Known vulnerabilities in yarnpkg
Vendor:
Fedoraproject
Software:
yarnpkg
Software CPE:
cpe:2.3:o:fedoraproject:yarnpkg:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
28
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
1.22.22-18.fc44
1.22.22-18.el10_3
1.22.22-18.fc42
1.22.22-18.el9
1.22.22-18.fc43
1.22.22-17.fc43
1.22.22-17.fc44
1.22.22-17.el10_3
1.22.22-17.fc42
1.22.22-16.el10_2
1.22.22-16.el9
1.22.22-16.fc42
1.22.22-16.fc43
1.22.22-12.fc42
1.22.22-12.fc41
1.22.22-12.fc43
1.22.22-11.fc41
1.22.22-11.fc42
1.22.22-11.el9
1.22.22-11.el10_1
1.22.22-9.el8
1.22.22-9.fc41
1.22.22-9.el9
1.22.22-9.el10_1
1.22.22-9.fc42
1.22.22-8.el8
1.22.22-8.el10_1
1.22.22-8.fc42
1.22.22-8.fc41
1.22.22-8.el9
1.22.22-7.el8
1.22.22-7.fc42
1.22.22-7.fc40
1.22.22-7.fc41
1.22.22-7.el9
1.22.22-5.el9
1.22.22-5.fc39
1.22.22-5.fc41
1.22.22-5.fc40
1.22.22-4.fc39
1.22.22-4.fc41
1.22.22-4.fc40
1.22.22-2.fc40
1.22.21-2.fc39
1.22.21-2.fc38
1.22.19-5.el9
1.22.19-5.fc37
1.22.19-5.fc38
1.22.19-5.fc36
1.22.19-3.fc36
1.22.19-3.fc37
1.22.19-2.fc36
1.22.19-2.fc37
Vulnerabilities (28)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU125803 - Improper Control of Generation of Code ('Code Injection') CVE-2026-4800 |
CWE-94 | High | 1.22.22-18.el9, 1.22.22-18.el10_3, 1.22.22-18.fc42, 1.22.22-18.fc43, 1.22.22-18.fc44 | 10.04.2026 |
SB2026041094 SB20260410101 SB20260410102 and 65 more |
||
| #VU121928 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\') CVE-2025-13465 |
CWE-1321 | Medium | 1.22.22-16.el9, 1.22.22-16.el10_2, 1.22.22-16.fc42, 1.22.22-16.fc43 | 22.01.2026 |
SB2026012209 SB2026012701 SB2026012744 and 71 more |
||
| #VU121666 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\') CVE-2025-64718 |
CWE-1321 | Medium | 1.22.22-17.el10_3, 1.22.22-17.fc42, 1.22.22-17.fc43, 1.22.22-17.fc44, 1.22.22-18.fc43 | 19.01.2026 |
SB2026011995 SB2026011999 SB20260119100 and 30 more |
||
| #VU117332 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-59343 |
CWE-22 | High | 1.22.22-12.fc41, 1.22.22-12.fc42, 1.22.22-12.fc43 | 17.10.2025 |
SB2025101702 SB2025101703 SB2025101704 and 22 more |
||
| #VU115829 - Resource exhaustion CVE-2025-8262 |
CWE-400 | Medium | 1.22.22-11.el9, 1.22.22-11.el10_1, 1.22.22-11.fc41, 1.22.22-11.fc42 | 18.09.2025 |
SB20250918113 SB20250918114 SB20250918115 and 3 more |
||
| #VU113173 - Use of Insufficiently Random Values CVE-2025-7783 |
CWE-330 | Medium | 1.22.22-11.el9, 1.22.22-11.el10_1, 1.22.22-11.fc41, 1.22.22-11.fc42 | 23.07.2025 |
SB2025072332 SB2025072333 SB2025081876 and 63 more |
||
| #VU112157 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-48387 |
CWE-22 | High | 1.22.22-8.el8, 1.22.22-8.el9, 1.22.22-8.el10_1, 1.22.22-8.fc41, 1.22.22-8.fc42 | 03.07.2025 |
SB2025070352 SB2025070353 SB2025070354 and 13 more |
