We’ve disclosed 13 vulnerabilities 🎉
The Snyk security team helps disclose many vulnerabilities every month, in key packages across a variety
of ecosystems. We work closely with open source package maintainers in order to ensure all vulnerabilities
are responsibly and efficiently handled in a timely manner.
Our ever-growing list of sources include:
-
Vulnerability disclosures and reports sent to us from members of the community
-
Vulnerabilities we've uncovered by monitoring security chatter and trends across open source ecosystems
-
Partnerships with organizations and academic institutions
-
Research done internally by the Snyk Security Team
Featured disclosed vulnerabilities
Recently disclosed vulnerabilities by Snyk
- H
Prototype Pollution in dset (npm)
- M
Denial of Service (DoS) in aaptjs (npm)
- M
Prototype Pollution in node-gettext (npm)
- H
Command Injection in aaptjs (npm)
- M
Insecure Randomness in github.com/greenpau/go-authcrunch/pkg/util (golang)
- M
Insecure Randomness in github.com/greenpau/go-authcrunch/pkg/identity (golang)
- M
Open Redirect in github.com/gophish/gophish/controllers (golang)
- C
Command Injection in check-branches (npm)
- M
Arbitrary File Write via Archive Extraction (Zip Slip) in github.com/ollama/ollama/cmd (golang)
- M
Arbitrary File Write via Archive Extraction (Zip Slip) in github.com/ollama/ollama/server (golang)