Direct Vulnerabilities

Known vulnerabilities in the pinot package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CRLF Injection

<1.5.1-r7
  • L
GHSA-wh89-7897-x99h

<1.5.1-r7
  • L
Resource Exhaustion

<1.5.1-r7
  • L
GHSA-q6cq-mhr2-jmr5

<1.5.1-r7
  • L
Improper Access Control

<1.5.1-r6
  • L
Resource Exhaustion

<1.5.1-r6
  • L
GHSA-6jqx-86gh-f27w

<1.5.1-r6
  • L
GHSA-6cqp-g7gg-8hr5

<1.5.1-r6
  • L
GHSA-gcjf-9mgh-3p7g

<1.5.1-r6
  • L
Resource Exhaustion

<1.5.1-r6
  • L
HTTP Request Smuggling

<1.5.1-r6
  • L
Allocation of Resources Without Limits or Throttling

<1.5.1-r6
  • L
Resource Exhaustion

<1.5.1-r6
  • L
GHSA-mvh2-crg5-v77c

<1.5.1-r6
  • L
GHSA-q4f6-jm68-57ww

<1.5.1-r6
  • L
GHSA-jppx-w49h-x2qq

<1.5.1-r6
  • L
GHSA-4mp9-239f-g9hg

<1.5.1-r6
  • L
CRLF Injection

<1.5.1-r6
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.5.1-r5
  • L
GHSA-558v-64gr-wgg4

<1.5.1-r5
  • L
GHSA-4qhr-g3c6-fcfx

<1.5.1-r4
  • L
XML External Entity (XXE) Injection

<1.5.1-r4
  • L
Improper Certificate Validation

<1.5.1-r3
  • L
GHSA-272m-gcwp-mpwg

<1.5.1-r3
  • L
Time-of-check Time-of-use (TOCTOU)

<1.5.1-r3
  • L
GHSA-g7hg-vrcf-mvmr

<1.5.1-r3
  • L
GHSA-wc96-39fc-566f

<1.5.1-r3
  • L
Improper Check for Certificate Revocation

<1.5.1-r3
  • L
Resource Exhaustion

<1.5.1-r1
  • L
Resource Exhaustion

<1.5.1-r1
  • L
GHSA-vhch-2wf3-m8rp

<1.5.1-r2
  • L
Resource Exhaustion

<1.5.1-r2
  • L
Incomplete Blacklist

<1.5.1-r1
  • L
Incorrect Authorization

<1.5.1-r1
  • L
GHSA-rmj7-2vxq-3g9f

<1.5.1-r1
  • L
Incomplete Blacklist

<1.5.1-r1
  • L
GHSA-9fxm-vc8v-hj55

<1.5.1-r1
  • L
Incorrect Authorization

<1.5.1-r1
  • L
Server-Side Request Forgery (SSRF)

<1.5.1-r1
  • L
GHSA-hgj6-7826-r7m5

<1.5.1-r1
  • L
GHSA-47qp-hqvx-6r3f

<1.5.1-r1
  • L
GHSA-2r2c-cx56-8933

<1.5.1-r1
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<1.5.1-r1
  • L
GHSA-5hh8-q8hv-fr38

