flawfinder
a program that examines source code looking for security weaknesses
Activity
- Latest release
- 3mo ago
- Total releases
- 16
- Cadence
- ~4 months
- Last 12 months
- 1
Details
- License
- GPL-2.0
- First release
- Sep 03, 2017
| Version | Released | |
|---|---|---|
2.0.20
patch
|
2.0.20
patch
|
|
2.0.19
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.19
patch
|
|
2.0.18
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.18
patch
|
|
2.0.17
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.17
patch
|
|
2.0.16
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.16
patch
|
|
2.0.15
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.15
patch
|
|
2.0.14
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.14
patch
|
|
2.0.11
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.11
patch
|
|
2.0.10
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.10
patch
|
|
2.0.9
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.9
patch
|
|
2.0.8
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.8
patch
|
|
2.0.7
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.7
patch
|
|
2.0.6
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.6
patch
|
|
2.0.5
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.5
patch
|
|
2.0.4
patch
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.4
patch
|
|
2.0.3
initial
1 CVE
CVE-2026-48813
PYSEC-2026-2480
GHSA-4c3c-r6p8-c863
Jul 13, 2026
Flawfinder output manipulation via untrusted filenames and source text
0.0
/ 10
None
Local
Low
None
None
Unchanged
None
None
None
ImpactThis vulnerability is an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection:
It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. The initial filename injection problem was reported by Dan Lenz https://www.linkedin.com/in/dan-lenz/ The other vulnerabilities were found by flawfinder project leader David A. Wheeler, GitHub david-a-wheeler, https://dwheeler.com/ PatchesThis issue has been fully patched in Version 2.0.20 (released 2026-05-16). All users should upgrade to version 2.0.20 or later immediately. If you use Python's package manager, you can upgrade using WorkaroundsThere is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by:
ResourcesSee the flawfinder GitHub Repository: https://github.com/david-a-wheeler/flawfinder Affected versions
2.0.10
2.0.11
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.3
2.0.4
2.0.5
2.0.6
+ 3 more Show less
2.0.7
2.0.8
2.0.9
Fixed in
2.0.20
References Updated Jul 13, 2026 · Source: OSV.dev |
2.0.3
initial
|