||
| #VU111944 - Improper input validation CVE-2025-6545 |
CWE-20 | Medium | 1.22.22-9.el8, 1.22.22-9.el9, 1.22.22-9.el10_1, 1.22.22-9.fc41, 1.22.22-9.fc42 | 25.06.2025 |
SB2025062533 SB2025062536 SB2025062537 and 11 more |
||
| #VU111943 - Improper input validation CVE-2025-6547 |
CWE-20 | Medium | 1.22.22-9.el8, 1.22.22-9.el9, 1.22.22-9.el10_1, 1.22.22-9.fc41, 1.22.22-9.fc42 | 25.06.2025 |
SB2025062533 SB2025062536 SB2025062537 and 10 more |
||
| #VU106282 - Improper Link Resolution Before File Access ('Link Following') CVE-2024-12905 |
CWE-59 | High | 1.22.22-7.el8, 1.22.22-7.el9, 1.22.22-7.fc40, 1.22.22-7.fc41, 1.22.22-7.fc42 | 31.03.2025 |
SB2025033140 SB2025033150 SB2025033151 and 15 more |
||
| #VU98513 - Improper input validation CVE-2024-48949 |
CWE-20 | Medium | 1.22.22-4.fc39, 1.22.22-4.fc40, 1.22.22-4.fc41, 1.22.22-5.el9, 1.22.22-5.fc39, 1.22.22-5.fc40, 1.22.22-5.fc41, 1.22.22-7.el8 | 14.10.2024 |
SB2024101490 SB20241014105 SB20241014106 and 25 more |
||
| #VU97606 - Improper Verification of Cryptographic Signature CVE-2024-42459 |
CWE-347 | Medium | 1.22.22-5.el9 | 19.09.2024 |
SB2024091934 SB2024091939 SB2024092062 and 23 more |
||
| #VU97605 - Improper Verification of Cryptographic Signature CVE-2024-42460 |
CWE-347 | Medium | 1.22.22-5.el9 | 19.09.2024 |
SB2024091934 SB2024091939 SB2024092062 and 24 more |
||
| #VU97604 - Improper Verification of Cryptographic Signature CVE-2024-42461 |
CWE-347 | Medium | 1.22.22-5.el9 | 19.09.2024 |
SB2024091934 SB2024091939 SB2024092062 and 24 more |
||
| #VU94329 - NULL Pointer Dereference CVE-2024-37890 |
CWE-476 | Medium | 1.22.22-5.el9, 1.22.22-5.fc39, 1.22.22-5.fc40, 1.22.22-5.fc41 | 15.07.2024 |
SB2024071508 SB2024071933 SB2024081608 and 32 more |
||
| #VU92406 - Incorrect Regular Expression CVE-2024-4067 |
CWE-185 | Medium | 1.22.22-2.fc40, 1.22.22-5.el9 | 20.06.2024 |
SB20240620121 SB2024062832 SB2024070501 and 41 more |
||
| #VU88532 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2024-29041 |
CWE-601 | Medium | 1.22.22-5.el9 | 15.04.2024 |
SB2024041530 SB2024041532 SB2024042918 and 44 more |
||
| #VU82608 - Improper Verification of Cryptographic Signature CVE-2023-46234 |
CWE-347 | Medium | 1.22.21-2.fc38, 1.22.21-2.fc39, 1.22.22-5.el9 | 31.10.2023 |
SB2023103186 SB20231031104 SB2023110166 and 14 more |
||
| #VU80323 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\') CVE-2023-26136 |
CWE-1321 | High | 1.22.21-2.fc38, 1.22.21-2.fc39, 1.22.22-5.el9 | 04.09.2023 |
SB2023090411 SB2023090423 SB2023090816 and 42 more |
||
| #VU78932 - Incorrect Regular Expression CVE-2022-25883 |
CWE-185 | Medium | 1.22.22-5.el9 | 03.08.2023 |
SB2023080361 SB2023080362 SB2023081514 and 73 more |
Showing elements 1 - 20 out of 28