
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Allocation of Resources Without Limits or Throttling
liquidjs is an A simple, expressive, safe and Shopify compatible template engine in pure JavaScript.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling through the date filter in filters/date.ts and the strftime formatter in strftime.ts. An attacker can exhaust memory or hang rendering by supplying a crafted date format string that includes extremely large numeric width directives or non-string format values that expand into large padding allocations.
The vulnerable code builds padding one character at a time and does not account for the allocation cost of strftime width handling in its memory accounting path, so a user-controlled template or data value can drive unbounded allocation work during date formatting. This can crash the process or make the application unresponsive while rendering attacker-controlled templates.
Session Fixation
gradio is a Python library for easily interacting with trained machine learning models
Affected versions of this package are vulnerable to Session Fixation via /proxy reverse proxy requests. A malicious HF Space can hijack user sessions and gain unauthorized access to other users' authenticated contexts by injecting malicious cookies through a shared HTTP client used in the reverse proxy endpoint. This allows the attacker's cookies to be replayed in subsequent proxy requests to other legitimate targets, impacting all users of the same deployment.
Use of a One-Way Hash with a Predictable Salt
Affected versions of this package are vulnerable to Use of a One-Way Hash with a Predictable Salt in the getSecretKeySaltGenerator function of the Password Hash Handler component. An attacker can compromise the confidentiality of hashed secrets by exploiting the use of a predictable salt in password hashing, allowing easier brute force or precomputed attacks.
Recent vulnerabilities disclosed by Snyk
- H
CSV Injection in json-2-csv (npm)- H
Denial of Service (DoS) in pacote (npm)- M
Access Control Bypass in @koa/router (npm)- M
Improper Handling of Highly Compressed Data (Data Amplification) in exifreader (npm)- H
Improper Validation of Specified Quantity in Input in exifreader (npm)
Snyk security
researchers
have disclosed
3493
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




