oracle-free-21-extras

Direct Vulnerabilities

Known vulnerabilities in the oracle-free-21-extras package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Improper Certificate Validation

*
  • L
Resource Exhaustion

*
  • L
GHSA-r7wm-3cxj-wff9

*
  • L
CVE-2026-59890

*
  • M
CVE-2026-8643

*
  • L
Incomplete Blacklist

*
  • L
Incomplete Blacklist

*
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Resource Exhaustion

*
  • H
CVE-2022-3509

*
  • L
GHSA-5cpq-8wj7-hf2v

*
  • H
XML External Entity (XXE) Injection

*
  • M
Cross-site Scripting (XSS)

*
  • L
GHSA-537c-gmf6-5ccf

*
  • M
Buffer Overflow

*
  • L
GHSA-6v7p-g79w-8964

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Improper Validation of Integrity Check Value

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • M
Insecure Temporary File

*
  • L
Arbitrary Command Injection

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • H
Directory Traversal

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • L
Information Exposure

*
  • H
Inefficient Regular Expression Complexity

*
  • M
CVE-2023-45803

*
  • H
Deserialization of Untrusted Data

*
  • L
CVE-2026-3219

*
  • H
Improper Encoding or Escaping of Output

*
  • H
Out-of-bounds Write

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
GHSA-72hv-8253-57qq

*
  • M
Information Exposure

*
  • H
Deserialization of Untrusted Data

*
  • L
CVE-2026-6357

*
  • M
Improper Validation of Certificate with Host Mismatch

*
  • M
Open Redirect

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Buffer Overflow

*
  • H
CVE-2022-3171

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
CRLF Injection

*
  • M
Inefficient Regular Expression Complexity

*
  • H
CVE-2021-36090

*
  • M
CVE-2023-32681

*
  • H
Inefficient Regular Expression Complexity

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Incorrect Permission Assignment for Critical Resource

*
  • M
CVE-2024-0727

*
  • L
Stack-based Buffer Overflow

*
  • L
Resource Exhaustion

*
  • M
Insecure Storage of Sensitive Information

*
  • H
Improper Certificate Validation

*
  • L
CVE-2026-1703

*
  • H
CVE-2022-3510

*
  • H
Out-of-bounds Write

*
  • L
GHSA-jm77-qphf-c4w8

*
  • L
CVE-2025-8869

*
  • M
CVE-2021-22569

*
  • M
Improper Certificate Validation

*
  • L
CVE-2024-35195

*
  • L
Resource Exhaustion

*
  • H
CVE-2023-43804

*
  • L
Arbitrary Code Injection

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • H
Insufficient Verification of Data Authenticity

*
  • M
Unrestricted Upload of File with Dangerous Type

*
  • M
NULL Pointer Dereference

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • L
GHSA-v8gr-m533-ghj9

*
  • H
Files or Directories Accessible to External Parties

*
  • M
Arbitrary Code Injection

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Resource Exhaustion

*
  • M
Open Redirect

*
  • M
CVE-2026-26007

*
  • M
Cross-site Scripting (XSS)

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
CVE-2020-25659

*
  • M
CVE-2024-37891

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Directory Traversal

*
  • M
Insufficient Comparison

*
  • H
Information Exposure

*
  • M
Improper Certificate Validation

*
  • M
Improper Input Validation

*
  • L
CVE-2025-48976

*
  • C
Deserialization of Untrusted Data

*
  • C
CVE-2022-21797

*
  • C
CVE-2018-20060

*
  • C
Insufficient Verification of Data Authenticity

*
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Improper Input Validation

*
  • C
Expression Language Injection

*
  • C
Improper Input Validation

*