kibana-9.0-advanced

Direct Vulnerabilities

Known vulnerabilities in the kibana-9.0-advanced package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-19693

*
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
CVE-2026-82299

*
  • L
Resource Exhaustion

*
  • L
CVE-2026-82298

*
  • L
CVE-2026-78596

*
  • L
GHSA-2x7j-588g-ccc2

*
  • L
GHSA-8m3c-c648-2xjj

*
  • L
CVE-2026-82302

*
  • M
Link Following

*
  • L
CVE-2026-78583

*
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
CVE-2026-78593

*
  • L
GHSA-wmmp-3585-3rmp

*
  • L
CVE-2026-82293

*
  • L
CVE-2026-78591

*
  • L
CVE-2026-78598

*
  • L
CVE-2026-78599

*
  • L
CVE-2026-78586

*
  • L
CVE-2026-78590

*
  • L
CVE-2026-78608

*
  • L
CVE-2026-75975

*
  • L
CVE-2026-78592

*
  • L
CVE-2026-78603

*
  • L
CVE-2026-72628

*
  • L
CVE-2026-33465

*
  • L
CVE-2026-72652

*
  • L
CVE-2026-72654

*
  • L
CVE-2026-76172

*
  • L
CVE-2026-78597

*
  • L
Integer Overflow or Wraparound

*
  • L
CVE-2026-8657

*
  • L
CVE-2026-45822

*
  • L
CVE-2026-72650

*
  • L
CVE-2026-72664

*
  • M
CVE-2026-72670

*
  • L
CVE-2026-72660

*
  • L
CVE-2026-72673

*
  • L
CVE-2026-72671

*
  • L
CVE-2026-72669

*
  • L
CVE-2026-72658

*
  • L
CVE-2026-72677

*
  • L
CVE-2026-72651

*
  • L
CVE-2026-72675

*
  • L
CVE-2026-72659

*
  • L
CVE-2026-72663

*
  • L
CVE-2026-49089

*
  • L
CVE-2026-72653

*
  • L
CVE-2026-72667

*
  • L
CVE-2026-49096

*
  • L
CVE-2026-72655

*
  • L
CVE-2026-72661

*
  • L
CVE-2026-72665

*
  • L
CVE-2026-72630

*
  • L
CVE-2026-72632

*
  • L
CVE-2026-72629

*
  • L
CVE-2026-56876

*
  • L
CVE-2026-63142

*
  • L
CVE-2026-63143

*
  • L
CVE-2026-13149

*
  • L
Interpretation Conflict

*
  • M
CVE-2026-16728

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Information Exposure

*
  • H
OS Command Injection

*
  • L
CVE-2026-18446

*
  • L
GHSA-42h9-826w-cgv3

*
  • L
Information Exposure

*
  • L
CVE-2026-49095

*
  • L
CVE-2026-56151

*
  • L
OS Command Injection

*
  • L
CVE-2026-63145

*
  • L
CVE-2025-9910

*
  • L
Arbitrary Code Injection

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
CVE-2026-33463

*
  • L
Cleartext Transmission of Sensitive Information

*
  • L
Algorithmic Complexity

*
  • L
GHSA-mmx7-hfxf-jppx

*
  • L
GHSA-wqvq-jvpq-h66f

*
  • L
Uncontrolled Recursion

*
  • L
CVE-2026-42399

*
  • H
Information Exposure

*
  • L
Uncaught Exception

*
  • L
CVE-2026-6733

*
  • L
CVE-2026-49087

*
  • L
Algorithmic Complexity

*
  • L
Uncaught Exception

*
  • L
GHSA-r292-9mhp-454m

*
  • L
CVE-2026-39244

*
  • L
Resource Exhaustion

*
  • L
Improper Verification of Cryptographic Signature

*
  • L
CVE-2025-12816

*
  • M
Cross-site Scripting (XSS)

