
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Missing Authorization
@astrojs/vercel is a Deploy your site to Vercel
Affected versions of this package are vulnerable to Missing Authorization via the _isr process. An attacker can access protected content by sending unauthenticated GET requests with a crafted x_astro_path query parameter, causing the server to render and return any route, even those protected by edge rules or middleware. This is only exploitable if edge-based access controls or middleware are used to protect routes, and the deployment uses split middleware or path-based rules at the edge.
HTTP Request Smuggling
h2 is a Pure-Python HTTP/2 protocol implementation
Affected versions of this package are vulnerable to HTTP Request Smuggling via the processing of HTTP/2 request headers containing multiple Host headers. An attacker can interfere with downstream HTTP/1.1 applications by crafting requests that result in multiple Host headers being forwarded, potentially enabling request smuggling attacks.
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
org.webjars.npm:crypto-js is a library of crypto standards.
Affected versions of this package are vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the WordArray.random function. An attacker can recover security-sensitive values by enumerating the reduced output space of the underlying pseudo-random number generator. This is only exploitable if the application uses the affected function to generate security-sensitive values.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




