traccar

Direct Vulnerabilities

Known vulnerabilities in the traccar package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-89425

<6.16.0-r3
  • L
GHSA-p6pp-m3f8-5c89

<6.16.0-r3
  • L
GHSA-7hhh-6rmp-j9qf

<6.16.0-r3
  • L
CVE-2026-89407

<6.16.0-r3
  • L
GHSA-wv8q-qhhj-9h54

<6.16.0-r2
  • L
CVE-2026-83557

<6.16.0-r1
  • L
GHSA-gx83-3vf8-gh7j

<6.16.0-r1
  • L
CVE-2026-91776

<6.16.0-r2
  • L
CVE-2026-91777

<6.16.0-r2
  • L
GHSA-cxp5-3px4-pw24

<6.16.0-r2
  • L
CVE-2026-68497

<6.16.0-r1
  • L
GHSA-q4xh-88c3-wmh7

<6.16.0-r1
  • L
CVE-2026-19032

<6.16.0-r1
  • L
GHSA-wjgm-6hv5-3cvf

<6.16.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<6.15.3-r1
  • L
GHSA-jh4v-gfqj-7rhx

<6.15.3-r1
  • L
Improper Encoding or Escaping of Output

<6.14.5-r8
  • L
GHSA-qv9r-c865-cp47

<6.14.5-r8
  • L
Uncontrolled Recursion

<6.14.5-r7
  • L
GHSA-68mj-5wr7-6fgg

<6.14.5-r7
  • L
Improper Input Validation

<6.14.5-r7
  • L
Uncontrolled Memory Allocation

<6.14.5-r7
  • L
GHSA-93j5-89vc-pph4

<6.14.5-r7
  • L
Improper Certificate Validation

<6.14.5-r7
  • L
GHSA-5xwg-cfvj-gff5

<6.14.5-r7
  • L
GHSA-5m9f-rphj-c435

<6.14.5-r7
  • L
GHSA-6g32-pxv4-2wfj

<6.14.5-r7
  • L
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

<6.14.5-r7
  • L
GHSA-hjcp-jmpx-g3qm

<6.14.5-r6
  • L
Missing Release of Resource after Effective Lifetime

<6.14.5-r6
  • L
GHSA-8c42-7qj2-3j46

<6.14.5-r5
  • H
Information Exposure Through Caching

<6.14.5-r5
  • L
CVE-2026-54428

<6.14.5-r4
  • L
GHSA-v3jc-474w-2wm6

<6.14.5-r4
  • H
Missing Release of Resource after Effective Lifetime

<6.14.5-r1
  • L
CVE-2026-54399

<6.14.5-r3
  • L
GHSA-hf6x-8p5f-cgmf

<6.14.5-r3
  • L
NULL Pointer Dereference

<6.14.5-r2
  • L
GHSA-xx22-p4ch-683r

<6.14.5-r2
  • L
GHSA-2fvj-hgj9-j2gr

<6.14.5-r1
  • L
GHSA-558v-64gr-wgg4

<6.14.5-r1
  • L
GHSA-mfg7-5gfp-c4w3

<6.14.5-r1
  • L
GHSA-q4f6-jm68-57ww

<6.14.5-r1
  • L
GHSA-gcjf-9mgh-3p7g

<6.14.5-r1
  • L
GHSA-mvh2-crg5-v77c

<6.14.5-r1
  • C
Improper Handling of Alternate Encoding

<6.14.5-r1
  • L
Not Failing Securely ('Failing Open')

<6.14.5-r1
  • L
Improper Access Control

<6.14.5-r1
  • H
HTTP Request Smuggling

<6.14.5-r1
  • L
Improper Input Validation

<6.14.5-r1
  • H
Resource Exhaustion

<6.14.5-r1
  • H
Allocation of Resources Without Limits or Throttling

<6.14.5-r1
  • M
CRLF Injection

<6.14.5-r1
  • L
GHSA-w7x5-g22v-xqhr

<6.14.5-r1
  • M
HTTP Request Smuggling

<6.14.5-r1
  • L
GHSA-c69g-56f8-xwqj

<6.14.5-r1
  • L
Resource Exhaustion

<6.14.5-r1
  • L
GHSA-6jqx-86gh-f27w

<6.14.5-r1
  • L
GHSA-f4v5-65jj-pcr2

<6.14.5-r1
  • L
GHSA-j92g-9f8w-j867

<6.14.5-r1
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<6.14.5-r1
  • L
GHSA-7p3p-8qv8-m2vh

<6.14.5-r1
  • L
GHSA-6cqp-g7gg-8hr5

<6.14.5-r1
  • L
GHSA-jppx-w49h-x2qq

<6.14.5-r1
  • L
Use of Non-Canonical URL Paths for Authorization Decisions

<6.14.5-r1
  • L
Information Exposure

<6.14.5-r1
  • L
Resource Exhaustion

<6.14.5-r1
  • L
GHSA-4mp9-239f-g9hg

<6.14.5-r1