sonarqube

Direct Vulnerabilities

Known vulnerabilities in the sonarqube package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Algorithmic Complexity

<26.8.0.126808-r3
  • L
Improper Check for Unusual or Exceptional Conditions

<26.8.0.126808-r3
  • L
GHSA-c4c3-7fpv-j4q5

<26.8.0.126808-r3
  • L
GHSA-fccg-mwvh-qqg4

<26.8.0.126808-r3
  • L
GHSA-6qm2-mcq7-53qp

<26.8.0.126808-r1
  • L
CVE-2026-18401

<26.8.0.126808-r1
  • L
GHSA-v3jc-474w-2wm6

<26.8.0.126808-r1
  • L
GHSA-hf6x-8p5f-cgmf

<26.8.0.126808-r1
  • L
GHSA-hjcp-jmpx-g3qm

<26.8.0.126808-r1
  • L
Missing Release of Resource after Effective Lifetime

<26.8.0.126808-r1
  • L
Improper Encoding or Escaping of Output

<26.8.0.126808-r1
  • L
CVE-2026-54399

<26.8.0.126808-r1
  • L
GHSA-qv9r-c865-cp47

<26.8.0.126808-r1
  • L
CVE-2026-54428

<26.8.0.126808-r1
  • L
HTTP Request Smuggling

<26.8.0.126808-r0
  • L
GHSA-5hh8-q8hv-fr38

<26.8.0.126808-r0
  • L
GHSA-hgj6-7826-r7m5

<26.8.0.126808-r1
  • L
GHSA-9342-92gg-6v29

<26.8.0.126808-r2
  • L
GHSA-c653-97m9-rcg9

<26.8.0.126808-r0
  • L
GHSA-5pvg-856g-cp85

<26.8.0.126808-r0
  • L
GHSA-hvcg-qmg6-jm4c

<26.8.0.126808-r0
  • L
Incomplete Blacklist

<26.8.0.126808-r1
  • L
GHSA-5gvw-p9qm-jgwh

<26.8.0.126808-r0
  • H
Improper Neutralization

<26.8.0.126808-r2
  • L
Server-Side Request Forgery (SSRF)

<26.8.0.126808-r1
  • L
Incorrect Authorization

<26.8.0.126808-r0
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<26.8.0.126808-r0
  • L
GHSA-rcqc-6cw3-h962

<26.8.0.126808-r0
  • C
Insufficient Verification of Data Authenticity

<26.8.0.126808-r0
  • L
GHSA-j3rv-43j4-c7qm

<26.8.0.126808-r1
  • L
GHSA-rmj7-2vxq-3g9f

<26.8.0.126808-r1
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<26.8.0.126808-r1
  • L
GHSA-x4gw-5cx5-pgmh

<26.8.0.126808-r0
  • L
Incomplete Blacklist

<26.8.0.126808-r1
  • L
GHSA-5jmj-h7xm-6q6v

<26.8.0.126808-r1
  • L
Incorrect Authorization

<26.8.0.126808-r0
  • L
GHSA-3pjw-73gf-8qr5

<26.8.0.126808-r1
  • L
GHSA-9fxm-vc8v-hj55

<26.8.0.126808-r0
  • M
Allocation of Resources Without Limits or Throttling

<26.8.0.126808-r0
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<26.8.0.126808-r1
  • L
GHSA-3qp7-7mw8-wx86

<26.8.0.126808-r0
  • L
Resource Exhaustion

<26.8.0.126808-r0
  • H
Resource Exhaustion

<26.8.0.126808-r0
  • L
Allocation of Resources Without Limits or Throttling

<26.8.0.126808-r0
  • L
Improper Access Control

<26.8.0.126808-r0
  • L
GHSA-2m67-wjpj-xhg9

<26.8.0.126808-r0
  • L
GHSA-mhm7-754m-9p8w

<26.8.0.126808-r0
  • L
Improper Verification of Cryptographic Signature

<26.8.0.126808-r0
  • L
Use of Insufficiently Random Values

<26.8.0.126808-r0
  • L
GHSA-676x-f7gg-47vc

<26.8.0.126808-r0
  • L
GHSA-5x3r-wrvg-rp6q

<26.8.0.126808-r0
  • L
GHSA-c2gf-v879-257j

<26.8.0.126808-r0
  • L
GHSA-563q-j3cm-6jxm

<26.8.0.126808-r0
  • L
GHSA-r7wm-3cxj-wff9

<26.8.0.126808-r1
  • L
Incorrect Authorization

<26.8.0.126808-r0
  • C
Insufficient Verification of Data Authenticity

<26.8.0.126808-r0
  • L
GHSA-xmv7-r254-6q78

<26.8.0.126808-r0
  • L
GHSA-xx22-p4ch-683r

<26.8.0.126808-r1
  • L
NULL Pointer Dereference

<26.8.0.126808-r1
  • L
Not Failing Securely ('Failing Open')