<1.5.1-r1
  • L
GHSA-rcqc-6cw3-h962

<1.5.1-r1
  • L
GHSA-j3rv-43j4-c7qm

<1.5.1-r1
  • L
GHSA-355h-qmc2-wpwf

<1.5.1-r0
  • L
GHSA-wg6q-6289-32hp

<1.5.1-r0
  • L
CVE-2026-0636

<1.5.1-r0
  • L
GHSA-c3fc-8qff-9hwx

<1.5.1-r0
  • C
HTTP Request Smuggling

<1.5.1-r0
  • L
CVE-2026-5588

<1.5.1-r0
  • L
GHSA-w573-9ffj-6ff9

<1.5.0-r22
  • L
GHSA-p93r-85wp-75v3

<1.5.0-r21
  • L
Information Exposure

<1.5.0-r22
  • L
CVE-2026-5598

<1.5.0-r21
  • L
HTTP Request Smuggling

<1.5.0-r21
  • L
GHSA-hvcg-qmg6-jm4c

<1.5.0-r21
  • L
GHSA-5x3r-wrvg-rp6q

<1.5.0-r20
  • L
GHSA-c2gf-v879-257j

<1.5.0-r20
  • L
Resource Exhaustion

<1.5.0-r20
  • H
Resource Exhaustion

<1.5.0-r20
  • L
CRLF Injection

<1.5.0-r19
  • L
GHSA-jq43-27x9-3v86

<1.5.0-r19
  • L
Improper Check or Handling of Exceptional Conditions

<1.5.0-r18
  • L
GHSA-h2qv-fj59-j46j

<1.5.0-r18
  • L
Allocation of Resources Without Limits or Throttling

<1.5.0-r17
  • L
GHSA-5xrh-qmmq-w6ch

<1.5.0-r17
  • H
Memory Leak

<1.5.0-r18
  • L
GHSA-cc37-9q2j-3hfv

<1.5.0-r18
  • L
GHSA-xmv7-r254-6q78

<1.5.0-r16
  • C
Insufficient Verification of Data Authenticity

<1.5.0-r16
  • C
Insufficient Verification of Data Authenticity

<1.5.0-r16
  • L
Use of Insufficiently Random Values

<1.5.0-r16
  • L
GHSA-5pvg-856g-cp85

<1.5.0-r16
  • L
GHSA-676x-f7gg-47vc

<1.5.0-r16
  • L
GHSA-x4gw-5cx5-pgmh

<1.5.0-r15
  • L
GHSA-3qp7-7mw8-wx86

<1.5.0-r15
  • L
Improper Access Control

<1.5.0-r15
  • L
Allocation of Resources Without Limits or Throttling

<1.5.0-r15
  • L
Resource Exhaustion

<1.5.0-r14
  • L
GHSA-3244-j874-rhc2

<1.5.0-r14
  • L
GHSA-6ghj-frrj-jjj3

<1.5.0-r14
  • L
Resource Exhaustion

<1.5.0-r14
  • L
GHSA-337m-mw94-2v6g

<1.5.0-r11
  • L
Uncontrolled Recursion

<1.5.0-r11
  • L
Information Exposure

<1.5.0-r10
  • L
GHSA-fmxf-pm6p-7xgm

<1.5.0-r10
  • L
GHSA-f6hv-jmp6-3vwv

<1.5.0-r5
  • L
GHSA-cm33-6792-r9fm

<1.5.0-r4
  • L
GHSA-rwm7-x88c-3g2p

<1.5.0-r6
  • L
GHSA-jfg9-48mv-9qgx

<1.5.0-r7
  • H
Resource Exhaustion

<1.5.0-r7
  • H
HTTP Response Splitting

<1.5.0-r9
  • L
Resource Exhaustion

<1.5.0-r5
  • L
GHSA-45q3-82m4-75jr

<1.5.0-r9
  • H
CRLF Injection

<1.5.0-r8
  • L
GHSA-mj4r-2hfc-f8p6

<1.5.0-r6
  • L
Missing Release of Resource after Effective Lifetime

<1.5.0-r6
  • L
GHSA-rgrr-p7gp-5xj7

<1.5.0-r8
  • L
Resource Exhaustion

<1.5.0-r6
  • C
Improper Input Validation

<1.5.0-r4
  • L
GHSA-v8h7-rr48-vmmv

<1.5.0-r3
  • L
CRLF Injection

<1.5.0-r3
  • L
Missing Critical Step in Authentication

<1.5.0-r2
  • L
GHSA-v468-qcjx-r72w

<1.5.0-r2
  • L
GHSA-cmxv-58fp-fm3g

<1.5.0-r1
  • L
Information Exposure

<1.5.0-r1
  • H
Improper Encoding or Escaping of Output

<1.5.0-r1
  • L
GHSA-h383-gmxw-35v2

<1.5.0-r1
  • L
CVE-2025-8916

<1.5.0-r0
  • H
Out-of-bounds Read

<1.5.0-r0
  • M
CVE-2024-6763

<1.5.1-r0
  • L
GHSA-4cx2-fc23-5wg6

<1.5.0-r0
  • L
GHSA-vx9q-rhv9-3jvg

<1.5.0-r0
  • L
GHSA-qh8g-58pp-2wxh

<1.5.1-r0
  • M
Improper Input Validation

<1.5.0-r0
  • L
GHSA-wjpw-4j6x-6rwh

<1.5.0-r0
  • L
GHSA-3pxv-7cmr-fjr4

<1.5.0-r0
  • H
Improper Encoding or Escaping of Output

<1.5.0-r0
  • L
GHSA-72hv-8253-57qq

<1.4.0-r8
  • L
GHSA-w9fj-cfpg-grvv

<1.4.0-r5
  • H
Allocation of Resources Without Limits or Throttling

<1.4.0-r5
  • L
HTTP Request Smuggling

<1.4.0-r4
  • L
GHSA-pwqr-wmgm-9rr8

<1.4.0-r4
  • L
GHSA-crhr-qqj8-rpxc

<1.4.0-r3
  • H
Information Exposure Through Log Files

<1.4.0-r3
  • L
Arbitrary Code Injection

<1.4.0-r1
  • L
GHSA-rp46-r563-jrc7

<1.4.0-r1