camunda-8.8

Direct Vulnerabilities

Known vulnerabilities in the camunda-8.8 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Improper Check for Unusual or Exceptional Conditions

<8.8.35-r0
  • L
Algorithmic Complexity

<8.8.35-r0
  • L
Authentication Bypass

<8.8.37-r0
  • L
Improper Access Control

<8.8.37-r0
  • L
Incorrect Authorization

<8.8.37-r0
  • L
CVE-2026-41001

<8.8.29-r0
  • L
Missing Release of Resource after Effective Lifetime

<8.8.36-r0
  • L
Information Exposure Through Caching

<8.8.35-r0
  • L
Improper Encoding or Escaping of Output

<8.8.32-r0
  • L
CVE-2026-54428

<8.8.32-r0
  • L
CVE-2026-41697

<8.8.29-r0
  • L
CVE-2026-41706

<8.8.29-r0
  • L
CVE-2026-41721

<8.8.29-r0
  • L
CVE-2026-54399

<8.8.32-r0
  • L
CVE-2026-41711

<8.8.29-r0
  • L
CVE-2026-41716

<8.8.29-r0
  • L
CVE-2026-40984

<8.8.29-r0
  • L
CVE-2026-40983

<8.8.29-r0
  • M
CVE-2026-41854

<8.8.29-r0
  • L
CVE-2026-41695

<8.8.29-r0
  • L
Resource Exhaustion

<8.8.32-r0
  • L
CVE-2026-41853

<8.8.29-r0
  • L
CVE-2026-41843

<8.8.29-r0
  • M
CVE-2026-41844

<8.8.29-r0
  • M
CVE-2026-41846

<8.8.29-r0
  • L
CVE-2026-41842

<8.8.29-r0
  • H
CVE-2026-41848

<8.8.29-r0
  • M
CVE-2026-41845

<8.8.29-r0
  • L
CVE-2026-41850

<8.8.29-r0
  • M
CVE-2026-41852

<8.8.29-r0
  • H
CVE-2026-41851

<8.8.29-r0
  • L
CVE-2026-41841

<8.8.29-r0
  • L
GHSA-mfg7-5gfp-c4w3

<8.8.32-r0
  • L
Improper Access Control

<8.8.32-r0
  • L
Resource Exhaustion

<8.8.32-r0
  • H
Allocation of Resources Without Limits or Throttling

<8.8.32-r0
  • L
Resource Exhaustion

<8.8.32-r0
  • L
Incorrect Authorization

<8.8.32-r0
  • H
Resource Exhaustion

<8.8.32-r0
  • M
HTTP Request Smuggling

<8.8.32-r0
  • M
CRLF Injection

<8.8.32-r0
  • L
GHSA-mhm7-754m-9p8w

<8.8.32-r0
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<8.8.32-r0
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<8.8.32-r0
  • H
HTTP Request Smuggling

<8.8.32-r0
  • L
GHSA-r7wm-3cxj-wff9

<8.8.26-r0
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<8.8.26-r0
  • L
Not Failing Securely ('Failing Open')

<8.8.31-r0
  • H
CVE-2026-47838

<8.8.29-r0
  • L
HTTP Request Smuggling

<8.8.29-r0
  • H
Resource Exhaustion

<8.8.29-r0
  • M
Allocation of Resources Without Limits or Throttling

<8.8.29-r0
  • L
Incomplete Blacklist

<8.8.26-r0
  • L
Incorrect Authorization

<8.8.26-r0
  • L
Incorrect Authorization

<8.8.26-r0
  • L
Server-Side Request Forgery (SSRF)

<8.8.26-r0
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<8.8.26-r0
  • L
Incomplete Blacklist

<8.8.26-r0
  • L
Improper Verification of Cryptographic Signature

<8.8.29-r0
  • C
Insufficient Verification of Data Authenticity

<8.8.29-r0
  • L
Improper Access Control

<8.8.29-r0
  • L
Information Exposure

<8.8.29-r0
  • L
Resource Exhaustion

<8.8.29-r0
  • L
Allocation of Resources Without Limits or Throttling

<8.8.29-r0
  • L
Use of Insufficiently Random Values

<8.8.29-r0
  • C
Insufficient Verification of Data Authenticity

<8.8.29-r0
  • H
CVE-2025-37731

*
  • L
CVE-2025-37727

*
  • L
CVE-2024-52980

*
  • L
Resource Exhaustion

<8.8.25-r0
  • L
Improper Authorization

<8.8.25-r0
  • L
Resource Exhaustion

<8.8.25-r0
  • L
Integer Overflow or Wraparound

<8.8.25-r0
  • L
Information Exposure

<8.8.25-r0
  • C
HTTP Request Smuggling

<8.8.25-r0
  • C
Improper Input Validation

<8.8.25-r0
  • L
Improper Input Validation

<8.8.25-r0
  • L
Allocation of Resources Without Limits or Throttling

<8.8.25-r0
  • L
Information Exposure

<8.8.25-r0
  • L
Authentication Bypass

<8.8.25-r0
  • C
HTTP Request Smuggling

<8.8.25-r0
  • H
HTTP Response Splitting

<8.8.25-r0
  • L
CRLF Injection

<8.8.25-r0
  • H
HTTP Request Smuggling

<8.8.25-r0
  • L
Improper Handling of Case Sensitivity

<8.8.25-r0