Direct Vulnerabilities

Known vulnerabilities in the libskia package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Use After Free

*
  • L
Use of Uninitialized Variable

*
  • L
Use of Uninitialized Variable

*
  • L
Race Condition

*
  • L
Out-of-bounds Write

*
  • L
CVE-2026-15766

*
  • L
Use After Free

*
  • L
Use of Uninitialized Variable

*
  • L
Information Exposure

*
  • L
Improper Protection Against Physical Side Channels

*
  • L
CVE-2026-15774

*
  • L
Out-of-bounds Read

*
  • L
Use After Free

*
  • L
Out-of-bounds Read

*
  • L
Use of Uninitialized Variable

*
  • L
CVE-2026-17702

*
  • L
Information Exposure

*
  • L
Information Exposure

*
  • L
Use of Uninitialized Variable

*
  • L
Use After Free

*
  • L
Use of Uninitialized Variable

*
  • L
Use of Uninitialized Resource

*
  • L
Information Exposure

*
  • L
Use of Uninitialized Resource

*
  • L
Out-of-bounds Read

*
  • L
Improper Input Validation

<146.20260602~git.3476902+dfsg-2
  • L
External Control of Assumed-Immutable Web Parameter

<146.20260602~git.3476902+dfsg-2
  • L
External Control of Assumed-Immutable Web Parameter

<146.20260602~git.3476902+dfsg-2
  • L
CVE-2026-14410

<146.20260602~git.3476902+dfsg-2
  • L
Use After Free

<146.20260602~git.3476902+dfsg-2
  • L
Heap-based Buffer Overflow

<146.20260602~git.3476902+dfsg-2
  • L
Improper Input Validation

<146.20260602~git.3476902+dfsg-2
  • L
Out-of-bounds Read

<146.20260602~git.3476902+dfsg-1
  • L
Use After Free

<146.20260602~git.3476902+dfsg-1
  • L
Use of Uninitialized Variable

<146.20260602~git.3476902+dfsg-1
  • C
Improper Input Validation

<146.20260602~git.3476902+dfsg-1
  • L
External Control of Assumed-Immutable Web Parameter

<146.20260602~git.3476902+dfsg-1
  • L
Use After Free

<146.20260414~git.ef5f213+dfsg-5
  • L
External Control of Assumed-Immutable Web Parameter

<146.20260414~git.ef5f213+dfsg-5
  • L
Improper Input Validation

*
  • L
CVE-2026-9981

<146.20260414~git.ef5f213+dfsg-5
  • L
Use After Free

<146.20260414~git.ef5f213+dfsg-5
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

<146.20260414~git.ef5f213+dfsg-5
  • H
Use After Free

<146.20260414~git.ef5f213+dfsg-5
  • L
External Control of Assumed-Immutable Web Parameter

<146.20260414~git.ef5f213+dfsg-5
  • L
CVE-2026-9892

<146.20260414~git.ef5f213+dfsg-5
  • L
CVE-2026-10011

<146.20260414~git.ef5f213+dfsg-5
  • L
External Control of Assumed-Immutable Web Parameter

<146.20260414~git.ef5f213+dfsg-5
  • L
Improper Input Validation

<146.20260414~git.ef5f213+dfsg-4
  • L
External Control of Assumed-Immutable Web Parameter

<146.20260414~git.ef5f213+dfsg-4
  • L
Out-of-bounds Read

<146.20260414~git.ef5f213+dfsg-3
  • L
Use After Free

<146.20260414~git.ef5f213+dfsg-3
  • L
Out-of-bounds Write

<146.20260414~git.ef5f213+dfsg-3
  • L
Heap-based Buffer Overflow

<146.20260414~git.ef5f213+dfsg-1
  • L
Out-of-bounds Read

<146.20260414~git.ef5f213+dfsg-1
  • L
Integer Overflow or Wraparound

<146.20260414~git.ef5f213+dfsg-1