conftest

Direct Vulnerabilities

Known vulnerabilities in the conftest package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-fxhp-mv3v-67qp

<0.69.0-r0
  • L
Directory Traversal

<0.69.0-r0
  • L
CVE-2026-56852

<0.68.2-r8
  • L
GHSA-jpjm-c3r5-q96r

<0.68.2-r8
  • L
GHSA-hrxh-6v49-42gf

<0.68.2-r7
  • L
GHSA-ff52-ph69-cf7x

<0.68.2-r6
  • L
GHSA-5wrp-cwcj-q835

<0.68.2-r6
  • L
CVE-2026-42505

<0.68.2-r6
  • L
Uncontrolled Memory Allocation

<0.68.2-r6
  • L
GHSA-vh4v-2xq2-g5cg

<0.68.2-r5
  • L
Server-Side Request Forgery (SSRF)

<0.68.2-r5
  • L
Cleartext Transmission of Sensitive Information

<0.68.2-r5
  • L
GHSA-8xwf-rjm4-xvhv

<0.68.2-r5
  • L
GHSA-xf85-363p-868w

<0.68.2-r5
  • L
GHSA-jxpm-75mh-9fp7

<0.68.2-r5
  • L
External Control of File Name or Path

<0.68.2-r5
  • L
GHSA-w2q5-6q6x-x959

<0.68.2-r4
  • L
GHSA-h3gm-q7m7-mp28

<0.68.2-r4
  • L
CVE-2026-42507

<0.68.2-r4
  • L
CVE-2026-39821

<0.68.2-r4
  • L
CVE-2026-27145

<0.68.2-r4
  • L
GHSA-4279-q6mj-392r

<0.68.2-r4
  • L
GHSA-2283-wf8c-rw8r

<0.68.2-r3
  • H
Double Free

<0.68.2-r3
  • L
CVE-2026-42501

<0.68.2-r3
  • L
GHSA-qf3q-3h68-mmh2

<0.68.2-r3
  • M
Out-of-bounds Write

<0.68.2-r3
  • L
GHSA-p9h5-jm8x-mjm5

<0.68.2-r3
  • L
GHSA-497x-jcxf-m478

<0.68.2-r3
  • L
Improper Encoding or Escaping of Output

<0.68.2-r3
  • L
GHSA-8g2r-hhvj-mv99

<0.68.2-r3
  • L
GHSA-qc64-m6c2-v4x7

<0.68.2-r3
  • H
NULL Pointer Dereference

<0.68.2-r3
  • H
Allocation of Resources Without Limits or Throttling

<0.68.2-r3
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0.68.2-r3
  • M
Link Following

<0.68.2-r3
  • L
GHSA-5m4p-2gjx-p2g8

<0.68.2-r3
  • L
CVE-2026-42499

<0.68.2-r3
  • L
GHSA-xq5j-9r39-c3vf

<0.68.2-r3
  • L
Cross-site Scripting (XSS)

<0.68.2-r3
  • L
GHSA-3v2c-x6q9-f697

<0.68.2-r3
  • L
GHSA-xmrv-pmrh-hhx2

<0.68.2-r1
  • L
CVE-2026-4660

<0.68.2-r0
  • L
GHSA-92mm-2pjq-r785

<0.68.2-r0
  • L
GHSA-hfvc-g4fc-pqhx

<0.68.0-r1
  • H
Untrusted Search Path

<0.68.0-r1
  • L
GHSA-78h2-9frx-2jm8

<0.68.0-r0
  • L
Uncaught Exception

<0.68.0-r0
  • L
GHSA-4vrq-3vrq-g6gg

<0.67.1-r2
  • C
Directory Traversal

<0.67.1-r2
  • L
GHSA-4c29-8rgm-jvjj

<0.67.1-r2
  • H
Directory Traversal

<0.67.1-r2
  • L
GHSA-p77j-4mvh-x3m3

<0.67.1-r1
  • L
Improper Authorization

<0.67.1-r1
  • L
Cross-site Scripting (XSS)

