policy-controller

Direct Vulnerabilities

Known vulnerabilities in the policy-controller package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Integer Overflow or Wraparound

<0.15.1-r8
  • L
CVE-2026-39829

<0.15.1-r8
  • L
CVE-2026-39831

<0.15.1-r8
  • L
Incorrect Type Conversion or Cast

<0.15.1-r8
  • L
Asymmetric Resource Consumption (Amplification)

<0.15.1-r0
  • L
GHSA-4qg8-fj49-pxjh

<0.15.1-r0
  • L
GHSA-pmwq-pjrm-6p5r

<0.15.1-r6
  • L
Improper Certificate Validation

<0.15.1-r4
  • L
GHSA-xm5m-wgh2-rrg3

<0.15.1-r4
  • H
Incorrect Authorization

<0.15.1-r4
  • M
Allocation of Resources Without Limits or Throttling

<0.15.1-r4
  • M
Cross-site Scripting (XSS)

<0.15.1-r4
  • H
Allocation of Resources Without Limits or Throttling

<0.15.1-r4
  • L
CVE-2026-32280

<0.15.1-r4
  • L
GHSA-7mr4-xjxg-34g6

<0.15.1-r4
  • L
GHSA-gjvh-7jh8-7xhm

<0.15.1-r4
  • L
GHSA-5w89-2c2x-6x66

<0.15.1-r4
  • L
GHSA-jrg3-gfjw-hm96

<0.15.1-r4
  • H
Improper Certificate Validation

<0.15.1-r4
  • L
GHSA-x4jj-h2v8-hqqv

<0.15.1-r4
  • L
GHSA-m4pr-4j3g-9v7v

<0.15.1-r4
  • L
GHSA-hfvc-g4fc-pqhx

<0.15.1-r2
  • H
Untrusted Search Path

<0.15.1-r2
  • L
GHSA-846p-jg2w-w324

<0.15.1-r0
  • L
GHSA-whqx-f9j3-ch6m

<0.15.1-r0
  • H
Reachable Assertion

<0.15.1-r0
  • L
Server-Side Request Forgery (SSRF)

<0.15.1-r0
  • M
Insufficient Verification of Data Authenticity

<0.15.1-r0
  • H
Improper Verification of Cryptographic Signature

<0.15.1-r0
  • L
GHSA-fphv-w9fq-2525

<0.15.1-r0
  • L
GHSA-fcv2-xgw5-pqxf

<0.15.1-r0
  • L
Directory Traversal

<0.15.1-r0
  • L
NULL Pointer Dereference

<0.15.1-r0
  • L
Uncaught Exception

<0.15.1-r1
  • L
GHSA-4c4x-jm2x-pf9j

<0.15.1-r0
  • L
GHSA-jqc5-w2xx-5vq4

<0.15.1-r0
  • L
GHSA-273p-m2cw-6833

<0.15.1-r0
  • M
Directory Traversal

<0.15.1-r0
  • L
GHSA-78h2-9frx-2jm8

<0.15.1-r1
  • L
GHSA-p77j-4mvh-x3m3

<0.14.0-r5
  • L
Improper Authorization

<0.14.0-r5
  • H
CVE-2025-15558

<0.14.0-r4
  • L
GHSA-p436-gjf2-799p

<0.14.0-r4
  • L
GHSA-gr56-3gp6-6gmj

<0.14.0-r1
  • L
CVE-2025-47914

<0.13.1-r2
  • L
Arbitrary Code Injection

<0.12.1-r1
  • L
GHSA-qxp5-gwg8-xv66

<0.12.0-r7
  • L
GHSA-9gcr-gp5f-jw27

<0.13.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.13.1-r1
  • L
CVE-2024-45341

<0.12.0-r1
  • L
GHSA-6m8w-jc87-6cr7

<0.12.1-r1
  • L
Algorithmic Complexity

<0.13.1-r1
  • L
GHSA-3f6r-qh9c-x6mm

<0.12.0-r1
  • L
GHSA-29wx-vh33-7x7r

<0.9.0-r11
  • L
GHSA-4f8r-qqr9-fq8j

<0.9.0-r10
  • L
CVE-2024-34156

<0.9.0-r9
  • C
CVE-2026-1229

<0.14.0-r2
  • L
Improper Handling of Exceptional Conditions

<0.9.0-r11
  • L
CVE-2025-61731

<0.14.0-r1
  • L
GHSA-c77r-fh37-x2px

<0.9.0-r10
  • L
GHSA-crqm-pwhx-j97f

<0.9.0-r9
  • L
CVE-2025-47912

<0.13.1-r1
  • L
GHSA-gm9r-q53w-2gh4

<0.14.0-r1
  • L
CVE-2025-22870

<0.12.0-r7
  • L
GHSA-qh38-484v-w52x

<0.13.1-r1
  • L
GHSA-xvqr-69v8-f3gv

<0.14.0-r1
  • L
CVE-2025-61730

<0.14.0-r1
  • L
Improper Certificate Validation

<0.13.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.12.0-r3
  • L
GHSA-cm6p-qc7v-m3jw

