policy-controller

Direct Vulnerabilities

Known vulnerabilities in the policy-controller package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-39821

<0.15.1-r10
  • L
GHSA-w2q5-6q6x-x959

<0.15.1-r10
  • L
GHSA-h524-452v-82p9

<0.15.1-r9
  • L
CVE-2026-42504

<0.15.1-r9
  • L
GHSA-h3gm-q7m7-mp28

<0.15.1-r9
  • L
CVE-2026-27145

<0.15.1-r9
  • L
CVE-2026-42507

<0.15.1-r9
  • L
GHSA-4279-q6mj-392r

<0.15.1-r9
  • L
Missing Authorization

<0.15.1-r8
  • L
Integer Overflow or Wraparound

<0.15.1-r8
  • L
Incorrect Type Conversion or Cast

<0.15.1-r8
  • L
Improper Verification of Cryptographic Signature

<0.15.1-r8
  • L
GHSA-pmwq-pjrm-6p5r

<0.15.1-r6
  • L
GHSA-xm5m-wgh2-rrg3

<0.15.1-r4
  • L
Improper Certificate Validation

<0.15.1-r4
  • L
GHSA-gjvh-7jh8-7xhm

<0.15.1-r8
  • L
GHSA-jrg3-gfjw-hm96

<0.15.1-r8
  • M
Cross-site Scripting (XSS)

<0.15.1-r8
  • L
GHSA-5w89-2c2x-6x66

<0.15.1-r8
  • H
Incorrect Authorization

<0.15.1-r8
  • L
GHSA-7mr4-xjxg-34g6

<0.15.1-r8
  • H
Improper Certificate Validation

<0.15.1-r8
  • M
Allocation of Resources Without Limits or Throttling

<0.15.1-r8
  • H
Allocation of Resources Without Limits or Throttling

<0.15.1-r8
  • L
GHSA-x4jj-h2v8-hqqv

<0.15.1-r8
  • L
GHSA-m4pr-4j3g-9v7v

<0.15.1-r8
  • L
CVE-2026-32280

<0.15.1-r8
  • H
Untrusted Search Path

<0.15.1-r2
  • L
Asymmetric Resource Consumption (Amplification)

<0.15.1-r0
  • L
GHSA-hfvc-g4fc-pqhx

<0.15.1-r2
  • L
GHSA-4qg8-fj49-pxjh

<0.15.1-r0
  • L
GHSA-78h2-9frx-2jm8

<0.15.1-r1
  • L
Directory Traversal

<0.15.1-r0
  • L
GHSA-4c4x-jm2x-pf9j

<0.15.1-r0
  • L
Uncaught Exception

<0.15.1-r1
  • L
GHSA-fphv-w9fq-2525

<0.15.1-r0
  • L
Server-Side Request Forgery (SSRF)

<0.15.1-r0
  • L
NULL Pointer Dereference

<0.15.1-r0
  • L
GHSA-fcv2-xgw5-pqxf

<0.15.1-r0
  • L
GHSA-846p-jg2w-w324

<0.15.1-r0
  • H
Improper Verification of Cryptographic Signature

<0.15.1-r0
  • M
Insufficient Verification of Data Authenticity

<0.15.1-r0
  • L
GHSA-whqx-f9j3-ch6m

<0.15.1-r0
  • H
Reachable Assertion

<0.15.1-r0
  • L
GHSA-273p-m2cw-6833

<0.15.1-r0
  • L
Improper Authorization

<0.14.0-r5
  • L
GHSA-p77j-4mvh-x3m3

<0.14.0-r5
  • L
GHSA-p436-gjf2-799p

<0.14.0-r4
  • H
CVE-2025-15558

<0.14.0-r4
  • L
GHSA-9h8m-3fm2-qjrq

<0.14.0-r3
  • L
Untrusted Search Path

<0.14.0-r3
  • L
GHSA-q9hv-hpm4-hj6x

<0.14.0-r2
  • C
CVE-2026-1229

<0.14.0-r2
  • L
GHSA-gm9r-q53w-2gh4

<0.14.0-r1
  • L
Out-of-bounds Write

<0.14.0-r1
  • L
GHSA-cm6p-qc7v-m3jw

<0.14.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.14.0-r1
  • L
CVE-2025-61730