<0.66.0-r4
  • L
GHSA-j4j7-vw47-rhfq

<0.66.0-r4
  • L
GHSA-j3gx-2473-5fp8

<0.66.0-r4
  • L
GHSA-rv83-g57w-fr8j

<0.66.0-r4
  • L
Direct Request ('Forced Browsing')

<0.66.0-r4
  • L
Directory Traversal

<0.66.0-r4
  • L
GHSA-9h8m-3fm2-qjrq

<0.66.0-r3
  • L
Untrusted Search Path

<0.66.0-r3
  • L
GHSA-8jvr-vh7g-f8gx

<0.66.0-r2
  • L
GHSA-h355-32pf-p2xm

<0.66.0-r2
  • C
CVE-2025-68121

<0.66.0-r2
  • L
CVE-2025-61732

<0.66.0-r2
  • L
GHSA-gr56-3gp6-6gmj

<0.66.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.66.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.66.0-r1
  • L
GHSA-xvqr-69v8-f3gv

<0.66.0-r1
  • L
CVE-2025-61731

<0.66.0-r1
  • L
Out-of-bounds Write

<0.66.0-r1
  • L
GHSA-gm9r-q53w-2gh4

<0.66.0-r1
  • L
CVE-2025-61730

<0.66.0-r1
  • L
GHSA-g9q4-qjx4-2v7q

<0.66.0-r1
  • L
GHSA-cm6p-qc7v-m3jw

<0.66.0-r1
  • L
GHSA-6v2p-p543-phr9

<0.58.0-r3
  • L
GHSA-hcg3-q754-cr77

<0.58.0-r1
  • L
CVE-2025-58181

<0.64.0-r1
  • L
GHSA-j5w8-q4qc-rx2x

<0.64.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.63.0-r1
  • L
Algorithmic Complexity

<0.63.0-r1
  • L
CVE-2025-58183

<0.63.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.63.0-r1
  • L
CVE-2025-58186

<0.63.0-r1
  • L
Information Exposure Through Log Files

<0.63.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.63.0-r1
  • L
Improper Certificate Validation

<0.63.0-r1
  • L
CVE-2025-47912

<0.63.0-r1
  • L
CVE-2025-61725

<0.63.0-r1
  • L
CVE-2025-47910

<0.62.0-r6
  • L
CVE-2025-8959

<0.62.0-r3
  • L
Race Condition

<0.62.0-r2
  • L
Arbitrary Code Injection

<0.59.0-r1
  • L
CVE-2025-22871

<0.58.0-r3
  • L
CVE-2025-22868

<0.58.0-r3
  • L
CVE-2025-22870

<0.58.0-r2
  • L
CVE-2025-22869

<0.58.0-r1
  • L
CVE-2025-22866

<0.56.0-r4
  • L
CVE-2024-45336

<0.56.0-r3
  • L
CVE-2024-45341

<0.56.0-r3
  • L
CVE-2024-45338

<0.56.0-r2
  • L
CVE-2024-45337

<0.56.0-r1
  • H
Authentication Bypass

<0.55.0-r2
  • L
CVE-2024-34158

<0.55.0-r1
  • L
CVE-2024-34156

<0.55.0-r1
  • L
CVE-2024-34155

<0.55.0-r1
  • L
CVE-2024-24791

<0.53.0-r2
  • H
CVE-2024-6257

<0.53.0-r1
  • C
CVE-2024-24790

<0.52.0-r3
  • M
CVE-2024-24789

<0.52.0-r3
  • L
CVE-2024-24788

<0.52.0-r1
  • L
CVE-2024-24787

<0.52.0-r1
  • L
CVE-2024-3817

<0.52.0-r0
  • L
CVE-2023-45288

<0.51.0-r1
  • H
Incorrect Resource Transfer Between Spheres

<0.50.0-r2
  • L
CVE-2024-24786

<0.50.0-r1
  • C
Directory Traversal

<0.49.0-r1
  • C
Incorrect Authorization

<0.49.0-r1
  • H
Race Condition

<0.49.0-r1
  • M
Improper Check for Unusual or Exceptional Conditions

<0.49.0-r1
  • M
Improper Validation of Integrity Check Value

<0.47.0-r3
  • H
CVE-2023-44487

<0.46.0-r1