<0.14.0-r1
  • L
GHSA-6v2p-p543-phr9

<0.12.0-r5
  • L
GHSA-rjcg-56ph-3qvg

<0.13.1-r1
  • L
GHSA-jwmf-chvc-rf92

<0.13.1-r1
  • L
GHSA-c6gw-w398-hv78

<0.12.0-r3
  • L
Allocation of Resources Without Limits or Throttling

<0.13.1-r1
  • L
GHSA-hjx7-fpxx-mj48

<0.13.1-r1
  • L
CVE-2025-22868

<0.12.0-r5
  • L
Improper Certificate Validation

<0.13.1-r4
  • L
GHSA-7c64-f9jr-v9h2

<0.13.1-r4
  • L
GHSA-mh63-6h87-95cp

<0.12.0-r8
  • L
GHSA-cxq7-xw9v-rcv3

<0.13.1-r1
  • L
CVE-2025-61725

<0.13.1-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.13.1-r1
  • L
GHSA-5mh9-3jwc-rp59

<0.13.1-r4
  • L
Asymmetric Resource Consumption (Amplification)

<0.12.0-r8
  • L
CVE-2024-34158

<0.9.0-r9
  • L
GHSA-wcw9-47fp-rrfr

<0.13.1-r1
  • L
Out-of-bounds Write

<0.14.0-r1
  • L
Allocation of Resources Without Limits or Throttling

<0.14.0-r1
  • L
CVE-2025-22871

<0.12.0-r9
  • L
CVE-2025-58183

<0.13.1-r1
  • L
GHSA-j5pm-7495-qmr3

<0.13.0-r2
  • L
GHSA-j7vj-rw65-4v26

<0.9.0-r9
  • L
CVE-2024-45336

<0.12.0-r1
  • L
CVE-2024-45337

<0.11.0-r1
  • L
GHSA-7wrw-r4p8-38rx

<0.12.0-r1
  • L
GHSA-g9pc-8g42-g6vq

<0.12.0-r9
  • L
GHSA-9h8m-3fm2-qjrq

<0.14.0-r3
  • L
GHSA-v778-237x-gjrc

<0.11.0-r1
  • L
GHSA-447v-2qg4-h8hc

<0.13.1-r1
  • L
Race Condition

<0.9.0-r10
  • L
CVE-2025-58186

<0.13.1-r1
  • L
GHSA-frhw-mqj2-wxw2

<0.13.1-r1
  • L
Information Exposure Through Log Files

<0.13.1-r1
  • L
Race Condition

<0.13.0-r2
  • L
CVE-2024-34155

<0.9.0-r9
  • L
Untrusted Search Path

<0.14.0-r3
  • L
GHSA-7wwx-xj66-r44x

<0.13.1-r1
  • L
Improper Certificate Validation

<0.13.1-r4
  • L
GHSA-f6x5-jh6r-wrfv

<0.13.1-r2
  • L
CVE-2025-58181

<0.13.1-r2
  • L
GHSA-hcg3-q754-cr77

<0.12.0-r6
  • L
GHSA-q9hv-hpm4-hj6x

<0.14.0-r2
  • L
Improper Validation of Specified Type of Input

<0.12.1-r2
  • L
GHSA-fv92-fjc5-jj9h

<0.12.1-r3
  • H
Authentication Bypass

<0.9.0-r10
  • L
GHSA-w32m-9786-jp63

<0.11.0-r2
  • L
GHSA-8xfx-rj4p-23jm

<0.9.0-r9
  • L
GHSA-3whm-j4xm-rv8x

<0.12.0-r2
  • L
GHSA-j5w8-q4qc-rx2x

<0.13.1-r2
  • L
CVE-2025-22866

<0.12.0-r2
  • L
GHSA-2x5j-vhc8-9cwm

<0.12.1-r2
  • L
CVE-2025-22869

<0.12.0-r6
  • L
CVE-2024-45338

<0.11.0-r2
  • L
CVE-2024-41110

<0.9.0-r7
  • L
CVE-2024-24791

<0.9.0-r6
  • M
Information Exposure Through Log Files

<0.9.0-r5
  • M
Race Condition

<0.9.0-r4
  • M
CVE-2024-24789

<0.9.0-r3
  • C
CVE-2024-24790

<0.9.0-r3
  • L
CVE-2024-24788

<0.9.0-r2
  • L
CVE-2024-24787

<0.9.0-r2
  • M
CVE-2024-32473

<0.9.0-r1
  • M
Allocation of Resources Without Limits or Throttling

<0.9.0-r0
  • H
Allocation of Resources Without Limits or Throttling

<0.9.0-r0
  • L
CVE-2023-45288

<0.8.4-r5
  • H
Origin Validation Error

<0.8.4-r4
  • L
CVE-2024-24786

<0.8.4-r4
  • L
CVE-2024-28180

<0.8.4-r3
  • C
Arbitrary Code Injection

<0.7.0-r4
  • C
Arbitrary Code Injection

<0.7.0-r4
  • C
Arbitrary Code Injection

<0.7.0-r4
  • H
Exposure of Resource to Wrong Sphere

<0.7.0-r4
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<0.8.3-r1