conductor-fips

Direct Vulnerabilities

Known vulnerabilities in the conductor-fips package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-54399

<3.32.1-r4
  • L
CVE-2026-54428

<3.32.1-r4
  • L
GHSA-hjcp-jmpx-g3qm

<3.32.1-r4
  • L
GHSA-hf6x-8p5f-cgmf

<3.32.1-r4
  • L
GHSA-v3jc-474w-2wm6

<3.32.1-r4
  • L
Missing Release of Resource after Effective Lifetime

<3.32.1-r4
  • L
Improper Encoding or Escaping of Output

<3.32.1-r3
  • L
GHSA-qv9r-c865-cp47

<3.32.1-r3
  • L
Information Exposure Through Caching

<3.32.1-r2
  • L
GHSA-8c42-7qj2-3j46

<3.32.1-r2
  • L
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

<3.32.1-r1
  • L
GHSA-6g32-pxv4-2wfj

<3.32.1-r1
  • L
Uncontrolled Memory Allocation

<3.32.1-r1
  • L
Improper Input Validation

<3.32.1-r1
  • L
GHSA-5xwg-cfvj-gff5

<3.32.1-r1
  • L
GHSA-68mj-5wr7-6fgg

<3.32.1-r1
  • L
Uncontrolled Recursion

<3.32.1-r1
  • L
GHSA-93j5-89vc-pph4

<3.32.1-r1
  • L
Improper Input Validation

<3.32.1-r1
  • L
GHSA-5m9f-rphj-c435

<3.32.1-r1
  • L
Improper Certificate Validation

<3.32.1-r1
  • L
GHSA-qx7j-jv8m-fppr

<3.32.1-r1
  • L
Missing Release of Resource after Effective Lifetime

<3.31.0-r6
  • L
GHSA-pmhh-3w7g-xqp8

<3.31.0-r9
  • L
Cross-site Scripting (XSS)

<3.31.0-r9
  • L
GHSA-r7wm-3cxj-wff9

<3.31.0-r8
  • L
GHSA-72hv-8253-57qq

<3.31.0-r8
  • L
NULL Pointer Dereference

<3.31.0-r8
  • L
GHSA-xx22-p4ch-683r

<3.31.0-r8
  • L
Not Failing Securely ('Failing Open')

<3.31.0-r7
  • L
GHSA-j92g-9f8w-j867

<3.31.0-r7
  • L
GHSA-mfg7-5gfp-c4w3

<3.31.0-r6
  • H
HTTP Request Smuggling

<3.31.0-r6
  • L
GHSA-4mp9-239f-g9hg

<3.31.0-r6
  • H
Resource Exhaustion

<3.31.0-r6
  • L
GHSA-c69g-56f8-xwqj

<3.31.0-r6
  • L
GHSA-6jqx-86gh-f27w

<3.31.0-r6
  • M
HTTP Request Smuggling

<3.31.0-r6
  • L
Resource Exhaustion

<3.31.0-r6
  • L
GHSA-q4f6-jm68-57ww

<3.31.0-r6
  • L
GHSA-mvh2-crg5-v77c

<3.31.0-r6
  • L
GHSA-jppx-w49h-x2qq

<3.31.0-r6
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<3.31.0-r6
  • L
Improper Access Control

<3.31.0-r6
  • M
CRLF Injection

<3.31.0-r6
  • L
GHSA-gcjf-9mgh-3p7g

<3.31.0-r6
  • L
GHSA-558v-64gr-wgg4

<3.31.0-r6
  • L
Resource Exhaustion

<3.31.0-r6
  • H
Allocation of Resources Without Limits or Throttling

<3.31.0-r6
  • L
GHSA-6cqp-g7gg-8hr5

<3.31.0-r6
  • L
CVE-2020-36843

<3.31.0-r5
  • L
GHSA-p53j-g8pw-4w5f

<3.31.0-r5
  • L
GHSA-5843-p793-ghmm

<3.31.0-r5
  • L
GHSA-wwpq-f5c3-7hvx

<3.31.0-r5
  • L
GHSA-vxf7-qj7q-83fh

<3.31.0-r5
  • L
GHSA-r936-gwx5-v52f

<3.31.0-r5
  • L
GHSA-6hcq-hmm3-jj3c

<3.31.0-r5
  • L
CVE-2026-22737

<3.31.0-r5
  • L
GHSA-5jmj-h7xm-6q6v

<3.31.0-r5
  • L
CVE-2026-22746

<3.31.0-r5
  • L
GHSA-6p4f-wcwh-5vvm

<3.31.0-r5
  • L
CVE-2025-41249

<3.31.0-r5
  • L
CVE-2026-22735

<3.31.0-r5
  • L
GHSA-wg35-8jpf-2xv3

<3.31.0-r5
  • L
CVE-2026-40973

<3.31.0-r5
  • L
CVE-2026-22740

<3.31.0-r5
  • L
CVE-2025-41242

<3.31.0-r5
  • L
CVE-2026-22741

<3.31.0-r5
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<3.31.0-r5
  • L
CVE-2026-22745

<3.31.0-r5
  • L
GHSA-jmp9-x22r-554x

<3.31.0-r5
  • L
GHSA-4773-3jfm-qmx3

<3.31.0-r5
  • H
CVE-2025-37731

<3.31.0-r4
  • L
GHSA-56r7-h6mw-rcfv

<3.31.0-r4
  • L
CVE-2025-37727

<3.31.0-r4
  • L
GHSA-ghfh-p92w-j4mg

<3.31.0-r4
  • L
CVE-2024-52980

<3.31.0-r4
  • L
GHSA-m9gh-789g-q5pv

<3.31.0-r4
  • L
GHSA-4q2v-9p7v-3v22

<3.31.0-r2
  • L
CVE-2025-22227

<3.31.0-r2
  • L
GHSA-hgj6-7826-r7m5

<3.31.0-r1
  • L
GHSA-rmj7-2vxq-3g9f

<3.31.0-r1
  • L
Incomplete Blacklist

<3.31.0-r1
  • L
Server-Side Request Forgery (SSRF)

<3.31.0-r1
  • L
GHSA-j3rv-43j4-c7qm

<3.31.0-r1
  • L
Incomplete Blacklist

<3.31.0-r1