trufflehog-fips

Direct Vulnerabilities

Known vulnerabilities in the trufflehog-fips package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Deserialization of Untrusted Data

<3.95.3-r1
  • L
Out-of-Bounds

<3.95.3-r1
  • L
Improper Verification of Cryptographic Signature

<3.95.3-r1
  • L
Improper Certificate Validation

<3.95.3-r1
  • L
Integer Overflow or Wraparound

<3.95.3-r1
  • L
Missing Authorization

<3.95.3-r1
  • L
Incorrect Type Conversion or Cast

<3.95.3-r1
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<3.95.3-r1
  • C
Improper Encoding or Escaping of Output

<3.94.3-r6
  • L
GHSA-crhj-59gh-8x96

<3.94.3-r6
  • L
Directory Traversal

<3.94.3-r6
  • L
GHSA-m7cr-m3pv-hgrp

<3.94.3-r6
  • H
Incorrect Behavior Order: Validate Before Canonicalize

<3.94.3-r5
  • L
GHSA-389r-gv7p-r3rp

<3.94.3-r5
  • L
GHSA-497x-jcxf-m478

<3.94.3-r3
  • L
Improper Encoding or Escaping of Output

<3.94.3-r3
  • H
Double Free

<3.94.3-r3
  • L
GHSA-3v2c-x6q9-f697

<3.94.3-r3
  • L
Cross-site Scripting (XSS)

<3.94.3-r3
  • L
GHSA-8g2r-hhvj-mv99

<3.94.3-r3
  • L
GHSA-5m4p-2gjx-p2g8

<3.94.3-r3
  • L
GHSA-qf3q-3h68-mmh2

<3.94.3-r3
  • M
Link Following

<3.94.3-r3
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<3.94.3-r3
  • L
GHSA-qc64-m6c2-v4x7

<3.94.3-r3
  • L
CVE-2026-42501

<3.94.3-r3
  • H
NULL Pointer Dereference

<3.94.3-r3
  • L
GHSA-2283-wf8c-rw8r

<3.94.3-r3
  • M
Out-of-bounds Write

<3.94.3-r3
  • H
Insufficiently Protected Credentials

<3.94.3-r2
  • L
GHSA-pjcq-xvwq-hhpj

<3.94.3-r3
  • H
Integer Overflow or Wraparound

<3.94.3-r3
  • L
GHSA-3xc5-wrhm-f963

<3.94.3-r2
  • L
GHSA-hfvc-g4fc-pqhx

<3.94.3-r1
  • H
Untrusted Search Path

<3.94.3-r1
  • L
GHSA-xmrv-pmrh-hhx2

<3.94.2-r3
  • L
GHSA-gm2x-2g9h-ccm8

<3.94.2-r1
  • L
Uncaught Exception

<3.94.2-r2
  • L
Improper Validation of Array Index

<3.94.2-r1
  • L
Integer Underflow

<3.94.2-r1
  • L
GHSA-jhf3-xxhw-2wpp

<3.94.2-r1
  • L
GHSA-78h2-9frx-2jm8

<3.94.2-r2
  • L
GHSA-p77j-4mvh-x3m3

<3.93.8-r1
  • L
Improper Authorization

<3.93.8-r1
  • L
GHSA-p436-gjf2-799p

<3.93.7-r1
  • H
CVE-2025-15558

<3.93.7-r1
  • L
GHSA-9h8m-3fm2-qjrq

<3.93.6-r1
  • L
Untrusted Search Path

<3.93.6-r1
  • L
GHSA-q9hv-hpm4-hj6x

<3.93.4-r1
  • C
CVE-2026-1229

<3.93.4-r1
  • M
Improper Validation of Integrity Check Value

<3.93.1-r1
  • L
GHSA-37cx-329c-33x3

<3.93.1-r1
  • L
GHSA-xvqr-69v8-f3gv

<3.92.5-r1
  • L
GHSA-gm9r-q53w-2gh4

<3.92.5-r1
  • L
CVE-2025-61731

<3.92.5-r1
  • L
GHSA-cm6p-qc7v-m3jw

<3.92.5-r1
  • L
Out-of-bounds Write

<3.92.5-r1
  • L
CVE-2025-61730

<3.92.5-r1
  • L
GHSA-g9q4-qjx4-2v7q

<3.92.5-r1
  • L
Allocation of Resources Without Limits or Throttling

<3.92.5-r1
  • L
Allocation of Resources Without Limits or Throttling

<3.92.5-r1
  • L
GHSA-gr56-3gp6-6gmj

<3.92.5-r1
  • L
GHSA-hcg3-q754-cr77

<3.88.16-r1
  • L
GHSA-6v2p-p543-phr9

<3.88.17-r0
  • L
Improper Validation of Specified Type of Input

<3.89.1-r1
  • L
Improper Certificate Validation

<3.91.2-r1
  • L
GHSA-7c64-f9jr-v9h2

<3.91.2-r1
  • M
CVE-2025-11579

<3.90.8-r1
  • L
Allocation of Resources Without Limits or Throttling

<3.90.5-r1
  • L
Race Condition

<3.90.3-r1
  • M
Missing Initialization of Resource

<3.90.2-r1
  • L
Asymmetric Resource Consumption (Amplification)

<3.88.18-r1
  • L
Allocation of Resources Without Limits or Throttling

<3.88.18-r1
  • L
CVE-2025-22870

<3.88.17-r0
  • L
CVE-2025-22868

<3.88.17-r0
  • L
CVE-2025-22869

<3.88.16-r1