Direct Vulnerabilities

Known vulnerabilities in the buf package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Open Redirect

<1.55.1-r1
  • L
GHSA-xcvf-46f4-xwxf

<1.55.1-r1
  • L
GHSA-c974-w86c-vpfw

<1.72.0-r2
  • L
GHSA-7qch-w8m5-g3h3

<1.72.0-r2
  • L
GHSA-xc2p-8ggw-6cr5

<1.72.0-r2
  • L
CVE-2026-56853

<1.72.0-r2
  • L
CVE-2026-56862

<1.72.0-r2
  • L
GHSA-25mv-j2qr-v5jq

<1.72.0-r2
  • L
CVE-2026-56860

<1.72.0-r2
  • L
CVE-2026-39821

<1.72.0-r2
  • L
GHSA-w2q5-6q6x-x959

<1.72.0-r2
  • L
CVE-2026-33818

<1.72.0-r2
  • L
CVE-2026-56858

<1.72.0-r2
  • L
GHSA-xphw-4f88-5f39

<1.72.0-r2
  • H
Incorrect Authorization

<1.68.3-r0
  • L
GHSA-cqrx-3m42-5p5w

<1.68.3-r0
  • L
GHSA-x4jj-h2v8-hqqv

<1.68.3-r0
  • L
CVE-2026-32280

<1.68.3-r0
  • M
Allocation of Resources Without Limits or Throttling

<1.68.3-r0
  • L
GHSA-gjvh-7jh8-7xhm

<1.68.3-r0
  • H
Allocation of Resources Without Limits or Throttling

<1.68.3-r0
  • L
GHSA-jrg3-gfjw-hm96

<1.68.3-r0
  • L
GHSA-cfp9-33rc-j74f

<1.68.3-r0
  • H
Off-by-one Error

<1.68.3-r0
  • C
CVE-2026-27143

<1.68.3-r0
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<1.68.3-r0
  • L
GHSA-5w89-2c2x-6x66

<1.68.3-r0
  • H
Authentication Bypass

<1.68.3-r0
  • L
GHSA-m4pr-4j3g-9v7v

<1.68.3-r0
  • L
GHSA-x744-4wpc-v9h2

<1.68.3-r0
  • H
Improper Certificate Validation

<1.68.3-r0
  • L
GHSA-pxq6-2prw-chj9

<1.68.3-r0
  • L
CVE-2025-61732

<1.65.0-r1
  • C
CVE-2025-68121

<1.65.0-r1
  • L
GHSA-8jvr-vh7g-f8gx

<1.65.0-r1
  • L
GHSA-h355-32pf-p2xm

<1.65.0-r1
  • L
GHSA-hcg3-q754-cr77

<1.50.1-r0
  • L
Allocation of Resources Without Limits or Throttling

<1.61.0-r2
  • L
GHSA-g754-hx8w-x2g6

<1.61.0-r2
  • L
CVE-2025-47914

<1.60.0-r1
  • L
GHSA-f6x5-jh6r-wrfv

<1.60.0-r1
  • L
CVE-2025-58181

<1.60.0-r1
  • L
GHSA-j5w8-q4qc-rx2x

<1.60.0-r1
  • L
Race Condition

<1.56.0-r1
  • M
Missing Initialization of Resource

<1.55.1-r3
  • L
CVE-2025-22874

<1.54.0-r1
  • L
CVE-2025-4673

<1.54.0-r1
  • L
CVE-2025-22869

<1.50.1-r0
  • L
CVE-2025-22866

<1.50.0-r2
  • L
CVE-2024-45338

<1.47.2-r3
  • L
CVE-2024-45337

<1.47.2-r2
  • L
Insufficient Verification of Data Authenticity

<1.47.2-r1
  • L
CVE-2024-34156

<1.40.1-r0
  • L
CVE-2024-34158

<1.40.1-r0
  • L
CVE-2024-34155

<1.40.1-r0
  • L
CVE-2024-41110

<1.35.1-r1
  • L
CVE-2024-24791

<1.34.0-r1
  • M
CVE-2024-24789

<1.32.2-r1
  • C
CVE-2024-24790

<1.32.2-r1
  • L
CVE-2023-45288

<1.31.0-r0
  • M
CVE-2024-32473

<1.31.0-r0
  • H
Incorrect Resource Transfer Between Spheres

<1.30.1-r0
  • L
CVE-2024-24786

<1.30.0-r0
  • M
Improper Validation of Integrity Check Value

<1.29.0-r0