Direct Vulnerabilities

Known vulnerabilities in the akhq package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-642r-3gj9-2pj5

<0.28.0-r2
  • L
CVE-2026-68494

<0.28.0-r2
  • L
CVE-2026-89425

<0.28.0-r12
  • L
GHSA-p6pp-m3f8-5c89

<0.28.0-r12
  • L
CVE-2026-89407

<0.28.0-r12
  • L
GHSA-7hhh-6rmp-j9qf

<0.28.0-r12
  • L
GHSA-gx83-3vf8-gh7j

<0.28.0-r11
  • L
GHSA-q4xh-88c3-wmh7

<0.28.0-r11
  • L
GHSA-wjgm-6hv5-3cvf

<0.28.0-r11
  • L
CVE-2026-19032

<0.28.0-r11
  • L
CVE-2026-68497

<0.28.0-r11
  • L
CVE-2026-83557

<0.28.0-r11
  • L
GHSA-vvgp-rfg2-7rr6

<0.28.0-r10
  • L
Server-Side Request Forgery (SSRF)

<0.28.0-r10
  • L
GHSA-5q95-hrpc-m3w3

<0.28.0-r9
  • L
Inefficient Regular Expression Complexity

<0.28.0-r9
  • L
GHSA-r2xf-8xr9-62gw

<0.28.0-r9
  • L
Inefficient Regular Expression Complexity

<0.28.0-r9
  • L
Inefficient Regular Expression Complexity

<0.28.0-r9
  • L
GHSA-ph9c-7hw9-vhhw

<0.28.0-r9
  • L
GHSA-fccg-mwvh-qqg4

<0.28.0-r8
  • L
GHSA-c4c3-7fpv-j4q5

<0.28.0-r8
  • L
GHSA-3g76-f9xq-8vp6

<0.28.0-r8
  • M
Allocation of Resources Without Limits or Throttling

<0.28.0-r8
  • C
Improper Check for Unusual or Exceptional Conditions

<0.28.0-r8
  • H
Algorithmic Complexity

<0.28.0-r8
  • L
CVE-2026-18401

<0.26.0-r9
  • L
GHSA-6qm2-mcq7-53qp

<0.26.0-r9
  • L
GHSA-8c42-7qj2-3j46

<0.28.0-r7
  • H
Information Exposure Through Caching

<0.28.0-r7
  • L
Improper Encoding or Escaping of Output

<0.28.0-r6
  • L
GHSA-qv9r-c865-cp47

<0.28.0-r6
  • L
GHSA-v3jc-474w-2wm6

<0.28.0-r4
  • L
CVE-2026-54428

<0.28.0-r4
  • L
Missing Release of Resource after Effective Lifetime

<0.28.0-r5
  • L
GHSA-hjcp-jmpx-g3qm

<0.28.0-r5
  • H
Missing Release of Resource after Effective Lifetime

<0.27.1-r14
  • L
GHSA-hf6x-8p5f-cgmf

<0.28.0-r3
  • L
CVE-2026-54399

<0.28.0-r3
  • L
GHSA-r7wm-3cxj-wff9

<0.28.0-r2
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<0.28.0-r2
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<0.28.0-r2
  • L
GHSA-3pjw-73gf-8qr5

<0.28.0-r2
  • L
Incorrect Authorization

<0.28.0-r2
  • L
Incorrect Authorization

<0.28.0-r2
  • L
GHSA-9fxm-vc8v-hj55

<0.28.0-r2
  • L
Information Exposure

<0.28.0-r2
  • L
GHSA-rcqc-6cw3-h962

<0.28.0-r2
  • L
GHSA-5hh8-q8hv-fr38

<0.28.0-r2
  • L
GHSA-w573-9ffj-6ff9

<0.28.0-r2
  • L
NULL Pointer Dereference

<0.27.1-r17
  • L
GHSA-f4v5-65jj-pcr2

<0.27.1-r16
  • L
Information Exposure

<0.27.1-r16
  • L
GHSA-xx22-p4ch-683r

<0.27.1-r17
  • L
Improper Input Validation

<0.27.1-r15
  • M
HTTP Request Smuggling

<0.27.1-r14
  • L
Incorrect Authorization

<0.27.1-r14
  • L
Use of Non-Canonical URL Paths for Authorization Decisions

<0.27.1-r15
  • L
GHSA-7p3p-8qv8-m2vh

<0.27.1-r15
  • L
GHSA-5gvw-p9qm-jgwh

<0.27.1-r14
  • L
GHSA-w7x5-g22v-xqhr

<0.27.1-r15
  • L
GHSA-mhm7-754m-9p8w

<0.27.1-r14
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<0.27.1-r14
  • L
GHSA-c69g-56f8-xwqj

