Direct Vulnerabilities

Known vulnerabilities in the seata package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Resource Exhaustion

<2.7.0-r3
  • H
HTTP Request Smuggling

<2.7.0-r3
  • L
CVE-2024-29025

<2.7.0-r3
  • L
GHSA-wh89-7897-x99h

<2.7.0-r3
  • L
GHSA-j92g-9f8w-j867

<2.7.0-r3
  • L
Not Failing Securely ('Failing Open')

<2.7.0-r3
  • M
Allocation of Resources Without Limits or Throttling

<2.7.0-r3
  • L
GHSA-xx22-p4ch-683r

<2.7.0-r3
  • H
Resource Exhaustion

<2.7.0-r3
  • L
GHSA-5jmj-h7xm-6q6v

<2.7.0-r3
  • L
GHSA-mfg7-5gfp-c4w3

<2.7.0-r3
  • L
GHSA-3g8r-4pfx-jmfh

<2.7.0-r3
  • L
GHSA-4mp9-239f-g9hg

<2.7.0-r3
  • L
Resource Exhaustion

<2.7.0-r3
  • L
Resource Exhaustion

<2.7.0-r3
  • H
Allocation of Resources Without Limits or Throttling

<2.7.0-r3
  • L
GHSA-xq3w-v528-46rv

<2.7.0-r3
  • L
GHSA-jppx-w49h-x2qq

<2.7.0-r3
  • L
GHSA-q6cq-mhr2-jmr5

<2.7.0-r3
  • H
Resource Exhaustion

<2.7.0-r3
  • M
HTTP Request Smuggling

<2.7.0-r3
  • L
Resource Exhaustion

<2.7.0-r3
  • L
CVE-2026-59949

<2.7.0-r3
  • L
GHSA-hvcg-qmg6-jm4c

<2.7.0-r3
  • L
HTTP Request Smuggling

<2.7.0-r3
  • L
Improper Access Control

<2.7.0-r3
  • L
Resource Exhaustion

<2.7.0-r3
  • L
GHSA-6cqp-g7gg-8hr5

<2.7.0-r3
  • L
GHSA-mhm7-754m-9p8w

<2.7.0-r3
  • L
GHSA-6jv9-x5w9-2ccm

<2.7.0-r3
  • L
GHSA-563q-j3cm-6jxm

<2.7.0-r3
  • H
HTTP Request Smuggling

<2.7.0-r3
  • L
Incorrect Authorization

<2.7.0-r3
  • H
Memory Leak

<2.7.0-r3
  • L
GHSA-mvh2-crg5-v77c

<2.7.0-r3
  • L
GHSA-5gvw-p9qm-jgwh

<2.7.0-r3
  • L
GHSA-389x-839f-4rhx

<2.7.0-r3
  • L
GHSA-5w86-c3rq-vjj7

<2.7.0-r3
  • L
GHSA-prj3-ccx8-p6x4

<2.7.0-r3
  • L
Resource Exhaustion

<2.7.0-r3
  • H
Resource Exhaustion

<2.7.0-r3
  • L
GHSA-5jpm-x58v-624v

<2.7.0-r3
  • H
Allocation of Resources Without Limits or Throttling

<2.7.0-r3
  • L
GHSA-93wv-jw9v-4972

<2.7.0-r3
  • L
GHSA-h2qv-fj59-j46j

<2.7.0-r3
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<2.7.0-r3
  • L
GHSA-gcjf-9mgh-3p7g

<2.7.0-r3
  • L
CRLF Injection

<2.7.0-r3
  • L
CRLF Injection

<2.7.0-r3
  • L
GHSA-fghv-69vj-qj49

<2.7.0-r3
  • H
Memory Leak

<2.7.0-r3
  • L
GHSA-c2gf-v879-257j

<2.7.0-r3
  • L
GHSA-q4f6-jm68-57ww

<2.7.0-r3
  • M
CRLF Injection

<2.7.0-r3
  • L
GHSA-c69g-56f8-xwqj

<2.7.0-r3
  • L
GHSA-6jqx-86gh-f27w

<2.7.0-r3
  • L
GHSA-3p8m-j85q-pgmj

<2.7.0-r2
  • L
GHSA-558v-64gr-wgg4

<2.7.0-r2
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<2.7.0-r2
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<2.7.0-r2
  • L
CVE-2025-24970

<2.7.0-r1
  • L
GHSA-c653-97m9-rcg9

<2.7.0-r1
  • L
GHSA-4g8c-wm8x-jfhw

<2.7.0-r1
  • L
Improper Verification of Cryptographic Signature

<2.7.0-r1
  • L
GHSA-272m-gcwp-mpwg

<2.6.0-r22
  • C
Improper Certificate Validation

<2.6.0-r22
  • L
GHSA-g7hg-vrcf-mvmr

<2.6.0-r22
  • L
Time-of-check Time-of-use (TOCTOU)

<2.6.0-r22
  • L
Improper Check for Certificate Revocation

<2.6.0-r22
  • L
GHSA-wc96-39fc-566f

<2.6.0-r22
  • L
GHSA-4qhr-g3c6-fcfx

<2.6.0-r21
  • L
GHSA-v74w-7mr3-4qg3

<2.6.0-r21
  • C
XML External Entity (XXE) Injection

<2.6.0-r21
  • L
Resource Exhaustion

<2.6.0-r20
  • L
GHSA-vhch-2wf3-m8rp

<2.6.0-r20
  • L
GHSA-j3rv-43j4-c7qm

<2.6.0-r19
  • L
Incomplete Blacklist

<2.6.0-r19
  • L
Incomplete Blacklist

<2.6.0-r19
  • L
GHSA-rmj7-2vxq-3g9f

<2.6.0-r19
  • L
Resource Exhaustion

<2.6.0-r19
  • L
GHSA-hgj6-7826-r7m5

<2.6.0-r19
  • L
GHSA-3wrr-7qpf-2prh

<2.6.0-r19
  • L
Server-Side Request Forgery (SSRF)

