signoz-otel-collector-fips

Direct Vulnerabilities

Known vulnerabilities in the signoz-otel-collector-fips package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Missing Initialization of Resource

<0.144.6-r1
  • L
Reachable Assertion

<0.129.0-r1
  • L
CVE-2025-58181

<0.129.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.129.0-r1
  • M
Information Exposure

<0.129.0-r1
  • L
CVE-2025-63811

<0.129.0-r1
  • L
CVE-2025-47914

<0.129.0-r1
  • M
CVE-2025-47911

<0.129.0-r1
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<0.129.0-r1
  • L
Untrusted Search Path

*
  • L
GHSA-mx64-mj3q-7prj

*
  • L
CVE-2026-39825

*
  • L
CVE-2026-56852

*
  • M
Cross-site Scripting (XSS)

*
  • L
Improper Validation of Array Index

*
  • L
GHSA-259r-337f-4rfw

*
  • H
Improper Certificate Validation

*
  • L
Improper Initialization

*
  • L
Integer Overflow or Wraparound

*
  • L
Integer Overflow or Wraparound

*
  • M
Link Following

*
  • L
Uncaught Exception

*
  • L
CVE-2026-42501

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
CVE-2026-42507

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
CVE-2026-46600

*
  • H
Untrusted Search Path

*
  • M
Link Following

*
  • L
Resource Exhaustion

*
  • H
Incorrect Authorization

*
  • L
CVE-2026-32280

*
  • L
CVE-2026-42504

*
  • H
NULL Pointer Dereference

*
  • L
Direct Request ('Forced Browsing')

*
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • L
Improper Encoding or Escaping of Output

*
  • L
CVE-2026-27145

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
CVE-2026-42499

*
  • L
GHSA-hrxh-6v49-42gf

*
  • L
CVE-2026-42505

*
  • L
Cross-site Scripting (XSS)

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Double Free

*
  • L
Cross-site Scripting (XSS)

*
  • L
CVE-2026-39822

*
  • L
Uncontrolled Memory Allocation

*
  • L
Directory Traversal

*
  • M
Out-of-bounds Write

*
  • C
CVE-2026-27143

*
  • L
Improper Authorization

*
  • L
GO-2026-5932

*
  • L
Cross-site Scripting (XSS)

*
  • L
CVE-2026-55701

*
  • L
Information Exposure

*
  • L
Uncontrolled Search Path Element

*
  • H
Symlink Following

*
  • H
Off-by-one Error

*
  • L
Resource Exhaustion

*
  • M
Cross-site Scripting (XSS)

*
  • L
Uncontrolled Memory Allocation

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Cross-site Scripting (XSS)

*
  • L
CVE-2026-2303

*
  • L
GHSA-xmrv-pmrh-hhx2

*
  • L
Information Exposure

*
  • H
Authentication Bypass

*
  • L
Deserialization of Untrusted Data

<0.144.6-r0
  • L
Incorrect Type Conversion or Cast

<0.144.6-r0
  • L
CVE-2026-39821

<0.144.6-r0
  • L
Improper Certificate Validation

<0.144.6-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<0.144.6-r0
  • L
Improper Certificate Validation

<0.144.6-r0
  • L
Cross-site Scripting (XSS)

<0.144.6-r0
  • L
Improper Certificate Validation

<0.144.6-r0
  • L
Improper Verification of Cryptographic Signature

<0.144.6-r0
  • L
Resource Exhaustion

<0.144.6-r0
  • L
CVE-2026-46598

<0.144.6-r0
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<0.144.6-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<0.144.6-r0
  • L
CVE-2026-39824

<0.144.6-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<0.144.6-r0
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0.144.6-r0
  • L
Integer Overflow or Wraparound

<0.144.6-r0
  • L
Out-of-Bounds

<0.144.6-r0
  • L
Missing Authorization

<0.144.6-r0
  • L
Missing Authorization

<0.144.6-r0
  • L
CVE-2026-46595

<0.144.6-r0