Direct Vulnerabilities

Known vulnerabilities in the kubo package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Information Exposure

<0.43.1-r0
  • L
Improper Handling of Case Sensitivity

<0.43.1-r0
  • L
Resource Exhaustion

<0.43.1-r0
  • L
CVE-2026-56855

<0.43.1-r0
  • L
CVE-2026-56854

<0.43.1-r0
  • L
Race Condition

<0.43.1-r0
  • L
CVE-2026-78662

<0.43.1-r0
  • L
CVE-2026-56864

<0.43.0-r1
  • L
CVE-2026-56865

<0.43.0-r1
  • L
CVE-2026-56860

<0.43.0-r1
  • L
CVE-2026-56853

<0.43.0-r1
  • L
CVE-2026-56862

<0.43.0-r1
  • L
CVE-2026-56858

<0.43.0-r1
  • L
CVE-2026-33818

<0.43.0-r1
  • L
CVE-2026-56859

<0.43.0-r1
  • L
GHSA-259r-337f-4rfw

<0.43.0-r0
  • L
Uncontrolled Memory Allocation

<0.43.0-r0
  • L
Out-of-bounds Read

<0.42.0-r3
  • L
GHSA-hrxh-6v49-42gf

<0.42.0-r3
  • L
Improper Input Validation

<0.42.0-r3
  • L
Uncontrolled Memory Allocation

<0.42.0-r2
  • L
CVE-2026-46600

<0.42.0-r2
  • L
CVE-2026-56852

<0.42.0-r2
  • L
Allocation of Resources Without Limits or Throttling

<0.42.0-r2
  • L
Improper Restriction of Rendered UI Layers or Frames

<0.42.0-r1
  • L
Integer Overflow or Wraparound

<0.42.0-r1
  • L
Resource Exhaustion

<0.42.0-r1
  • L
Missing Authorization

<0.42.0-r1
  • L
Improper Certificate Validation

<0.42.0-r1
  • H
Allocation of Resources Without Limits or Throttling

<0.42.0-r1
  • L
Improper Restriction of Rendered UI Layers or Frames

<0.42.0-r1
  • L
Improper Certificate Validation

<0.42.0-r1
  • L
Out-of-Bounds

<0.42.0-r1
  • L
Cross-site Scripting (XSS)

<0.42.0-r1
  • L
Deserialization of Untrusted Data

<0.42.0-r1
  • L
Improper Restriction of Rendered UI Layers or Frames

<0.42.0-r1
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<0.42.0-r1
  • L
CVE-2026-46598

<0.42.0-r1
  • L
Missing Authorization

<0.42.0-r1
  • L
Incorrect Type Conversion or Cast

<0.42.0-r1
  • L
CVE-2026-39821

<0.42.0-r1
  • L
Improper Verification of Cryptographic Signature

<0.42.0-r1
  • L
Improper Certificate Validation

<0.42.0-r1
  • L
CVE-2026-46595

<0.42.0-r1