All 5 CVE vulnerabilities found in snappy, with AI-generated Chinese analysis, references, and POCs.
Vendor: KnpLabs
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-46683 | Snappy: SSRF and local file read via the xsl-style-sheet option CWE-918 | - | - | 2026-06-10 |
| CVE-2026-46643 | Snappy: Binary path is never shell-escaped due to an inverted is_executable check CWE-78 | - | - | 2026-06-10 |
| CVE-2024-36124 | iq80 Snappy has an out-of-bounds read when uncompressing data, leading to JVM crash CWE-125 | 5.3 | Medium | 2024-06-03 |
| CVE-2023-41330 | Unsafe deserialization in knplabs/knp-snappy CWE-502 | 9.8 | Critical | 2023-09-06 |
| CVE-2023-28115 | Snappy vulnerable to PHAR deserialization, allowing remote code execution CWE-502 | 9.8 | Critical | 2023-03-17 |
All 5 known CVE vulnerabilities affecting snappy with full Chinese analysis, references, and POCs where available.