wso2is

Direct Vulnerabilities

Known vulnerabilities in the wso2is package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-wv8q-qhhj-9h54

<7.3.0-r6
  • L
GHSA-p6pp-m3f8-5c89

<7.3.0-r6
  • L
GHSA-7hhh-6rmp-j9qf

<7.3.0-r6
  • L
CVE-2026-91776

<7.3.0-r6
  • L
CVE-2026-89407

<7.3.0-r6
  • L
CVE-2026-89425

<7.3.0-r6
  • L
GHSA-cxp5-3px4-pw24

<7.3.0-r6
  • L
CVE-2026-91777

<7.3.0-r6
  • L
CVE-2026-68494

<7.3.0-r5
  • L
GHSA-642r-3gj9-2pj5

<7.3.0-r5
  • L
CVE-2026-68497

<7.3.0-r5
  • L
GHSA-vvgp-rfg2-7rr6

<7.3.0-r5
  • L
GHSA-w7x5-g22v-xqhr

<7.3.0-r5
  • L
GHSA-wjgm-6hv5-3cvf

<7.3.0-r5
  • L
GHSA-gx83-3vf8-gh7j

<7.3.0-r5
  • L
CVE-2026-83557

<7.3.0-r5
  • L
GHSA-5gvw-p9qm-jgwh

<7.3.0-r5
  • L
Incorrect Authorization

<7.3.0-r5
  • L
GHSA-mhm7-754m-9p8w

<7.3.0-r5
  • L
Use of Non-Canonical URL Paths for Authorization Decisions

<7.3.0-r5
  • L
Server-Side Request Forgery (SSRF)

<7.3.0-r5
  • L
GHSA-q4xh-88c3-wmh7

<7.3.0-r5
  • L
CVE-2026-19032

<7.3.0-r5
  • C
CVE-2026-8763

<7.3.0-r4
  • L
Improper Encoding or Escaping of Output

<7.3.0-r4
  • L
GHSA-5jmj-h7xm-6q6v

<7.3.0-r5
  • L
GHSA-qp49-qgx5-5m26

<7.3.0-r4
  • L
GHSA-qv9r-c865-cp47

<7.3.0-r4
  • L
GHSA-9pwp-9qqc-pr26

<7.3.0-r4
  • H
CVE-2026-13506

<7.3.0-r4
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<7.3.0-r5
  • L
GHSA-6qm2-mcq7-53qp

<7.3.0-r5
  • L
CVE-2026-18401

<7.3.0-r5
  • L
GHSA-hgj6-7826-r7m5

<7.3.0-r5
  • L
Missing Release of Resource after Effective Lifetime

<7.3.0-r3
  • H
Resource Exhaustion

<7.3.0-r3
  • L
Incomplete Blacklist

<7.3.0-r5
  • L
GHSA-ghvc-7hp8-2g2v

<7.3.0-r3
  • L
CVE-2026-54399

<7.3.0-r3
  • L
Server-Side Request Forgery (SSRF)

<7.3.0-r5
  • L
GHSA-rmj7-2vxq-3g9f

<7.3.0-r5
  • L
Incomplete Blacklist

<7.3.0-r5
  • L
GHSA-v3jc-474w-2wm6

<7.3.0-r3
  • L
GHSA-r7wm-3cxj-wff9

<7.3.0-r5
  • L
GHSA-hjcp-jmpx-g3qm

<7.3.0-r3
  • L
GHSA-j3rv-43j4-c7qm

<7.3.0-r5
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<7.3.0-r5
  • L
GHSA-hf6x-8p5f-cgmf

<7.3.0-r3
  • L
GHSA-3pjw-73gf-8qr5

<7.3.0-r5
  • L
CVE-2026-54428

<7.3.0-r3
  • L
GHSA-72hv-8253-57qq

<7.3.0-r5
  • L
GHSA-6fmv-xxpf-w3cw

<7.3.0-r0
  • H
Improper Encoding or Escaping of Output

<7.3.0-r0
  • L
GHSA-7xrh-hqfc-g7qr

<7.3.0-r0
  • L
Resource Exhaustion

<7.3.0-r0
  • L
GHSA-gjx9-j8f8-7j74

<7.3.0-r0
  • L
GHSA-6hg6-v5c8-fphq

<7.3.0-r0
  • L
GHSA-qh8g-58pp-2wxh

<7.3.0-r0
  • L
Improper Neutralization of Special Elements Used in a Template Engine

<7.3.0-r0
  • L
GHSA-c3fc-8qff-9hwx

<7.3.0-r0
  • L
GHSA-wjpw-4j6x-6rwh

<7.3.0-r0
  • L
GHSA-w35j-pv5h-q9q9

<7.3.0-r0
  • L
GHSA-vc5p-v9hr-52mj

<7.3.0-r0
  • C
HTTP Request Smuggling

<7.3.0-r0
  • M
Improper Validation of Certificate with Host Mismatch

<7.3.0-r0
  • H
Improper Certificate Validation

<7.3.0-r0
  • L
GHSA-355h-qmc2-wpwf

<7.3.0-r0
  • L
CVE-2026-0636

<7.3.0-r0
  • H
Improper Encoding or Escaping of Output

<7.3.0-r0
  • L
GHSA-crhr-qqj8-rpxc

<7.3.0-r0
  • H
CVE-2025-67030

<7.3.0-r0
  • L
GHSA-wg6q-6289-32hp

<7.3.0-r0
  • L
CVE-2026-5588

<7.3.0-r0
  • L
GHSA-pvp8-3xj6-8c6x

<7.3.0-r0
  • L
GHSA-3pxv-7cmr-fjr4

<7.3.0-r0
  • L
Resource Exhaustion

<7.3.0-r0
  • M
Improper Input Validation

<7.3.0-r0
  • L
GHSA-36wv-v2qp-v4g4

<7.3.0-r0
  • L
GHSA-p93r-85wp-75v3

<7.3.0-r0
  • H
Information Exposure Through Log Files

<7.3.0-r0
  • L
CVE-2026-5598

<7.3.0-r0
  • M
Improper Certificate Validation

<7.3.0-r0
  • M
CVE-2024-6763

<7.3.0-r0
  • L
GHSA-7p63-w6x9-6gr7

<7.2.0-r0
  • H
Race Condition

<7.2.0-r0
  • L
GHSA-wf8f-6423-gfxg

<7.1.0-r2
  • L
Information Exposure

<7.1.0-r2
  • L
GHSA-fh5r-crhr-qrrq

<7.1.0-r1
  • H
CVE-2025-23184

<7.1.0-r1