
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Allocation of Resources Without Limits or Throttling
phoenix is a The official JavaScript client for the Phoenix web framework.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the Elixir.Phoenix.Transports.LongPoll POST requests handling with Content-Type: application/x-ndjson. An attacker can exhaust system memory and schedulers, leading to a crash and termination of all active sessions by sending a large request body consisting entirely of newline bytes, which is split into a massive list of empty binaries and further processed without limits.
Note:
This is only exploitable if the longpoll transport is enabled on any
Phoenix.Socketdeclaration, including the LiveView/livesocket.Longpoll is enabled for newly generated Phoenix projects since Phoenix 1.7.11.
Use of Hard-coded Credentials
ogham-mcp is a Shared memory MCP server — persistent, searchable, cross-client
Affected versions of this package are vulnerable to Use of Hard-coded Credentials due to hardcoded credentials present in the source files, including development database URLs and an API key. An attacker can gain unauthorized access to external services by extracting these credentials from the distributed source files.
Access Control Bypass
Affected versions of this package are vulnerable to Access Control Bypass via the updateUserRealmRoles function. An attacker can escalate privileges by invoking the API with a valid token from one realm to modify user roles in another realm, potentially granting administrative access to unauthorized users.
Recent vulnerabilities disclosed by Snyk
- M
Missing Authentication for Critical Function in django-mdeditor (pip)- C
Remote Code Execution (RCE) in simple-git (npm)- C
- M
Cross-site Scripting (XSS) in github.com/yuin/goldmark/renderer/html (golang)- M
Division by zero in jsrsasign (npm)
Snyk security
researchers
have disclosed
3486
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