<26.7.0.124771-r1
  • L
GHSA-j92g-9f8w-j867

<26.7.0.124771-r1
  • L
CVE-2026-10532

<26.7.0.124771-r0
  • L
GHSA-jhq6-gfmj-v8fx

<26.7.0.124771-r0
  • L
GHSA-mj4r-2hfc-f8p6

<26.7.0.124771-r0
  • L
CVE-2026-9828

<26.7.0.124771-r0
  • H
HTTP Request Smuggling

<26.7.0.124771-r0
  • C
HTTP Request Smuggling

<26.7.0.124771-r0
  • L
GHSA-p47f-322f-whfh

<26.7.0.124771-r0
  • H
Improper Encoding or Escaping of Output

<26.7.0.124771-r0
  • L
GHSA-w9fj-cfpg-grvv

<26.7.0.124771-r0
  • C
HTTP Request Smuggling

<26.7.0.124771-r0
  • L
GHSA-38f8-5428-x5cv

<26.7.0.124771-r0
  • L
GHSA-h383-gmxw-35v2

<26.7.0.124771-r0
  • L
CRLF Injection

<26.7.0.124771-r0
  • M
Improper Validation of Certificate with Host Mismatch

<26.7.0.124771-r0
  • L
GHSA-v8h7-rr48-vmmv

<26.7.0.124771-r0
  • L
GHSA-c3fc-8qff-9hwx

<26.7.0.124771-r0
  • L
GHSA-xxqh-mfjm-7mv9

<26.7.0.124771-r0
  • L
GHSA-f6hv-jmp6-3vwv

<26.7.0.124771-r0
  • L
GHSA-m4cv-j2px-7723

<26.7.0.124771-r0
  • L
GHSA-445c-vh5m-36rj

<26.7.0.124771-r0
  • H
Improper Output Neutralization for Logs

<26.7.0.124771-r0
  • L
Resource Exhaustion

<26.7.0.124771-r0
  • L
GHSA-57rv-r2g8-2cj3

<26.7.0.124771-r0
  • L
GHSA-wg6q-6289-32hp

<26.7.0.124771-r0
  • L
GHSA-pwqr-wmgm-9rr8

<26.7.0.124771-r0
  • L
Integer Overflow or Wraparound

<26.7.0.124771-r0
  • C
Improper Input Validation

<26.7.0.124771-r0
  • L
GHSA-6hg6-v5c8-fphq

<26.7.0.124771-r0
  • L
GHSA-3pxv-7cmr-fjr4

<26.7.0.124771-r0
  • L
HTTP Request Smuggling

<26.7.0.124771-r0
  • L
CVE-2026-5588

<26.7.0.124771-r0
  • H
Improper Encoding or Escaping of Output

<26.7.0.124771-r0
  • L
CVE-2026-0636

<26.7.0.124771-r0
  • H
Allocation of Resources Without Limits or Throttling

<26.7.0.124771-r0
  • L
GHSA-cm33-6792-r9fm

<26.7.0.124771-r0
  • L
Resource Exhaustion

<26.7.0.124771-r0
  • L
CVE-2025-14813

<26.6.0.123539-r1
  • L
GHSA-574f-3g2m-x479

<26.6.0.123539-r1
  • L
CVE-2026-5598

<26.6.0.123539-r0
  • L
GHSA-p93r-85wp-75v3

<26.6.0.123539-r0
  • L
Allocation of Resources Without Limits or Throttling

<26.4.0.121862-r1
  • L
GHSA-98qh-xjc8-98pq

<26.4.0.121862-r1
  • L
GHSA-j288-q9x7-2f5v

<26.8.0.126808-r0
  • L
Uncontrolled Recursion

<26.8.0.126808-r0
  • M
Improper Certificate Validation

<26.7.0.124771-r0
  • L
GHSA-72hv-8253-57qq

<26.8.0.126808-r1
  • L
GHSA-vc5p-v9hr-52mj

<26.7.0.124771-r0
  • L
GHSA-cmp6-m4wj-q63q

<26.2.0.119303-r2
  • L
CRLF Injection

<26.2.0.119303-r2
  • L
GHSA-84h7-rjj3-6jx4

<26.2.0.119303-r2
  • L
Information Exposure

<26.2.0.119303-r2
  • L
GHSA-6v53-7c9g-w56r

<26.2.0.119303-r1
  • H
Allocation of Resources Without Limits or Throttling

<26.2.0.119303-r1
  • L
CVE-2026-1225

<26.1.0.118079-r2
  • L
GHSA-qqpg-mvqg-649v

<26.1.0.118079-r2
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<25.12.0.117093-r1
  • L
GHSA-fghv-69vj-qj49

<25.12.0.117093-r1
  • L
GHSA-wxr5-93ph-8wr9

<25.12.0.117093-r0
  • L
CVE-2025-48734

<25.12.0.117093-r0
  • L
GHSA-qf7c-7r9h-mm92

<25.12.0.117093-r2
  • L
CVE-2025-68384

<25.12.0.117093-r2
  • H
Allocation of Resources Without Limits or Throttling

<25.12.0.117093-r1
  • L
GHSA-3p8m-j85q-pgmj

<25.12.0.117093-r1
  • H
HTTP Request Smuggling

<25.12.0.117093-r1
  • L
GHSA-25qh-j22f-pwp8

<25.11.0.114957-r0
  • L
CVE-2025-11226

<25.11.0.114957-r0
  • L
GHSA-prj3-ccx8-p6x4

<25.12.0.117093-r1
  • H
CVE-2025-37731

<25.12.0.117093-r1
  • L
GHSA-m9gh-789g-q5pv

<25.12.0.117093-r1
  • L
CVE-2025-68390

<25.12.0.117093-r0
  • L
GHSA-gphj-4h6p-37xq

<25.12.0.117093-r0
  • L
GHSA-78wr-2p64-hpwj

<25.6.0.109173-r0
  • L
CVE-2024-12801

<25.6.0.109173-r0
  • L
Resource Exhaustion

<25.6.0.109173-r0
  • L
Resource Exhaustion

<25.6.0.109173-r0
  • L
GHSA-xq3w-v528-46rv

<25.6.0.109173-r0
  • L
CVE-2024-12798

<25.6.0.109173-r0
  • L
GHSA-pr98-23f8-jwxv

<25.6.0.109173-r0
  • L
GHSA-6v67-2wr5-gvf4

<25.6.0.109173-r0