paketo-buildpacks-yarn

Direct Vulnerabilities

Known vulnerabilities in the paketo-buildpacks-yarn package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Information Exposure

<2.4.1-r0
  • L
Resource Exhaustion

*
  • L
Improper Handling of Case Sensitivity

*
  • L
Improper Validation of Array Index

*
  • L
CVE-2026-78662

*
  • L
CVE-2026-56855

*
  • L
Resource Exhaustion

*
  • L
CVE-2026-56854

<2.4.1-r1
  • L
Race Condition

<2.4.1-r0
  • L
CVE-2026-56860

<2.4.1-r1
  • L
CVE-2026-33818

<2.4.1-r1
  • L
CVE-2026-56864

<2.4.1-r1
  • L
CVE-2026-56865

<2.4.1-r1
  • L
CVE-2026-56853

<2.4.1-r1
  • L
CVE-2026-56859

<2.4.1-r1
  • L
CVE-2026-56862

<2.4.1-r1
  • L
CVE-2026-56858

<2.4.1-r1
  • L
GO-2026-5932

*
  • L
Directory Traversal

<2.4.0-r0
  • L
Link Following

<2.4.0-r0
  • L
GHSA-259r-337f-4rfw

<2.2.37-r0
  • L
CVE-2026-56852

<2.2.38-r0
  • L
CVE-2026-46600

<2.2.35-r0
  • L
GHSA-hrxh-6v49-42gf

<2.2.40-r0
  • L
CVE-2026-39822

<2.2.38-r0
  • L
CVE-2026-42505

<2.2.38-r0
  • H
Incorrect Execution-Assigned Permissions

<2.2.32-r0
  • M
Memory Leak

<2.2.32-r0
  • L
Uncontrolled Memory Allocation

<2.2.33-r0
  • H
Integer Overflow or Wraparound

<2.2.32-r0
  • L
Uncontrolled Memory Allocation

<2.2.32-r0
  • L
CVE-2026-50195

<2.2.36-r0
  • L
CVE-2026-47262

<2.2.36-r0
  • L
Improper Input Validation

<2.2.32-r0
  • L
Symlink Following

<2.2.36-r0
  • L
Improper Input Validation

<2.2.36-r0
  • L
Directory Traversal

<2.2.32-r0
  • L
Improper Certificate Validation

<2.2.32-r0
  • L
Improper Authorization

<2.2.32-r0
  • H
Incorrect Behavior Order: Validate Before Canonicalize

<2.2.32-r0
  • L
Uncontrolled Recursion

<2.2.32-r0
  • L
Improper Verification of Cryptographic Signature

<2.2.32-r0
  • C
Improper Encoding or Escaping of Output

<2.2.32-r0
  • L
GHSA-xmrv-pmrh-hhx2

<2.2.32-r0
  • L
Improper Validation of Array Index

<2.2.32-r0
  • L
Missing Authorization

<2.2.32-r0
  • L
Directory Traversal

<2.2.32-r0
  • L
CVE-2026-39821

<2.2.32-r0
  • L
GHSA-w5pp-99ch-qj29

<2.2.32-r0
  • H
Authentication Bypass

<2.2.32-r0
  • L
Integer Overflow or Wraparound

<2.2.32-r0
  • L
Improper Privilege Management

<2.2.32-r0
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<2.2.32-r0
  • L
CVE-2026-46598

<2.2.32-r0
  • L
Uncaught Exception

<2.2.32-r0
  • L
Cross-site Scripting (XSS)

<2.2.32-r0
  • L
Allocation of Resources Without Limits or Throttling

<2.2.32-r0
  • L
Resource Exhaustion

<2.2.32-r0
  • L
Improper Cleanup on Thrown Exception

<2.2.32-r0
  • L
Untrusted Search Path

<2.2.32-r0
  • H
Insufficiently Protected Credentials

<2.2.32-r0
  • H
Untrusted Search Path

<2.2.32-r0
  • C
CVE-2026-1229

<2.2.32-r0
  • L
CVE-2026-4660

<2.2.32-r0
  • H
CVE-2025-15558

<2.2.32-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<2.2.32-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<2.2.32-r0
  • L
CVE-2026-46595

<2.2.32-r0
  • L
Improper Certificate Validation

<2.2.32-r0
  • L
Incorrect Type Conversion or Cast

<2.2.32-r0
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<2.2.32-r0
  • L
Missing Authorization

<2.2.32-r0
  • H
Off-by-one Error

<2.2.32-r0
  • L
Cross-site Scripting (XSS)

<2.2.32-r0
  • L
Out-of-Bounds

<2.2.32-r0
  • L
Deserialization of Untrusted Data

<2.2.32-r0
  • L
Uncontrolled Search Path Element

<2.2.32-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<2.2.32-r0
  • L
Integer Underflow

<2.2.32-r0
  • M
Improper Validation of Integrity Check Value

<2.2.32-r0
  • L
Improper Certificate Validation

<2.2.32-r0
  • L
CVE-2026-39824

<2.2.32-r0
  • H
Symlink Following

<2.2.32-r0