<2.6.0-r19
  • L
Information Exposure

<2.6.0-r16
  • L
GHSA-w573-9ffj-6ff9

<2.6.0-r16
  • L
GHSA-cc37-9q2j-3hfv

<2.6.0-r15
  • L
Improper Check or Handling of Exceptional Conditions

<2.6.0-r15
  • L
GHSA-5xrh-qmmq-w6ch

<2.6.0-r14
  • L
Allocation of Resources Without Limits or Throttling

<2.6.0-r14
  • L
GHSA-6ghj-frrj-jjj3

<2.6.0-r12
  • L
Resource Exhaustion

<2.6.0-r12
  • L
Improper Access Control

<2.6.0-r12
  • L
GHSA-x4gw-5cx5-pgmh

<2.6.0-r12
  • L
GHSA-3qp7-7mw8-wx86

<2.6.0-r12
  • L
Resource Exhaustion

<2.6.0-r12
  • L
GHSA-3244-j874-rhc2

<2.6.0-r12
  • L
Allocation of Resources Without Limits or Throttling

<2.6.0-r12
  • C
Insufficient Verification of Data Authenticity

<2.6.0-r13
  • L
GHSA-676x-f7gg-47vc

<2.6.0-r13
  • L
GHSA-5pvg-856g-cp85

<2.6.0-r13
  • L
GHSA-xmv7-r254-6q78

<2.6.0-r13
  • L
Resource Exhaustion

<2.6.0-r12
  • L
Use of Insufficiently Random Values

<2.6.0-r13
  • L
GHSA-5x3r-wrvg-rp6q

<2.6.0-r12
  • C
Insufficient Verification of Data Authenticity

<2.6.0-r13
  • L
GHSA-98qh-xjc8-98pq

<2.6.0-r10
  • L
Allocation of Resources Without Limits or Throttling

<2.6.0-r10
  • L
GHSA-cm33-6792-r9fm

<2.6.0-r9
  • L
GHSA-rgrr-p7gp-5xj7

<2.6.0-r9
  • L
Resource Exhaustion

<2.6.0-r9
  • L
GHSA-45q3-82m4-75jr

<2.6.0-r9
  • L
GHSA-jfg9-48mv-9qgx

<2.6.0-r9
  • L
GHSA-57rv-r2g8-2cj3

<2.6.0-r9
  • L
CRLF Injection

<2.6.0-r9
  • L
Integer Overflow or Wraparound

<2.6.0-r9
  • L
GHSA-v8h7-rr48-vmmv

<2.6.0-r9
  • L
GHSA-xxqh-mfjm-7mv9

<2.6.0-r9
  • H
Resource Exhaustion

<2.6.0-r9
  • L
GHSA-m4cv-j2px-7723

<2.6.0-r9
  • C
HTTP Request Smuggling

<2.6.0-r9
  • C
HTTP Request Smuggling

<2.6.0-r9
  • H
CRLF Injection

<2.6.0-r9
  • L
GHSA-mj4r-2hfc-f8p6

<2.6.0-r9
  • L
Resource Exhaustion

<2.6.0-r9
  • C
Improper Input Validation

<2.6.0-r9
  • L
GHSA-38f8-5428-x5cv

<2.6.0-r9
  • H
HTTP Request Smuggling

<2.6.0-r9
  • L
GHSA-f6hv-jmp6-3vwv

<2.6.0-r9
  • H
HTTP Response Splitting

<2.6.0-r9
  • L
Missing Release of Resource after Effective Lifetime

<2.6.0-r8
  • L
GHSA-rwm7-x88c-3g2p

<2.6.0-r8
  • L
GHSA-wf66-mphr-4c4r

<2.6.0-r8
  • L
Race Condition

<2.6.0-r8
  • L
Information Exposure Through Server Log Files

<2.6.0-r8
  • L
GHSA-5qcv-4rpc-jp93

<2.6.0-r8
  • L
GHSA-w9fj-cfpg-grvv

<2.6.0-r6
  • L
GHSA-pwqr-wmgm-9rr8

<2.6.0-r6
  • H
Allocation of Resources Without Limits or Throttling

<2.6.0-r6
  • L
HTTP Request Smuggling

<2.6.0-r6
  • H
Improper Certificate Validation

<2.6.0-r4
  • L
GHSA-crhr-qqj8-rpxc

<2.6.0-r4
  • L
GHSA-7xrh-hqfc-g7qr

<2.6.0-r4
  • H
Information Exposure Through Log Files

<2.6.0-r4
  • L
GHSA-72hv-8253-57qq

<2.6.0-r3
  • L
GHSA-84h7-rjj3-6jx4

<2.5.0-r4
  • L
CRLF Injection

<2.5.0-r4
  • L
Improper Neutralization

<2.5.0-r3
  • L
Directory Traversal

<2.5.0-r3
  • L
Improper Resource Shutdown or Release

<2.5.0-r3
  • L
CRLF Injection

<2.5.0-r1