step-issuer-fips

Direct Vulnerabilities

Known vulnerabilities in the step-issuer-fips package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Open Redirect

<0.9.8-r5
  • L
GHSA-xcvf-46f4-xwxf

<0.9.8-r5
  • L
Information Exposure

<0.12.0-r13
  • L
GHSA-8wmf-6v46-5gfg

<0.12.0-r13
  • L
GHSA-2v4p-qf9q-27wj

<0.12.0-r11
  • L
Improper Validation of Array Index

<0.12.0-r11
  • L
GHSA-vp52-pcj8-j9qc

<0.12.0-r10
  • L
Resource Exhaustion

<0.12.0-r10
  • L
GHSA-jpjm-c3r5-q96r

<0.12.0-r5
  • L
CVE-2026-56852

<0.12.0-r5
  • L
GHSA-hrxh-6v49-42gf

<0.12.0-r4
  • L
Incorrect Authorization

<0.12.0-r3
  • L
GHSA-ff52-ph69-cf7x

<0.12.0-r1
  • L
CVE-2026-42505

<0.12.0-r1
  • L
GHSA-5wrp-cwcj-q835

<0.11.0-r3
  • L
Uncontrolled Memory Allocation

<0.11.0-r3
  • L
GHSA-w879-237q-wc7r

<0.10.2-r7
  • L
GHSA-f5wc-c3c7-36mc

<0.10.2-r7
  • L
GHSA-hfvc-g4fc-pqhx

<0.11.0-r1
  • L
GHSA-89gr-r52h-f8rx

<0.10.2-r7
  • L
GHSA-q4h4-gmj2-qvw2

<0.10.2-r7
  • H
Untrusted Search Path

<0.11.0-r1
  • L
GHSA-rm3j-f69w-wqmq

<0.10.2-r7
  • L
GHSA-h3gm-q7m7-mp28

<0.10.2-r9
  • L
CVE-2026-42507

<0.10.2-r9
  • L
CVE-2026-27145

<0.10.2-r9
  • L
CVE-2026-42504

<0.10.2-r9
  • L
GHSA-4279-q6mj-392r

<0.10.2-r9
  • L
GHSA-h524-452v-82p9

<0.10.2-r9
  • L
Deserialization of Untrusted Data

<0.10.2-r7
  • L
Improper Verification of Cryptographic Signature

<0.10.2-r7
  • L
Integer Overflow or Wraparound

<0.10.2-r7
  • L
Missing Authorization

<0.10.2-r7
  • L
Incorrect Type Conversion or Cast

<0.10.2-r7
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0.10.2-r6
  • H
NULL Pointer Dereference

<0.10.2-r5
  • L
GHSA-497x-jcxf-m478

<0.10.2-r5
  • L
GHSA-2283-wf8c-rw8r

<0.10.2-r5
  • M
Out-of-bounds Write

<0.10.2-r5
  • L
Improper Encoding or Escaping of Output

<0.10.2-r5
  • L
GHSA-qf3q-3h68-mmh2

<0.10.2-r5
  • L
CVE-2026-42501

<0.10.2-r5
  • L
GHSA-3v2c-x6q9-f697

<0.10.2-r5
  • L
GHSA-5m4p-2gjx-p2g8

<0.10.2-r5
  • L
Cross-site Scripting (XSS)

<0.10.2-r5
  • L
GHSA-qc64-m6c2-v4x7

<0.10.2-r5
  • M
Link Following

<0.10.2-r5
  • H
Double Free

<0.10.2-r5
  • L
GHSA-8g2r-hhvj-mv99

<0.10.2-r5
  • C
SQL Injection

<0.10.2-r3
  • L
GHSA-mh2q-q3fh-2475

<0.10.2-r4
  • L
Allocation of Resources Without Limits or Throttling

<0.10.2-r4
  • L
GHSA-j88v-2chj-qfwx

<0.10.2-r3
  • L
GHSA-78h2-9frx-2jm8

<0.10.2-r2
  • L
Uncaught Exception

<0.10.2-r2
  • L
GHSA-5w89-2c2x-6x66

<0.10.2-r1
  • H
Improper Certificate Validation

<0.10.2-r1
  • M
Cross-site Scripting (XSS)

