flyway

Direct Vulnerabilities

Known vulnerabilities in the flyway package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-xvr9-35cr-46v9

<13.4.0-r1
  • L
Cleartext Transmission of Sensitive Information

<13.4.0-r1
  • L
GHSA-g9jj-cgmh-9f38

<13.4.0-r1
  • L
Insufficiently Protected Credentials

<13.4.0-r1
  • L
GHSA-qxvw-fvwx-5cp7

<13.4.0-r1
  • L
Inappropriate Encoding for Output Context

<13.4.0-r1
  • L
Information Exposure Through Caching

<13.3.0-r1
  • L
GHSA-8c42-7qj2-3j46

<13.3.0-r1
  • L
GHSA-j92g-9f8w-j867

<13.0.0-r1
  • L
GHSA-5gvw-p9qm-jgwh

<13.0.0-r1
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<13.0.0-r1
  • H
Allocation of Resources Without Limits or Throttling

<13.0.0-r1
  • L
GHSA-4mp9-239f-g9hg

<13.0.0-r1
  • L
Improper Verification of Cryptographic Signature

<13.0.0-r1
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<13.0.0-r1
  • L
GHSA-558v-64gr-wgg4

<13.0.0-r1
  • L
GHSA-3pjw-73gf-8qr5

<13.0.0-r1
  • H
HTTP Request Smuggling

<13.0.0-r1
  • H
Resource Exhaustion

<13.0.0-r1
  • L
GHSA-c69g-56f8-xwqj

<13.0.0-r1
  • M
HTTP Request Smuggling

<13.0.0-r1
  • L
GHSA-563q-j3cm-6jxm

<13.0.0-r1
  • M
Allocation of Resources Without Limits or Throttling

<13.0.0-r1
  • L
GHSA-6jqx-86gh-f27w

<13.0.0-r1
  • L
Improper Access Control

<13.0.0-r1
  • L
GHSA-r7wm-3cxj-wff9

<13.0.0-r1
  • L
GHSA-gcjf-9mgh-3p7g

<13.0.0-r1
  • L
Incorrect Authorization

<13.0.0-r1
  • L
Resource Exhaustion

<13.0.0-r1
  • L
Not Failing Securely ('Failing Open')

<13.0.0-r1
  • L
GHSA-6cqp-g7gg-8hr5

<13.0.0-r1
  • L
GHSA-jppx-w49h-x2qq

<13.0.0-r1
  • M
CRLF Injection

<13.0.0-r1
  • L
GHSA-c653-97m9-rcg9

<13.0.0-r1
  • L
Resource Exhaustion

<13.0.0-r1
  • L
GHSA-hvcg-qmg6-jm4c

<13.0.0-r1
  • L
GHSA-q4f6-jm68-57ww

<13.0.0-r1
  • L
HTTP Request Smuggling

<13.0.0-r1
  • L
GHSA-mhm7-754m-9p8w

<13.0.0-r1
  • L
GHSA-mvh2-crg5-v77c

<13.0.0-r1
  • L
GHSA-5jmj-h7xm-6q6v

<13.0.0-r1
  • L
Incorrect Authorization

<12.9.0-r1
  • L
Incomplete Blacklist

<13.0.0-r1
  • L
Server-Side Request Forgery (SSRF)

<13.0.0-r1
  • L
Incorrect Authorization

<12.9.0-r1
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<12.9.0-r1
  • L
GHSA-9fxm-vc8v-hj55

<12.9.0-r1
  • L
GHSA-rmj7-2vxq-3g9f

<13.0.0-r1
  • L
GHSA-rcqc-6cw3-h962

<12.9.0-r1
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<13.0.0-r1
  • L
GHSA-hgj6-7826-r7m5

<13.0.0-r1
  • L
GHSA-j3rv-43j4-c7qm

<13.0.0-r1
  • L
Incomplete Blacklist

<13.0.0-r1
  • L
GHSA-5hh8-q8hv-fr38

<12.9.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<13.0.0-r1
  • L
Improper Access Control

