teleport-18

Direct Vulnerabilities

Known vulnerabilities in the teleport-18 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-56862

<18.10.0-r7
  • L
CVE-2026-56853

<18.10.0-r7
  • L
CVE-2026-33818

<18.10.0-r7
  • L
CVE-2026-56860

<18.10.0-r7
  • L
CVE-2026-56864

<18.10.0-r7
  • L
CVE-2026-56858

<18.10.0-r7
  • L
CVE-2026-56859

<18.10.0-r7
  • L
CVE-2026-56865

<18.10.0-r7
  • L
Directory Traversal

<18.10.0-r6
  • L
Link Following

<18.10.0-r6
  • L
GHSA-259r-337f-4rfw

<18.10.0-r5
  • L
GHSA-hrxh-6v49-42gf

<18.10.0-r4
  • L
Use of a Key Past its Expiration Date

<18.10.0-r3
  • L
CVE-2026-46600

<18.10.0-r2
  • L
CVE-2026-56852

<18.10.0-r2
  • L
Directory Traversal

<18.10.0-r2
  • L
Uncontrolled Memory Allocation

<18.10.0-r1
  • H
Allocation of Resources Without Limits or Throttling

<18.10.0-r1
  • H
Improper Verification of Cryptographic Signature

<18.10.0-r1
  • L
CVE-2026-39822

<18.9.2-r1
  • L
GHSA-vh4v-2xq2-g5cg

<18.9.2-r1
  • L
Cleartext Transmission of Sensitive Information

<18.9.2-r1
  • L
Server-Side Request Forgery (SSRF)

<18.9.2-r1
  • L
Allocation of Resources Without Limits or Throttling

<18.9.2-r1
  • L
External Control of File Name or Path

<18.9.2-r1
  • L
CVE-2026-42505

<18.9.2-r1
  • L
Improper Certificate Validation

<18.7.6-r0
  • L
GHSA-3fxj-6jh8-hvhx

<18.7.6-r0
  • L
Race Condition

<18.7.6-r0
  • L
GHSA-vrw8-fxc6-2r93

<18.2.1-r0
  • L
GHSA-9g5q-2w5x-hmxf

<18.7.6-r0
  • L
GHSA-rjr7-jggh-pgcp

<18.7.6-r0
  • L
CVE-2026-47262

<18.9.1-r1
  • L
Improper Input Validation

<18.9.1-r1
  • L
CVE-2026-2303

<18.9.1-r1
  • H
Allocation of Resources Without Limits or Throttling

<18.9.1-r1
  • L
Incorrect Type Conversion or Cast

<18.8.3-r2
  • L
Improper Certificate Validation

<18.8.3-r2
  • L
Deserialization of Untrusted Data

<18.8.3-r2
  • L
Improper Certificate Validation

<18.8.3-r2
  • L
Improper Certificate Validation

<18.8.3-r2
  • L
CVE-2026-46598

<18.8.3-r2
  • L
Out-of-Bounds

<18.8.3-r2
  • L
Improper Verification of Cryptographic Signature

<18.8.3-r2
  • L
Integer Overflow or Wraparound

<18.8.3-r2
  • L
Missing Authorization

<18.8.3-r2
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<18.8.3-r2
  • L
Missing Authorization

<18.8.3-r2
  • L
CVE-2026-46595

<18.8.3-r2
  • L
GHSA-mqqf-5wvp-8fh8

<18.6.5-r0
  • L
Resource Exhaustion

<18.8.3-r0
  • L
CVE-2026-42507

<18.8.3-r0
  • L
CVE-2026-39821

<18.8.3-r0
  • L
CVE-2026-42504

<18.8.3-r0
  • M
Use of a Broken or Risky Cryptographic Algorithm

<18.6.0-r0
  • M
CVE-2025-47911

<18.4.1-r0
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<18.4.1-r0
  • L
CVE-2026-33815

<18.7.6-r0
  • L
Reachable Assertion

<18.4.1-r0
  • L
Cross-site Scripting (XSS)

<18.8.3-r0
  • L
Use of a Broken or Risky Cryptographic Algorithm

<18.6.0-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<18.8.3-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<18.8.3-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<18.8.3-r0
  • L
Improper Privilege Management

<18.8.3-r0
  • L
CVE-2026-27145

<18.8.3-r0
  • L
CVE-2026-39824

<18.8.3-r0
  • L
GHSA-w5pp-99ch-qj29

<18.8.2-r0
  • H
Improper Validation of Array Index

<18.7.6-r0
  • C
Improper Encoding or Escaping of Output

<18.8.2-r0
  • L
Directory Traversal

<18.8.2-r0
  • L
Cross-site Scripting (XSS)

<18.7.6-r0
  • H
Symlink Following

<18.7.6-r0
  • L
Uncontrolled Search Path Element

<18.7.6-r0
  • L
GHSA-pmwq-pjrm-6p5r

<18.9.1-r1
  • L
Directory Traversal

<18.8.1-r0
  • H
Incorrect Behavior Order: Validate Before Canonicalize

<18.8.1-r0
  • L
Uncontrolled Recursion

<18.8.1-r0
  • M
Out-of-bounds Write

<18.7.6-r1
  • H
NULL Pointer Dereference

<18.7.6-r1
  • L
CVE-2026-42499

<18.7.6-r1
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<18.7.6-r1
  • L
CVE-2026-42501