<0.14.0-r1
  • L
GHSA-gr56-3gp6-6gmj

<0.14.0-r1
  • L
CVE-2025-61731

<0.14.0-r1
  • L
GHSA-xvqr-69v8-f3gv

<0.14.0-r1
  • M
Directory Traversal

<0.15.1-r0
  • L
GHSA-jqc5-w2xx-5vq4

<0.15.1-r0
  • L
GHSA-6v2p-p543-phr9

<0.12.0-r5
  • L
GHSA-hcg3-q754-cr77

<0.12.0-r6
  • L
Improper Validation of Specified Type of Input

<0.12.1-r2
  • L
Improper Certificate Validation

<0.13.1-r4
  • L
GHSA-7c64-f9jr-v9h2

<0.13.1-r4
  • L
Improper Certificate Validation

<0.13.1-r4
  • L
GHSA-5mh9-3jwc-rp59

<0.13.1-r4
  • L
GHSA-f6x5-jh6r-wrfv

<0.13.1-r2
  • L
CVE-2025-58181

<0.13.1-r2
  • L
GHSA-j5w8-q4qc-rx2x

<0.13.1-r2
  • L
CVE-2025-47914

<0.13.1-r2
  • L
Improper Certificate Validation

<0.13.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.13.1-r1
  • L
CVE-2025-61725

<0.13.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.13.1-r1
  • L
CVE-2025-58183

<0.13.1-r1
  • L
Algorithmic Complexity

<0.13.1-r1
  • L
CVE-2025-47912

<0.13.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.13.1-r1
  • L
Information Exposure Through Log Files

<0.13.1-r1
  • L
CVE-2025-58186

<0.13.1-r1
  • L
Race Condition

<0.13.0-r2
  • L
Arbitrary Code Injection

<0.12.1-r1
  • L
CVE-2025-22871

<0.12.0-r9
  • L
Asymmetric Resource Consumption (Amplification)

<0.12.0-r8
  • L
CVE-2025-22870

<0.12.0-r7
  • L
CVE-2025-22869

<0.12.0-r6
  • L
CVE-2025-22868

<0.12.0-r5
  • L
Allocation of Resources Without Limits or Throttling

<0.12.0-r3
  • L
CVE-2025-22866

<0.12.0-r2
  • L
CVE-2024-45341

<0.12.0-r1
  • L
CVE-2024-45336

<0.12.0-r1
  • L
CVE-2024-45338

<0.11.0-r2
  • L
CVE-2024-45337

<0.11.0-r1
  • L
Improper Handling of Exceptional Conditions

<0.9.0-r11
  • L
Race Condition

<0.9.0-r10
  • H
Authentication Bypass

<0.9.0-r10
  • L
CVE-2024-34158

<0.9.0-r9
  • L
CVE-2024-34155

<0.9.0-r9
  • L
CVE-2024-34156

<0.9.0-r9
  • L
CVE-2024-41110

<0.9.0-r7
  • L
CVE-2024-24791

<0.9.0-r6
  • M
Information Exposure Through Log Files

<0.9.0-r5
  • M
Race Condition

<0.9.0-r4
  • C
CVE-2024-24790

<0.9.0-r3
  • M
CVE-2024-24789

<0.9.0-r3
  • L
CVE-2024-24788

<0.9.0-r2
  • L
CVE-2024-24787

<0.9.0-r2
  • M
CVE-2024-32473

<0.9.0-r1
  • H
Allocation of Resources Without Limits or Throttling

<0.9.0-r0
  • M
Allocation of Resources Without Limits or Throttling

<0.9.0-r0
  • L
CVE-2023-45288

<0.8.4-r5
  • L
CVE-2024-24786

<0.8.4-r4
  • H
Origin Validation Error

<0.8.4-r4
  • L
CVE-2024-28180

<0.8.4-r3
  • H
Exposure of Resource to Wrong Sphere

<0.7.0-r4
  • C
Arbitrary Code Injection

<0.7.0-r4
  • C
Arbitrary Code Injection

<0.7.0-r4
  • C
Arbitrary Code Injection

<0.7.0-r4
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<0.8.3-r1