<0.10.2-r1
  • H
Incorrect Authorization

<0.10.2-r1
  • L
GHSA-jrg3-gfjw-hm96

<0.10.2-r1
  • L
GHSA-7mr4-xjxg-34g6

<0.10.2-r1
  • L
GHSA-gjvh-7jh8-7xhm

<0.10.2-r1
  • L
CVE-2026-32280

<0.10.2-r1
  • H
Allocation of Resources Without Limits or Throttling

<0.10.2-r1
  • L
GHSA-m4pr-4j3g-9v7v

<0.10.2-r1
  • L
Improper Authentication

<0.9.11-r10
  • L
Improper Authorization

<0.9.11-r9
  • L
GHSA-q4r8-xm5f-56gw

<0.9.11-r10
  • L
GHSA-p77j-4mvh-x3m3

<0.9.11-r9
  • L
GHSA-j4j7-vw47-rhfq

<0.9.11-r8
  • L
Directory Traversal

<0.9.11-r8
  • L
Direct Request ('Forced Browsing')

<0.9.11-r8
  • L
Cross-site Scripting (XSS)

<0.9.11-r8
  • L
GHSA-j3gx-2473-5fp8

<0.9.11-r8
  • L
GHSA-rv83-g57w-fr8j

<0.9.11-r8
  • L
GHSA-8fj7-8h3w-xwfm

<0.9.11-r6
  • L
CVE-2026-27141

<0.9.11-r6
  • L
GHSA-69x3-g4r3-p962

<0.9.11-r5
  • H
Improper Verification of Cryptographic Signature

<0.9.11-r5
  • L
GHSA-8jvr-vh7g-f8gx

<0.9.11-r4
  • L
CVE-2025-61732

<0.9.11-r4
  • C
CVE-2025-68121

<0.9.11-r4
  • L
GHSA-h355-32pf-p2xm

<0.9.11-r4
  • M
Improper Validation of Array Index

<0.9.11-r3
  • L
GHSA-gx3x-vq4p-mhhv

<0.9.11-r3
  • L
GHSA-hcg3-q754-cr77

<0.9.7-r7
  • L
GHSA-ghw8-3xqw-hhcj

<0.9.6-r0
  • L
GHSA-6v2p-p543-phr9

<0.9.7-r6
  • M
Improper Input Validation

<0.9.6-r0
  • L
CVE-2025-47914

<0.9.9-r5
  • L
GHSA-f6x5-jh6r-wrfv

<0.9.9-r5
  • L
Unprotected Alternate Channel

<0.9.9-r3
  • L
GHSA-vrw8-fxc6-2r93

<0.9.8-r5
  • L
GHSA-6f52-wpx2-hvf2

<0.9.8-r3
  • L
CVE-2025-22874

<0.9.8-r3
  • L
CVE-2025-4673

<0.9.8-r3
  • L
GHSA-62jj-gr2r-5c34

<0.9.8-r3
  • L
CVE-2025-22872

<0.9.8-r2
  • L
CVE-2025-22871

<0.9.8-r1
  • M
Open Redirect

<0.9.8-r0
  • L
CVE-2025-22870

<0.9.7-r8
  • L
CVE-2025-22869

<0.9.7-r7
  • L
CVE-2025-22868

<0.9.7-r6
  • L
Allocation of Resources Without Limits or Throttling

<0.9.7-r5
  • L
CVE-2025-22866

<0.9.7-r3
  • L
CVE-2024-45339

<0.9.7-r2
  • L
CVE-2024-45338

<0.9.6-r2
  • L
CVE-2024-45337

<0.9.6-r1
  • L
CVE-2024-34158

<0.9.3-r1
  • L
CVE-2024-34155

<0.9.3-r1
  • L
CVE-2024-34156

<0.9.3-r1
  • L
CVE-2024-24791

<0.9.2-r1
  • C
CVE-2024-24790

<0.9.1-r6
  • M
CVE-2024-24789

<0.9.1-r6
  • L
CVE-2023-45288

<0.9.1-r3