<18.7.6-r1
  • L
CVE-2026-39825

<18.7.6-r1
  • H
Allocation of Resources Without Limits or Throttling

<18.7.6-r1
  • M
Link Following

<18.7.6-r1
  • L
Improper Encoding or Escaping of Output

<18.7.6-r1
  • L
Cross-site Scripting (XSS)

<18.7.6-r1
  • H
Double Free

<18.7.6-r1
  • H
Off-by-one Error

<18.7.6-r0
  • C
SQL Injection

<18.7.6-r0
  • L
Improper Validation of Array Index

<18.7.6-r0
  • L
Improper Validation of Array Index

<18.7.6-r0
  • L
GHSA-pcgw-qcv5-h8ch

<18.7.6-r0
  • L
GHSA-hwqm-qvj9-4jr2

<18.7.6-r0
  • L
Improper Authorization

<18.7.6-r0
  • L
Improper Verification of Cryptographic Signature

<18.7.6-r0
  • H
Authentication Bypass

<18.7.6-r0
  • L
Improper Validation of Array Index

<18.7.6-r0
  • L
Integer Underflow

<18.7.6-r0
  • L
GHSA-xmrv-pmrh-hhx2

<18.7.6-r0
  • L
Uncaught Exception

<18.7.6-r0
  • L
CVE-2026-33816

<18.7.6-r0
  • L
Uncontrolled Memory Allocation

<18.7.6-r0
  • H
Insufficiently Protected Credentials

<18.7.6-r0
  • M
Directory Traversal

<18.7.6-r0
  • L
Allocation of Resources Without Limits or Throttling

<18.7.6-r0
  • H
Integer Overflow or Wraparound

<18.7.6-r0
  • L
Allocation of Resources Without Limits or Throttling

<18.7.6-r0
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<18.7.2-r1
  • C
CVE-2026-27143

<18.7.2-r1
  • H
Incorrect Authorization

<18.7.2-r1
  • M
Allocation of Resources Without Limits or Throttling

<18.7.2-r1
  • M
Link Following

<18.7.2-r1
  • L
CVE-2026-32280

<18.7.2-r1
  • M
Cross-site Scripting (XSS)

<18.7.2-r1
  • H
Allocation of Resources Without Limits or Throttling

<18.7.2-r1
  • H
Improper Certificate Validation

<18.7.2-r1
  • H
Improper Certificate Validation

<18.7.2-r1
  • H
CVE-2025-15558

<18.7.6-r0
  • L
Untrusted Search Path

<18.7.6-r0
  • L
Direct Request ('Forced Browsing')

<18.7.2-r0
  • L
Cross-site Scripting (XSS)

<18.7.2-r0
  • L
Improper Certificate Validation

<18.7.2-r0
  • L
Improper Certificate Validation

<18.7.2-r0
  • L
Directory Traversal

<18.7.2-r0
  • M
Improper Validation of Integrity Check Value

<18.7.1-r0
  • M
Directory Traversal

<18.7.6-r0
  • L
CVE-2025-61732

<18.6.7-r0
  • C
CVE-2025-68121

<18.6.7-r0
  • H
Improper Verification of Cryptographic Signature

<18.7.6-r0
  • H
Reachable Assertion

<18.7.6-r0
  • L
NULL Pointer Dereference

<18.7.6-r0
  • L
Directory Traversal

<18.7.6-r0
  • L
Server-Side Request Forgery (SSRF)

<18.7.6-r0
  • L
CVE-2025-61731

<18.6.4-r0
  • L
Allocation of Resources Without Limits or Throttling

<18.6.4-r0
  • L
Allocation of Resources Without Limits or Throttling

<18.6.4-r0
  • L
Out-of-bounds Write

<18.6.4-r0
  • L
CVE-2025-61730

<18.6.4-r0
  • L
Allocation of Resources Without Limits or Throttling

<18.5.1-r0
  • L
Asymmetric Resource Consumption (Amplification)

<18.7.6-r0
  • L
Improper Certificate Validation

<18.5.0-r0
  • L
Improper Certificate Validation

<18.5.0-r0
  • L
CVE-2025-47914

<18.4.1-r0
  • L
CVE-2025-58181

<18.4.1-r0
  • H
Incorrect Execution-Assigned Permissions

<18.3.2-r0
  • M
Memory Leak

<18.3.2-r0
  • L
CVE-2025-58183

<18.2.10-r0
  • L
Allocation of Resources Without Limits or Throttling

<18.2.10-r0
  • L
Allocation of Resources Without Limits or Throttling

<18.2.10-r0
  • L
Allocation of Resources Without Limits or Throttling

<18.2.10-r0
  • L
Information Exposure Through Log Files

<18.2.10-r0
  • L
CVE-2025-61725

<18.2.10-r0
  • L
Improper Certificate Validation

<18.2.10-r0
  • L
CVE-2025-47912

<18.2.10-r0
  • L
Algorithmic Complexity

<18.2.10-r0
  • L
CVE-2025-58186

<18.2.10-r0
  • L
Reachable Assertion

<18.3.2-r0
  • L
CVE-2025-47910

<18.2.0-r0
  • L
Allocation of Resources Without Limits or Throttling

<18.1.4-r1
  • L
Use of Uninitialized Resource

<18.1.4-r1