spark-fips-4.2

Direct Vulnerabilities

Known vulnerabilities in the spark-fips-4.2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-89425

<4.2.0-r13
  • L
CVE-2026-89407

<4.2.0-r13
  • L
GHSA-7hhh-6rmp-j9qf

<4.2.0-r13
  • L
GHSA-p6pp-m3f8-5c89

<4.2.0-r13
  • L
CVE-2026-68494

<4.2.0-r8
  • L
GHSA-642r-3gj9-2pj5

<4.2.0-r8
  • L
CVE-2026-19032

<4.2.0-r12
  • L
GHSA-q4xh-88c3-wmh7

<4.2.0-r12
  • L
CVE-2026-68497

<4.2.0-r12
  • L
GHSA-wjgm-6hv5-3cvf

<4.2.0-r12
  • L
CVE-2026-83557

<4.2.0-r12
  • L
GHSA-gx83-3vf8-gh7j

<4.2.0-r12
  • L
Inefficient Regular Expression Complexity

<4.2.0-r11
  • L
GHSA-r2xf-8xr9-62gw

<4.2.0-r11
  • L
GHSA-5q95-hrpc-m3w3

<4.2.0-r11
  • L
Inefficient Regular Expression Complexity

<4.2.0-r11
  • L
Inefficient Regular Expression Complexity

<4.2.0-r11
  • L
GHSA-ph9c-7hw9-vhhw

<4.2.0-r11
  • L
GHSA-c4c3-7fpv-j4q5

<4.2.0-r9
  • L
GHSA-fccg-mwvh-qqg4

<4.2.0-r9
  • H
Algorithmic Complexity

<4.2.0-r9
  • C
Improper Check for Unusual or Exceptional Conditions

<4.2.0-r9
  • L
GHSA-9fxm-vc8v-hj55

<4.2.0-r8
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<4.2.0-r8
  • L
Incorrect Authorization

<4.2.0-r8
  • L
Incomplete Blacklist

<4.2.0-r8
  • L
GHSA-5hh8-q8hv-fr38

<4.2.0-r8
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<4.2.0-r8
  • L
GHSA-2r2c-cx56-8933

<4.2.0-r10
  • L
Resource Exhaustion

<4.2.0-r10
  • L
Incorrect Authorization

<4.2.0-r8
  • L
GHSA-rcqc-6cw3-h962

<4.2.0-r8
  • L
GHSA-j3rv-43j4-c7qm

<4.2.0-r8
  • L
Incomplete Blacklist

<4.2.0-r8
  • L
GHSA-hgj6-7826-r7m5

<4.2.0-r8
  • L
Server-Side Request Forgery (SSRF)

<4.2.0-r8
  • L
GHSA-rmj7-2vxq-3g9f

<4.2.0-r8
  • L
GHSA-r7wm-3cxj-wff9

<4.2.0-r8
  • L
Resource Exhaustion

<4.2.0-r10
  • L
GHSA-3pjw-73gf-8qr5

<4.2.0-r8
  • L
GHSA-47qp-hqvx-6r3f

<4.2.0-r10
  • L
GHSA-8c42-7qj2-3j46

<4.2.0-r5
  • H
Information Exposure Through Caching

<4.2.0-r5
  • L
GHSA-qv9r-c865-cp47

<4.2.0-r4
  • L
Improper Encoding or Escaping of Output

<4.2.0-r4
  • H
Missing Release of Resource after Effective Lifetime

<4.2.0-r3
  • L
GHSA-5jmj-h7xm-6q6v

<4.2.0-r8
  • L
GHSA-jppx-w49h-x2qq

<4.2.0-r3
  • H
Resource Exhaustion

<4.2.0-r3
  • L
GHSA-5gvw-p9qm-jgwh

<4.2.0-r8
  • L
Resource Exhaustion

<4.2.0-r3
  • L
Resource Exhaustion

<4.2.0-r3
  • M
CRLF Injection

<4.2.0-r3
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<4.2.0-r8
  • L
Improper Access Control

<4.2.0-r3
  • L
GHSA-6cqp-g7gg-8hr5

<4.2.0-r3
  • L
GHSA-c69g-56f8-xwqj

<4.2.0-r3
  • L
Incorrect Authorization

<4.2.0-r8
  • L
GHSA-4mp9-239f-g9hg

<4.2.0-r3
  • L
GHSA-93wv-jw9v-4972

<4.2.0-r3
  • L
GHSA-xx22-p4ch-683r

<4.2.0-r3
  • L
Resource Exhaustion

<4.2.0-r3
  • L
NULL Pointer Dereference

<4.2.0-r3
  • M
HTTP Request Smuggling

<4.2.0-r3
  • H
HTTP Request Smuggling

<4.2.0-r3
  • H
Allocation of Resources Without Limits or Throttling

<4.2.0-r3
  • L
GHSA-6jqx-86gh-f27w

<4.2.0-r3
  • L
GHSA-gcjf-9mgh-3p7g

<4.2.0-r3
  • L
GHSA-mvh2-crg5-v77c

<4.2.0-r3
  • L
GHSA-q4f6-jm68-57ww

<4.2.0-r3
  • L
GHSA-mfg7-5gfp-c4w3

<4.2.0-r3
  • L
GHSA-mhm7-754m-9p8w

<4.2.0-r8
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<4.2.0-r2
  • L
GHSA-558v-64gr-wgg4

<4.2.0-r2
  • L
GHSA-2fvj-hgj9-j2gr

<4.2.0-r1
  • L
GHSA-w7x5-g22v-xqhr

<4.2.0-r1
  • L
Improper Input Validation

<4.2.0-r1
  • L
GHSA-7p3p-8qv8-m2vh

<4.2.0-r1
  • C
Improper Handling of Alternate Encoding

<4.2.0-r1
  • L
Use of Non-Canonical URL Paths for Authorization Decisions

<4.2.0-r1
  • L
GHSA-f4v5-65jj-pcr2

<4.2.0-r1
  • L
Information Exposure

<4.2.0-r1