Known vulnerabilities in yarnpkg

Software: yarnpkg
Software CPE: cpe:2.3:o:fedoraproject:yarnpkg:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 28
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting yarnpkg yarnpkg is affected by 28 known vulnerabilities: 6 high, 22 medium Critical High Medium Low

Vulnerabilities (28)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU125803 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-4800
CWE-94 High
No
No
1.22.22-18.el9, 1.22.22-18.el10_3, 1.22.22-18.fc42, 1.22.22-18.fc43, 1.22.22-18.fc44 10.04.2026 SB2026041094
SB20260410101
SB20260410102
and 65 more
#VU121928 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2025-13465
CWE-1321 Medium
No
No
1.22.22-16.el9, 1.22.22-16.el10_2, 1.22.22-16.fc42, 1.22.22-16.fc43 22.01.2026 SB2026012209
SB2026012701
SB2026012744
and 71 more
#VU121666 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2025-64718
CWE-1321 Medium
No
No
1.22.22-17.el10_3, 1.22.22-17.fc42, 1.22.22-17.fc43, 1.22.22-17.fc44, 1.22.22-18.fc43 19.01.2026 SB2026011995
SB2026011999
SB20260119100
and 30 more
#VU117332 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-59343
CWE-22 High
No
No
1.22.22-12.fc41, 1.22.22-12.fc42, 1.22.22-12.fc43 17.10.2025 SB2025101702
SB2025101703
SB2025101704
and 22 more
#VU115829 - Resource exhaustion
CVE-2025-8262
CWE-400 Medium
No
No
1.22.22-11.el9, 1.22.22-11.el10_1, 1.22.22-11.fc41, 1.22.22-11.fc42 18.09.2025 SB20250918113
SB20250918114
SB20250918115
and 3 more
#VU113173 - Use of Insufficiently Random Values
CVE-2025-7783
CWE-330 Medium
Available
No
1.22.22-11.el9, 1.22.22-11.el10_1, 1.22.22-11.fc41, 1.22.22-11.fc42 23.07.2025 SB2025072332
SB2025072333
SB2025081876
and 63 more
#VU112157 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-48387
CWE-22 High
No
No
1.22.22-8.el8, 1.22.22-8.el9, 1.22.22-8.el10_1, 1.22.22-8.fc41, 1.22.22-8.fc42 03.07.2025 SB2025070352
SB2025070353
SB2025070354
and 13 more
#VU111944 - Improper input validation
CVE-2025-6545
CWE-20 Medium
No
No
1.22.22-9.el8, 1.22.22-9.el9, 1.22.22-9.el10_1, 1.22.22-9.fc41, 1.22.22-9.fc42 25.06.2025 SB2025062533
SB2025062536
SB2025062537
and 11 more
#VU111943 - Improper input validation
CVE-2025-6547
CWE-20 Medium
No
No
1.22.22-9.el8, 1.22.22-9.el9, 1.22.22-9.el10_1, 1.22.22-9.fc41, 1.22.22-9.fc42 25.06.2025 SB2025062533
SB2025062536
SB2025062537
and 10 more
#VU106282 - Improper Link Resolution Before File Access ('Link Following')
CVE-2024-12905
CWE-59 High
No
No
1.22.22-7.el8, 1.22.22-7.el9, 1.22.22-7.fc40, 1.22.22-7.fc41, 1.22.22-7.fc42 31.03.2025 SB2025033140
SB2025033150
SB2025033151
and 15 more
#VU98513 - Improper input validation
CVE-2024-48949
CWE-20 Medium
No
No
1.22.22-4.fc39, 1.22.22-4.fc40, 1.22.22-4.fc41, 1.22.22-5.el9, 1.22.22-5.fc39, 1.22.22-5.fc40, 1.22.22-5.fc41, 1.22.22-7.el8 14.10.2024 SB2024101490
SB20241014105
SB20241014106
and 25 more
#VU97606 - Improper Verification of Cryptographic Signature
CVE-2024-42459
CWE-347 Medium
No
No
1.22.22-5.el9 19.09.2024 SB2024091934
SB2024091939
SB2024092062
and 23 more
#VU97605 - Improper Verification of Cryptographic Signature
CVE-2024-42460
CWE-347 Medium
No
No
1.22.22-5.el9 19.09.2024 SB2024091934
SB2024091939
SB2024092062
and 24 more
#VU97604 - Improper Verification of Cryptographic Signature
CVE-2024-42461
CWE-347 Medium
No
No
1.22.22-5.el9 19.09.2024 SB2024091934
SB2024091939
SB2024092062
and 24 more
#VU94329 - NULL Pointer Dereference
CVE-2024-37890
CWE-476 Medium
No
No
1.22.22-5.el9, 1.22.22-5.fc39, 1.22.22-5.fc40, 1.22.22-5.fc41 15.07.2024 SB2024071508
SB2024071933
SB2024081608
and 32 more
#VU92406 - Incorrect Regular Expression
CVE-2024-4067
CWE-185 Medium
No
No
1.22.22-2.fc40, 1.22.22-5.el9 20.06.2024 SB20240620121
SB2024062832
SB2024070501
and 41 more
#VU88532 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-29041
CWE-601 Medium
No
No
1.22.22-5.el9 15.04.2024 SB2024041530
SB2024041532
SB2024042918
and 44 more
#VU82608 - Improper Verification of Cryptographic Signature
CVE-2023-46234
CWE-347 Medium
No
No
1.22.21-2.fc38, 1.22.21-2.fc39, 1.22.22-5.el9 31.10.2023 SB2023103186
SB20231031104
SB2023110166
and 14 more
#VU80323 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2023-26136
CWE-1321 High
No
No
1.22.21-2.fc38, 1.22.21-2.fc39, 1.22.22-5.el9 04.09.2023 SB2023090411
SB2023090423
SB2023090816
and 42 more
#VU78932 - Incorrect Regular Expression
CVE-2022-25883
CWE-185 Medium
No
No
1.22.22-5.el9 03.08.2023 SB2023080361
SB2023080362
SB2023081514
and 73 more


Showing elements 1 - 20 out of 28