See the full list of npm packages compromised in the "Keyv / Cacheable Supply Chain Compromise - Aug 2026" [View compromised packages].

Homepage
  1. Snyk Vulnerability Database
  2. Linux
  3. centos
  4. centos:10
  5. toolbox

toolbox

Report a new vulnerability Found a mistake?

Direct Vulnerabilities

Known vulnerabilities in the toolbox package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Improper Validation of Unsafe Equivalence in Input

*
  • H
Arbitrary Code Injection

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improper Output Neutralization for Logs

*
  • M
Improper Validation of Unsafe Equivalence in Input

*
  • M
HTTP Request Smuggling

*
  • M
Excessive Platform Resource Consumption within a Loop

*
  • M
Cross-site Scripting (XSS)

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • M
Improper Certificate Validation

*
  • M
Creation of Immutable Text Using String Concatenation

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Output Neutralization for Logs

*
  • M
Information Exposure

*
  • M
Expected Behavior Violation

*
  • M
Expected Behavior Violation

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
Untrusted Search Path

<0:0.2-1.el10_0
  • M
CVE-2025-4673

*
  • M
HTTP Request Smuggling

*
  • M
Information Exposure

*
  • L
Improper Verification of Cryptographic Signature

*
  • M
Information Exposure

*
  • M
Improper Input Validation

*
                                  
Product
  • Partners
  • Developers & Devops Features
  • Enterprise Features
  • Pricing
  • Test with GitHub
  • Test with CLI
  • API status
Resources
  • Vulnerability DB
  • Blog
  • Documentation
  • FAQs
Company
  • About
  • Jobs
  • Contact
  • Legal terms
  • Privacy
  • Press kit
  • Events
Contact us
  • Support
  • Report a new vuln

Find us online

Track our development

DevSecOps Community Podcast

© 2026 Snyk Ltd.