<0.27.1-r14
  • L
GHSA-mfg7-5gfp-c4w3

<0.27.1-r14
  • L
GHSA-5jmj-h7xm-6q6v

<0.27.1-r14
  • L
Missing Release of Resource after Effective Lifetime

<0.27.1-r13
  • L
GHSA-rwm7-x88c-3g2p

<0.27.1-r13
  • L
GHSA-q4f6-jm68-57ww

<0.27.1-r12
  • L
GHSA-mvh2-crg5-v77c

<0.27.1-r12
  • H
Allocation of Resources Without Limits or Throttling

<0.27.1-r12
  • L
GHSA-4mp9-239f-g9hg

<0.27.1-r12
  • L
GHSA-6jqx-86gh-f27w

<0.27.1-r12
  • M
CRLF Injection

<0.27.1-r12
  • L
GHSA-6cqp-g7gg-8hr5

<0.27.1-r12
  • L
Resource Exhaustion

<0.27.1-r12
  • L
Improper Access Control

<0.27.1-r12
  • L
Resource Exhaustion

<0.27.1-r12
  • L
GHSA-gcjf-9mgh-3p7g

<0.27.1-r12
  • H
Resource Exhaustion

<0.27.1-r12
  • L
GHSA-jppx-w49h-x2qq

<0.27.1-r12
  • H
HTTP Request Smuggling

<0.27.1-r12
  • L
GHSA-558v-64gr-wgg4

<0.27.1-r11
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0.27.1-r11
  • L
GHSA-2fvj-hgj9-j2gr

<0.27.1-r10
  • C
Improper Handling of Alternate Encoding

<0.27.1-r10
  • L
CVE-2026-10532

<0.27.1-r8
  • L
GHSA-jhq6-gfmj-v8fx

<0.27.1-r8
  • L
CVE-2026-9828

<0.27.1-r7
  • L
GHSA-p47f-322f-whfh

<0.27.1-r7
  • L
Server-Side Request Forgery (SSRF)

