. {a},b}) causes the parser to rewrite the input string and restart the scan, absorbing one closing brace per pass. Because each pass re-reads the entire string and the string itself grows by approximately 25 characters per rewrite (due to the escClose sentinel), the work is quadratic in the number of trailing braces, allowing an attacker to block the event loop with a small input. An input of the form '{a}' + '}'.repeat(128000) + ',z}' takes approximately 27 seconds to process while producing only two results, and neither the existing max nor maxLength guards can prevent this because the cost is incurred during parsing before any result set is produced.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




