code-server vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the code-server package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-2mjp-6q6p-2qxm

<4.110.1-r2
  • L
CVE-2026-2581

<4.110.1-r2
  • L
CVE-2026-2229

<4.110.1-r2
  • L
CVE-2026-1528

<4.110.1-r2
  • C
CVE-2026-1525

<4.110.1-r2
  • L
GHSA-vrm6-8vpv-qv8q

<4.110.1-r2
  • L
GHSA-v9p9-hfj2-hcw8

<4.110.1-r2
  • L
CVE-2026-1526

<4.110.1-r2
  • L
CVE-2026-1527

<4.110.1-r2
  • L
GHSA-phc3-fgpg-7m6h

<4.110.1-r2
  • L
GHSA-f269-vfmq-vjvj

<4.110.1-r2
  • L
GHSA-4992-7rv2-5pvq

<4.110.1-r2
  • L
GHSA-gmq8-994r-jv83

<4.110.1-r1
  • M
Off-by-one Error

<4.110.1-r1
  • L
GHSA-vpq2-c234-7xj6

<4.110.1-r1
  • L
CVE-2026-3449

<4.110.1-r1
  • L
Inefficient Regular Expression Complexity

<4.109.2-r0
  • L
Algorithmic Complexity

<4.109.2-r0
  • L
GHSA-7r86-cg39-jmmj

<4.109.2-r0
  • L
GHSA-23c5-xmqv-rm74

<4.109.2-r0
  • L
GHSA-5rq4-664w-9x2c

<4.106.3-r6
  • C
Directory Traversal

<4.106.3-r6
  • H
Inefficient Regular Expression Complexity

<4.106.3-r5
  • H
Directory Traversal

<4.106.3-r5
  • L
GHSA-83g3-92jg-28cx

<4.106.3-r5
  • L
GHSA-3ppc-4f35-3m26

<4.106.3-r5
  • L
GHSA-w7fw-mjwx-w883

<4.106.3-r5
  • H
CVE-2026-2391

<4.106.3-r5
  • L
GHSA-3966-f6p6-2qr9

<4.106.3-r4
  • L
Incorrect Permission Assignment for Critical Resource

<4.106.3-r4
  • M
Improper Handling of Unicode Encoding

<4.106.3-r4
  • L
Directory Traversal

<4.106.3-r4
  • L
GHSA-34x7-hfp2-rc4v

<4.106.3-r4
  • L
GHSA-r6q2-hw4h-h46w

<4.106.3-r4
  • L
GHSA-8qq5-rm4j-mr97

<4.106.3-r2
  • H
Allocation of Resources Without Limits or Throttling

<4.106.3-r2
  • M
Directory Traversal

<4.106.3-r2
  • L
GHSA-g9mf-h72j-4rw9

<4.106.3-r2
  • L
GHSA-8cj5-5rvv-wf4v

<4.105.1-r1
  • L
GHSA-pq67-2wwv-3xjx

<4.105.1-r1
  • L
Directory Traversal

<4.105.1-r1
  • L
GHSA-vj76-c3g6-qr5v

<4.105.1-r1
  • L
CVE-2024-12905

<4.105.1-r1
  • L
Directory Traversal

<4.105.1-r1
  • L
GHSA-6rw7-vpxm-498p

<4.106.3-r1
  • L
CVE-2025-15284

<4.106.3-r1
  • L
GHSA-wqch-xfxh-vrr4

<4.106.2-r1
  • L
CVE-2025-13466

<4.106.2-r1
  • L
GHSA-mh29-5h37-fv8m

<4.106.2-r0
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<4.106.2-r0
  • L
CVE-2025-7339

<4.102.1-r0
  • L
GHSA-76c9-3jph-rj3q

<4.102.1-r0
  • L
GHSA-v6h2-p8h4-qcjw

<4.100.3-r1
  • L
Resource Exhaustion

<4.100.3-r1
  • L
Memory Leak

<4.100.2-r1
  • L
GHSA-cxrh-j4jr-qwg3

<4.100.2-r1