*
  • L
Algorithmic Complexity

*
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Improper Input Validation

*
  • C
Deserialization of Untrusted Data

*
  • L
Directory Traversal

*
  • L
CVE-2026-12143

*
  • L
CVE-2026-33464

*
  • H
Uncontrolled Recursion

*
  • H
Use of Uninitialized Resource

*
  • L
Resource Exhaustion

*
  • H
Improper Check or Handling of Exceptional Conditions

*
  • L
GHSA-7q8q-rj6j-mhjq

*
  • H
Uncontrolled Recursion

*
  • H
Inefficient Regular Expression Complexity

*
  • L
CVE-2025-13204

*
  • M
CVE-2025-48985

*
  • L
CVE-2026-63261

*
  • L
GHSA-268h-hp4c-crq3

*
  • H
Improper Validation of Syntactic Correctness of Input

*
  • L
GHSA-pmv8-rq9r-6j72

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Arbitrary Code Injection

*
  • M
CVE-2026-63141

*
  • L
CVE-2026-42400

*
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
CVE-2026-11525

*
  • L
CVE-2026-13676

*
  • L
Uncontrolled Recursion

*
  • L
GHSA-5p4m-2wfm-xmqj

*
  • M
Resource Exhaustion

*
  • M
CVE-2026-15157

*
  • M
CVE-2026-42401

*
  • L
CVE-2026-56147

*
  • L
CVE-2026-9679

*
  • L
CVE-2026-14257

*
  • M
CVE-2026-16729

*
  • L
CVE-2026-63139

*
  • L
Incorrect Type Conversion or Cast

*
  • L
CVE-2026-16221

*
  • L
GHSA-r7g4-qg5f-qqm2

*
  • L
CVE-2026-63260

*
  • M
Integer Overflow or Wraparound

*
  • L
GHSA-jqh4-m9w3-8hp9

*
  • L
Uncaught Exception

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Uncaught Exception

*
  • H
CVE-2026-33462

*
  • L
Uncaught Exception

*
  • L
Resource Exhaustion

*
  • L
GHSA-p6gq-j5cr-w38f

*
  • L
CVE-2026-12151

*
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
CVE-2026-42398

*
  • L
Interpretation Conflict

*
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Resource Exhaustion

*
  • L
CVE-2026-26939

*
  • L
CVE-2026-33459

*
  • M
CVE-2026-33461

*
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
Improper Handling of Unicode Encoding

*
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • M
Cross-site Scripting (XSS)

*
  • L
Improper Handling of Exceptional Conditions

*
  • H
Arbitrary Code Injection

*
  • L
Improper Input Validation

*
  • L
CVE-2026-6322

*
  • L
OS Command Injection

*
  • L
Deserialization of Untrusted Data

*
  • L
CVE-2026-6321

*
  • L
Resource Exhaustion

*
  • L
Uncontrolled Recursion

*
  • L
Arbitrary Code Injection

*
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
Improper Encoding or Escaping of Output

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
HTTP Response Splitting

*
  • H
Server-Side Request Forgery (SSRF)

*
  • M
Improper Authentication

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • H
Uncontrolled Recursion

*
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • L
Permissive Whitelist

*
  • L
CRLF Injection

*
  • C
Permissive Whitelist

*
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
Improper Validation of Specified Quantity in Input

*
  • L
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • M
CVE-2026-26940

*
  • L
Uncontrolled Recursion

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
GHSA-c7w3-x93f-qmm8

*
  • M
Cross-site Scripting (XSS)

*
  • C
Improper Certificate Validation

*
  • L
Improper Input Validation

*
  • L
Inefficient Regular Expression Complexity

*
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
Improper Verification of Cryptographic Signature

*
  • H
Resource Exhaustion

*
  • L
Arbitrary Code Injection

*
  • L
Improper Check for Unusual or Exceptional Conditions

*
  • H
Cross-site Scripting (XSS)

*
  • L
GHSA-442j-39wm-28r2

*
  • L
GHSA-7rx3-28cr-v5wh

*
  • L
Arbitrary Code Injection

*
  • L
Arbitrary Code Injection

*
  • M
CVE-2026-2950

*
  • C
CVE-2026-4800

*
  • H
Inefficient Regular Expression Complexity

*
  • C
Arbitrary Code Injection

*
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • L
GHSA-r4q5-vmmm-2653

*
  • M
HTTP Response Splitting

*
  • C
Unintended Proxy or Intermediary ('Confused Deputy')

*
  • L
GHSA-6v7q-wjvx-w8wg

*
  • L
Information Exposure

*
  • L
Resource Exhaustion

*
  • L
GHSA-vvjj-xcjg-gr5g

*
  • H
Out-of-bounds Write

*
  • L
XML Injection

*
  • L
CVE-2026-1527

*
  • L
CVE-2026-1526

*
  • L
CVE-2026-26934

*
  • M
Directory Traversal

*
  • H
CVE-2026-26936

*
  • C
CVE-2026-1525

*
  • H
CVE-2026-26937

*
  • M
Directory Traversal

*
  • L
CVE-2026-2229

*
  • H
CVE-2026-26935

*
  • L
CVE-2026-3449

*
  • L
CVE-2026-1528

*
  • L
CVE-2025-68389

*
  • C
Directory Traversal

*
  • L
Algorithmic Complexity

*
  • L
CVE-2025-68387

*
  • L
Inefficient Regular Expression Complexity

*
  • L
CVE-2026-0530

*
  • L
CVE-2025-68422

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • H
Server-Side Request Forgery (SSRF)

*
  • L
CVE-2026-0531

*
  • L
CVE-2025-37732

*
  • L
CVE-2026-0532

*
  • H
Buffer Overflow

*
  • M
CVE-2025-68385

*
  • L
CVE-2025-68386

*
  • M
CVE-2025-25009

<9.0.8-r0
  • L
CVE-2025-37728

<9.0.8-r0
  • M
CVE-2025-25018

<9.0.8-r0
  • M
CVE-2025-25017

<9.0.7-r0
  • L
OS Command Injection

*
  • H
Inefficient Regular Expression Complexity

*
  • H
Directory Traversal

*
  • L
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • L
Inefficient Regular Expression Complexity

*
  • L
Incorrect Regular Expression

*
  • H
OS Command Injection

*
  • L
CVE-2026-2739

*
  • L
Server-Side Request Forgery (SSRF)

*
  • H
CVE-2026-2327

*
  • L
Improper Check for Unusual or Exceptional Conditions

*
  • L
Directory Traversal

*
  • M
CVE-2025-13465

*
  • M
Improper Handling of Unicode Encoding

*
  • L
GHSA-6475-r3vj-m8vf

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Directory Traversal

*