<0.27.1-r5
  • L
Incomplete Blacklist

<0.27.1-r5
  • L
GHSA-j3rv-43j4-c7qm

<0.27.1-r5
  • L
GHSA-rmj7-2vxq-3g9f

<0.27.1-r5
  • L
Incomplete Blacklist

<0.27.1-r5
  • L
GHSA-hgj6-7826-r7m5

<0.27.1-r5
  • L
GHSA-xmv7-r254-6q78

<0.27.1-r3
  • L
Allocation of Resources Without Limits or Throttling

<0.27.1-r3
  • L
Resource Exhaustion

<0.27.1-r3
  • L
GHSA-5pvg-856g-cp85

<0.27.1-r3
  • L
GHSA-c2gf-v879-257j

<0.27.1-r3
  • L
Improper Access Control

<0.27.1-r3
  • L
GHSA-5x3r-wrvg-rp6q

<0.27.1-r3
  • C
Insufficient Verification of Data Authenticity

<0.27.1-r3
  • L
Use of Insufficiently Random Values

<0.27.1-r3
  • C
Insufficient Verification of Data Authenticity

<0.27.1-r3
  • L
GHSA-676x-f7gg-47vc

<0.27.1-r3
  • H
Resource Exhaustion

<0.27.1-r3
  • L
GHSA-x4gw-5cx5-pgmh

<0.27.1-r3
  • L
GHSA-3qp7-7mw8-wx86

<0.27.1-r3
  • L
CRLF Injection

<0.27.1-r1
  • L
GHSA-xxqh-mfjm-7mv9

<0.27.1-r1
  • C
Improper Input Validation

<0.27.1-r1
  • C
HTTP Request Smuggling

<0.27.1-r1
  • L
Integer Overflow or Wraparound

<0.27.1-r1
  • C
HTTP Request Smuggling

<0.27.1-r1
  • L
GHSA-f6hv-jmp6-3vwv

<0.27.1-r1
  • L
GHSA-cm33-6792-r9fm

<0.27.1-r1
  • H
HTTP Request Smuggling

<0.27.1-r1
  • L
GHSA-v8h7-rr48-vmmv

<0.27.1-r1
  • L
GHSA-m4cv-j2px-7723

<0.27.1-r1
  • L
GHSA-38f8-5428-x5cv

<0.27.1-r1
  • L
GHSA-57rv-r2g8-2cj3

<0.27.1-r1
  • L
GHSA-mj4r-2hfc-f8p6

<0.27.1-r1
  • L
Resource Exhaustion

<0.27.1-r1
  • H
HTTP Response Splitting

<0.27.1-r1
  • L
Resource Exhaustion

<0.27.1-r1
  • L
GHSA-45q3-82m4-75jr

<0.27.1-r1
  • L
GHSA-h383-gmxw-35v2

<0.27.0-r2
  • C
HTTP Request Smuggling

<0.27.0-r2
  • L
GHSA-355h-qmc2-wpwf

<0.27.0-r2
  • H
Improper Output Neutralization for Logs

<0.27.0-r2
  • M
Improper Validation of Certificate with Host Mismatch

<0.27.0-r2
  • L
GHSA-445c-vh5m-36rj

<0.27.0-r2
  • H
Improper Encoding or Escaping of Output

<0.27.0-r2
  • H
Improper Encoding or Escaping of Output

<0.27.0-r2
  • L
GHSA-3pxv-7cmr-fjr4

<0.27.0-r2
  • L
GHSA-6hg6-v5c8-fphq

<0.27.0-r2
  • L
GHSA-vc5p-v9hr-52mj

<0.27.0-r1
  • L
GHSA-xxh7-fcf3-rj7f

<0.27.0-r1
  • L
GHSA-6fmv-xxpf-w3cw

<0.27.0-r1
  • H
CVE-2025-67030

<0.27.0-r1
  • L
Resource Exhaustion

<0.27.0-r1
  • M
Improper Certificate Validation

<0.27.0-r1
  • L
HTTP Request Smuggling

<0.27.0-r0
  • L
GHSA-pwqr-wmgm-9rr8

<0.27.0-r0
  • H
Allocation of Resources Without Limits or Throttling

<0.27.0-r0
  • L
GHSA-w9fj-cfpg-grvv

<0.27.0-r0
  • H
Information Exposure Through Log Files

<0.26.0-r11
  • L
GHSA-crhr-qqj8-rpxc

<0.26.0-r11
  • H
Improper Certificate Validation

<0.26.0-r11
  • L
GHSA-7xrh-hqfc-g7qr

<0.26.0-r11
  • L
GHSA-wjpw-4j6x-6rwh

<0.26.0-r10
  • M
Improper Input Validation

<0.26.0-r10
  • L
GHSA-72hv-8253-57qq

<0.26.0-r9
  • L
Arbitrary Code Injection

<0.26.0-r8
  • L
GHSA-rp46-r563-jrc7

<0.26.0-r8
  • L
GHSA-qqpg-mvqg-649v

<0.26.0-r7
  • L
CVE-2026-1225

<0.26.0-r7
  • L
GHSA-prj3-ccx8-p6x4

<0.26.0-r3
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<0.26.0-r4
  • L
GHSA-3p8m-j85q-pgmj

<0.26.0-r4
  • H
Allocation of Resources Without Limits or Throttling

<0.26.0-r3
  • L
GHSA-fghv-69vj-qj49

<0.26.0-r4
  • L
CRLF Injection

<0.26.0-r4
  • L
GHSA-84h7-rjj3-6jx4

<0.26.0-r4
  • H
HTTP Request Smuggling

<0.26.0-r4
  • L
CVE-2025-11226

<0.26.0-r3
  • L
Uncontrolled Recursion

<0.26.0-r0
  • L
Uncontrolled Recursion

<0.26.0-r0
  • L
CVE-2025-48734

<0.25.1-r4
  • L
CVE-2024-57699

<0.25.1-r3
  • L
CVE-2025-24970

<0.25.1-r3
  • M
CVE-2024-6763

<0.25.1-r3
  • L
CVE-2024-12798

<0.25.1-r2
  • L
CVE-2024-12801

<0.25.1-r2
  • L
Deserialization of Untrusted Data

<0.25.1-r1