paketo-buildpacks-pipenv

Direct Vulnerabilities

Known vulnerabilities in the paketo-buildpacks-pipenv package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Information Exposure

<1.29.1-r0
  • L
Resource Exhaustion

*
  • L
Improper Handling of Case Sensitivity

*
  • L
Improper Validation of Array Index

*
  • L
CVE-2026-56855

*
  • L
CVE-2026-78662

*
  • L
Resource Exhaustion

*
  • L
CVE-2026-56854

<1.29.1-r1
  • L
Race Condition

<1.29.1-r0
  • L
CVE-2026-56864

<1.29.1-r1
  • L
CVE-2026-33818

<1.29.1-r1
  • L
CVE-2026-56859

<1.29.1-r1
  • L
CVE-2026-56858

<1.29.1-r1
  • L
CVE-2026-56853

<1.29.1-r1
  • L
CVE-2026-56862

<1.29.1-r1
  • L
CVE-2026-56860

<1.29.1-r1
  • L
CVE-2026-56865

<1.29.1-r1
  • L
GO-2026-5932

*
  • L
Link Following

<1.29.0-r0
  • L
Directory Traversal

<1.29.0-r0
  • L
GHSA-259r-337f-4rfw

<1.28.8-r0
  • L
GHSA-hrxh-6v49-42gf

<1.28.10-r0
  • L
CVE-2026-46600

<1.28.6-r0
  • L
CVE-2026-56852

<1.28.8-r0
  • L
CVE-2026-42505

<1.28.8-r0
  • L
CVE-2026-39822

<1.28.8-r0
  • L
Uncontrolled Memory Allocation

<1.28.4-r0
  • L
Uncontrolled Memory Allocation

<1.28.4-r0
  • L
CVE-2026-50195

<1.28.6-r0
  • L
CVE-2026-47262

<1.28.6-r0
  • L
Improper Input Validation

<1.28.6-r0
  • L
Improper Input Validation

<1.28.6-r0
  • L
Symlink Following

<1.28.5-r0
  • L
CVE-2026-4660

<1.28.4-r0
  • L
Directory Traversal

<1.28.4-r0
  • L
CVE-2026-39824

<1.28.4-r0
  • L
GHSA-w5pp-99ch-qj29

<1.28.4-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.28.4-r0
  • H
Symlink Following

<1.28.4-r0
  • L
Improper Validation of Array Index

<1.28.4-r0
  • L
Out-of-Bounds

<1.28.4-r0
  • L
Uncontrolled Search Path Element

<1.28.4-r0
  • L
Improper Certificate Validation

<1.28.4-r0
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.28.4-r0
  • H
Insufficiently Protected Credentials

<1.28.4-r0
  • L
Improper Authorization

<1.28.4-r0
  • L
Resource Exhaustion

<1.28.4-r0
  • L
Incorrect Type Conversion or Cast

<1.28.4-r0
  • L
CVE-2026-39821

<1.28.4-r0
  • L
Cross-site Scripting (XSS)

<1.28.4-r0
  • L
Improper Cleanup on Thrown Exception

<1.28.4-r0
  • L
Improper Certificate Validation

<1.28.4-r0
  • H
Untrusted Search Path

<1.28.4-r0
  • H
Authentication Bypass

<1.28.4-r0
  • L
CVE-2026-46598

<1.28.4-r0
  • L
Missing Authorization

<1.28.4-r0
  • L
Improper Certificate Validation

<1.28.4-r0
  • L
Uncaught Exception

<1.28.4-r0
  • C
Improper Encoding or Escaping of Output

<1.28.4-r0
  • L
Cross-site Scripting (XSS)

<1.28.4-r0
  • L
Integer Underflow

<1.28.4-r0
  • L
Directory Traversal

<1.28.4-r0
  • L
Integer Overflow or Wraparound

<1.28.4-r0
  • L
Missing Authorization

<1.28.4-r0
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<1.28.4-r0
  • L
Uncontrolled Recursion

<1.28.4-r0
  • L
Improper Verification of Cryptographic Signature

<1.28.4-r0
  • L
CVE-2026-46595

<1.28.4-r0
  • H
Incorrect Behavior Order: Validate Before Canonicalize

<1.28.4-r0
  • H
Off-by-one Error

<1.28.4-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.28.4-r0
  • L
Deserialization of Untrusted Data

<1.28.4-r0
  • L
Improper Privilege Management

<1.28.4-r0
  • L
GHSA-xmrv-pmrh-hhx2

<1.28.4-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.28.4-r0