dependency-track

Direct Vulnerabilities

Known vulnerabilities in the dependency-track package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-642r-3gj9-2pj5

<4.14.2-r7
  • L
CVE-2026-68494

<4.14.2-r7
  • L
GHSA-p6pp-m3f8-5c89

<4.14.4-r3
  • L
CVE-2026-89407

<4.14.4-r3
  • L
GHSA-7hhh-6rmp-j9qf

<4.14.4-r3
  • L
CVE-2026-89425

<4.14.4-r3
  • L
GHSA-cxp5-3px4-pw24

<4.14.4-r2
  • L
CVE-2026-91776

<4.14.4-r2
  • L
CVE-2026-91777

<4.14.4-r2
  • L
GHSA-wv8q-qhhj-9h54

<4.14.4-r2
  • L
GHSA-wjgm-6hv5-3cvf

<4.14.4-r1
  • L
CVE-2026-19032

<4.14.4-r1
  • L
CVE-2026-83557

<4.14.4-r1
  • L
GHSA-gx83-3vf8-gh7j

<4.14.4-r1
  • L
CVE-2026-68497

<4.14.4-r1
  • L
GHSA-q4xh-88c3-wmh7

<4.14.4-r1
  • L
GHSA-jhq6-gfmj-v8fx

<4.14.4-r0
  • L
GHSA-p47f-322f-whfh

<4.14.4-r0
  • L
CVE-2026-10532

<4.14.4-r0
  • L
CVE-2026-9828

<4.14.4-r0
  • L
CVE-2026-18401

<4.13.6-r2
  • L
GHSA-6qm2-mcq7-53qp

<4.13.6-r2
  • L
Missing Release of Resource after Effective Lifetime

<4.14.3-r2
  • L
GHSA-hjcp-jmpx-g3qm

<4.14.3-r2
  • L
GHSA-g3pr-3p32-fp23

<4.14.3-r1
  • L
GHSA-w737-wx49-qj23

<4.14.3-r1
  • L
CVE-2026-40984

<4.14.3-r1
  • L
CVE-2026-40983

<4.14.3-r1
  • L
GHSA-7p3p-8qv8-m2vh

<4.14.3-r0
  • C
Improper Handling of Alternate Encoding

<4.14.3-r0
  • L
GHSA-w7x5-g22v-xqhr

<4.14.3-r0
  • L
Use of Non-Canonical URL Paths for Authorization Decisions

<4.14.3-r0
  • L
Information Exposure

<4.14.3-r0
  • L
GHSA-f4v5-65jj-pcr2

<4.14.3-r0
  • L
GHSA-2fvj-hgj9-j2gr

<4.14.3-r0
  • L
Improper Input Validation

<4.14.3-r0
  • L
GHSA-r7wm-3cxj-wff9

<4.14.2-r7
  • L
Not Failing Securely ('Failing Open')

<4.14.2-r6
  • L
GHSA-j92g-9f8w-j867

<4.14.2-r6
  • L
GHSA-5jmj-h7xm-6q6v

<4.14.2-r5
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<4.14.2-r5
  • L
GHSA-xwmg-2g98-w7v9

<4.14.2-r4
  • L
Uncontrolled Recursion

<4.14.2-r4
  • L
Incomplete Blacklist

<4.14.2-r3
  • L
Incorrect Authorization

<4.14.2-r3
  • L
Incorrect Authorization

<4.14.2-r3
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<4.14.2-r3
  • L
Server-Side Request Forgery (SSRF)

<4.14.2-r3
  • L
GHSA-j3rv-43j4-c7qm

<4.14.2-r3
  • L
GHSA-hgj6-7826-r7m5

<4.14.2-r3
  • L
GHSA-rcqc-6cw3-h962

<4.14.2-r3
  • L
GHSA-5hh8-q8hv-fr38

<4.14.2-r3
  • L
Incomplete Blacklist

<4.14.2-r3
  • L
GHSA-rmj7-2vxq-3g9f

<4.14.2-r3
  • L
GHSA-9fxm-vc8v-hj55

<4.14.2-r3
  • L
GHSA-98qh-xjc8-98pq

<4.14.1-r3
  • L
Allocation of Resources Without Limits or Throttling

<4.14.1-r3
  • L
GHSA-v468-qcjx-r72w

<4.14.1-r2
  • L
Missing Critical Step in Authentication

<4.14.1-r2
  • L
GHSA-6fmv-xxpf-w3cw

<4.14.0-r5
  • H
CVE-2025-67030

<4.14.0-r5
  • L
Resource Exhaustion

<4.14.0-r0
  • L
GHSA-xxh7-fcf3-rj7f

<4.14.0-r0
  • L
GHSA-qqpg-mvqg-649v

<4.14.0-r0
  • M
Improper Input Validation

<4.14.0-r0
  • L
GHSA-wjpw-4j6x-6rwh

<4.14.0-r0
  • L
CVE-2026-1225

<4.14.0-r0
  • L
GHSA-72hv-8253-57qq

<4.13.6-r2
  • L
GHSA-pr98-23f8-jwxv

<4.13.5-r0
  • L
GHSA-m6vm-37g8-gqvh

<4.13.5-r0
  • L
GHSA-25qh-j22f-pwp8

<4.13.6-r0
  • H
Improper Input Validation

<4.13.6-r0
  • M
CVE-2025-1686

<4.13.5-r0
  • L
GHSA-m494-w24q-6f7w

<4.13.6-r0
  • L
GHSA-6v67-2wr5-gvf4

<4.13.5-r0
  • H
CVE-2023-22102

<4.13.5-r0
  • L
GHSA-p75g-cxfj-7wrx

<4.13.5-r0
  • L
CVE-2024-12801

<4.13.5-r0
  • L
CVE-2024-12798

<4.13.5-r0
  • L
CVE-2025-11226

<4.13.6-r0
  • L
XML External Entity (XXE) Injection

<4.13.5-r1
  • H
Improper Neutralization

<4.13.3-r1
  • L
Uncontrolled Recursion

<4.13.2-r2
  • L
CVE-2024-57699

<4.13.0-r1
  • L
CVE-2024-38374

<4.11.4-r0
  • H
CVE-2023-52428

<4.10.1-r3
  • M
Allocation of Resources Without Limits or Throttling

<4.10.1-r2
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<4.10.1-r2
  • C
SQL Injection

<4.10.1-r1