<13.0.0-r1
  • L
GHSA-3qp7-7mw8-wx86

<13.0.0-r1
  • H
Resource Exhaustion

<13.0.0-r1
  • L
GHSA-x4gw-5cx5-pgmh

<13.0.0-r1
  • L
Resource Exhaustion

<13.0.0-r1
  • L
GHSA-c2gf-v879-257j

<13.0.0-r1
  • L
GHSA-5x3r-wrvg-rp6q

<13.0.0-r1
  • H
HTTP Response Splitting

<12.9.0-r0
  • C
HTTP Request Smuggling

<12.9.0-r0
  • L
GHSA-m4cv-j2px-7723

<12.9.0-r0
  • L
GHSA-xxqh-mfjm-7mv9

<12.9.0-r0
  • C
HTTP Request Smuggling

<12.9.0-r0
  • L
GHSA-mj4r-2hfc-f8p6

<12.9.0-r0
  • L
GHSA-57rv-r2g8-2cj3

<12.9.0-r0
  • L
Resource Exhaustion

<12.9.0-r0
  • L
GHSA-38f8-5428-x5cv

<12.9.0-r0
  • L
Resource Exhaustion

<12.9.0-r0
  • L
GHSA-f6hv-jmp6-3vwv

<12.9.0-r0
  • L
Integer Overflow or Wraparound

<12.9.0-r0
  • L
GHSA-v8h7-rr48-vmmv

<12.9.0-r0
  • L
GHSA-45q3-82m4-75jr

<12.9.0-r0
  • H
HTTP Request Smuggling

<12.9.0-r0
  • L
CRLF Injection

<12.9.0-r0
  • L
Information Exposure

<12.8.1-r5
  • L
GHSA-w573-9ffj-6ff9

<12.8.1-r5
  • C
Insufficient Verification of Data Authenticity

<12.8.1-r4
  • L
GHSA-5pvg-856g-cp85

<12.8.1-r4
  • C
Insufficient Verification of Data Authenticity

<12.8.1-r4
  • L
GHSA-xmv7-r254-6q78

<12.8.1-r4
  • L
GHSA-676x-f7gg-47vc

<12.8.1-r4
  • L
Use of Insufficiently Random Values

<12.8.1-r4
  • L
GHSA-337m-mw94-2v6g

<12.8.1-r1
  • L
Uncontrolled Recursion

<12.8.1-r1
  • C
Improper Input Validation

<12.6.0-r0
  • L
GHSA-cm33-6792-r9fm

<12.6.0-r0
  • L
GHSA-rwm7-x88c-3g2p

<12.6.0-r0
  • L
Missing Release of Resource after Effective Lifetime

<12.6.0-r0
  • L
GHSA-98qh-xjc8-98pq

<12.5.0-r0
  • L
Allocation of Resources Without Limits or Throttling

<12.5.0-r0
  • L
GHSA-2m67-wjpj-xhg9

<12.7.0-r0
  • L
GHSA-72hv-8253-57qq

<12.6.0-r0
  • L
GHSA-pwqr-wmgm-9rr8

<12.5.0-r0
  • L
HTTP Request Smuggling

<12.5.0-r0
  • H
Allocation of Resources Without Limits or Throttling

<12.5.0-r0
  • L
GHSA-w9fj-cfpg-grvv

<12.5.0-r0
  • L
GHSA-6v53-7c9g-w56r

<12.1.0-r0
  • H
Allocation of Resources Without Limits or Throttling

<12.1.0-r0
  • L
Uncontrolled Recursion

<11.16.0-r0
  • L
Uncontrolled Recursion

<11.16.0-r0
  • L
GHSA-j288-q9x7-2f5v

<11.16.0-r0
  • L
GHSA-xwmg-2g98-w7v9

<11.16.0-r0
  • L
CRLF Injection

<12.5.0-r0
  • L
GHSA-84h7-rjj3-6jx4

<12.5.0-r0
  • H
Improper Input Validation

<11.15.0-r1
  • L
GHSA-m494-w24q-6f7w

<11.15.0-r1
  • H
HTTP Request Smuggling

<11.12.0-r1
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<11.11.2-r1
  • H
Allocation of Resources Without Limits or Throttling

<11.11.0-r1
  • L
CVE-2025-22227

<11.10.3-r0
  • L
Information Exposure Through Log Files

<11.4.1-r0
  • L
CVE-2025-24970

<11.3.1-r1
  • L
Untrusted Search Path

<11.2.0-r1
  • L
Incorrect Default Permissions

<11.2.0-r1