opentofu-fips-1.10

Direct Vulnerabilities

Known vulnerabilities in the opentofu-fips-1.10 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Uncaught Exception

<1.10.10-r4
  • H
Integer Overflow or Wraparound

<1.10.10-r4
  • L
Incorrect Type Conversion or Cast

<1.10.10-r4
  • M
Information Exposure

<1.10.10-r4
  • L
Improper Certificate Validation

<1.10.10-r4
  • L
Allocation of Resources Without Limits or Throttling

<1.10.10-r4
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<1.10.10-r4
  • L
Improper Verification of Cryptographic Signature

<1.10.10-r4
  • C
CVE-2026-1229

<1.10.10-r4
  • L
CVE-2026-46598

<1.10.10-r4
  • L
Deserialization of Untrusted Data

<1.10.10-r4
  • L
Improper Certificate Validation

<1.10.10-r4
  • L
CVE-2026-56852

<1.10.10-r4
  • L
CVE-2026-46600

<1.10.10-r4
  • L
Improper Certificate Validation

<1.10.10-r4
  • L
Uncontrolled Memory Allocation

<1.10.10-r3
  • L
Allocation of Resources Without Limits or Throttling

<1.10.10-r2
  • L
Directory Traversal

<1.10.10-r1
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.10.10-r1
  • L
Resource Exhaustion

<1.10.10-r1
  • L
CVE-2026-39824

<1.10.10-r1
  • L
CVE-2025-47914

<1.10.10-r1
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.10.10-r1
  • M
CVE-2025-47911

<1.10.10-r1
  • L
Cleartext Transmission of Sensitive Information

<1.10.10-r1
  • L
GHSA-vh4v-2xq2-g5cg

<1.10.10-r1
  • L
Reachable Assertion

<1.10.10-r1
  • L
CVE-2025-58181

<1.10.10-r1
  • L
Cross-site Scripting (XSS)

<1.10.10-r1
  • L
External Control of File Name or Path

<1.10.10-r1
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.10.10-r1
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.10.10-r1
  • L
CVE-2025-8959

<1.10.10-r1
  • L
GHSA-fv92-fjc5-jj9h

<1.10.10-r1
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.10.10-r1
  • L
CVE-2025-22868

<1.10.10-r1
  • L
Server-Side Request Forgery (SSRF)

<1.10.10-r1
  • L
CVE-2026-39821

<1.10.10-r1
  • L
Improper Validation of Specified Type of Input

<1.10.10-r1
  • L
Out-of-Bounds

<1.10.10-r4
  • L
Improper Authorization

<1.10.10-r1
  • L
CVE-2026-46595

<1.10.10-r4
  • L
Integer Overflow or Wraparound

<1.10.10-r4
  • L
Missing Authorization

<1.10.10-r4
  • L
Missing Authorization

<1.10.10-r4