kibana-9

Direct Vulnerabilities

Known vulnerabilities in the kibana-9 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
CVE-2026-16729

*
  • L
Improper Input Validation

*
  • H
CVE-2026-14643

*
  • L
CVE-2026-18446

*
  • M
CVE-2026-16728

*
  • C
CVE-2026-13697

*
  • M
CVE-2026-15157

*
  • L
Resource Exhaustion

*
  • L
GHSA-r292-9mhp-454m

*
  • L
CVE-2026-14257

*
  • L
Uncaught Exception

*
  • L
CVE-2026-13676

*
  • L
CVE-2026-16221

*
  • L
Algorithmic Complexity

*
  • L
Incorrect Type Conversion or Cast

*
  • L
GHSA-pmv8-rq9r-6j72

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
GHSA-42h9-826w-cgv3

*
  • L
CVE-2026-12590

*
  • L
Uncaught Exception

*
  • L
GHSA-mmx7-hfxf-jppx

*
  • L
Algorithmic Complexity

*
  • L
GHSA-7q8q-rj6j-mhjq

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
GHSA-jqh4-m9w3-8hp9

*
  • L
CVE-2026-13149

*
  • L
CVE-2026-39244

*
  • H
OS Command Injection

*
  • H
Inefficient Regular Expression Complexity

*
  • L
CVE-2026-9679

*
  • L
CVE-2026-11525

*
  • L
CVE-2026-12151

*
  • L
CVE-2026-6733

*
  • L
GHSA-p6gq-j5cr-w38f

*
  • L
CVE-2026-9678

*
  • L
Arbitrary Code Injection

*
  • L
Algorithmic Complexity

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
GHSA-r7g4-qg5f-qqm2

*
  • L
Resource Exhaustion

*
  • L
Uncontrolled Recursion

*
  • L
GHSA-268h-hp4c-crq3

*
  • L
GHSA-wqvq-jvpq-h66f

*
  • L
Interpretation Conflict

*
  • L
CVE-2026-12143

*
  • L
Resource Exhaustion

*
  • L
Uncontrolled Recursion

*
  • L
Cleartext Transmission of Sensitive Information

*
  • L
Uncaught Exception

*
  • L
Uncaught Exception

*
  • L
Uncaught Exception

*
  • L
Directory Traversal

*
  • L
Information Exposure

*
  • H
Information Exposure

*
  • L
Resource Exhaustion

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

*
  • L
Arbitrary Code Injection

*
  • M
Resource Exhaustion

*
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
Interpretation Conflict

*
  • L
Information Exposure

*
  • H
Directory Traversal

<9.1.3-r0
  • L
CVE-2026-8723

*
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • H
Uncontrolled Recursion

*
  • H
Use of Uninitialized Resource

*
  • L
Improper Handling of Unicode Encoding

*
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
Arbitrary Code Injection

*
  • L
Uncontrolled Recursion

*
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
Deserialization of Untrusted Data

*
  • L
OS Command Injection

*
  • H
Arbitrary Code Injection

*
  • L
Improper Handling of Exceptional Conditions

*
  • L
Improper Input Validation

*