Direct Vulnerabilities

Known vulnerabilities in the ignition package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Excessive Platform Resource Consumption within a Loop

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • H
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • H
Cross-site Scripting (XSS)

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Arbitrary Code Injection

*
  • H
Unchecked Input for Loop Condition

*
  • M
Information Exposure

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • H
Unchecked Input for Loop Condition

*
  • H
Creation of Immutable Text Using String Concatenation

*
  • M
Cross-site Scripting (XSS)

*
  • M
External Control of Assumed-Immutable Web Parameter

*
  • M
Improper Output Neutralization for Logs

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Improper Validation of Unsafe Equivalence in Input

*
  • M
Improper Validation of Unsafe Equivalence in Input

*
  • M
HTTP Request Smuggling

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Improper Validation of Unsafe Equivalence in Input

*
  • M
Cross-site Scripting (XSS)

*
  • M
Excessive Platform Resource Consumption within a Loop

*
  • M
NULL Pointer Dereference

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Certificate Validation

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • L
CVE-2025-58186

*
  • M
Reachable Assertion

*
  • M
Creation of Immutable Text Using String Concatenation

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Output Neutralization for Logs

*
  • M
Expected Behavior Violation

*
  • M
Expected Behavior Violation

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
CVE-2025-4673

*
  • M
HTTP Request Smuggling

*
  • M
Improper Input Validation

*
  • H
Improper Validation of Syntactic Correctness of Input

*
  • M
Information Exposure

*
  • L
Improper Verification of Cryptographic Signature

*
  • M
Use of Uninitialized Variable

*
  • H
Memory Leak

*
  • M
Improper Certificate Validation

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Arbitrary Code Injection

*
  • M
Resource Exhaustion

*
  • H
Resource Exhaustion

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Cross-site Scripting (XSS)

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Cross-site Scripting (XSS)

*
  • M
Resource Exhaustion

*
  • M
Directory Traversal

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Resource Exhaustion

*
  • M
Arbitrary Code Injection

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
CVE-2022-41715

*
  • M
HTTP Request Smuggling

*
  • M
Resource Exhaustion

*
  • L
Resource Exhaustion

*
  • M
Information Exposure

*
  • M
Improperly Controlled Sequential Memory Allocation

*
  • M
HTTP Request Smuggling

*
  • M
Incorrect Authorization

*
  • L
Insufficient Entropy

*
  • M
Integer Overflow or Wraparound

*