Unleash is an enterprise ready feature flag service. It provides different strategies for handling feature flags.
72%
Total Score
100
13
100
40
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-63466 New unleash-server is vulnerable to Improper Encoding or Escaping of Output in versions 0.0.0 - 8.0.3. | 0.0.0 - 8.0.3 | Medium |
CVE-2026-63004 New unleash-server is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 7.5.2, 7.6.0 - 7.6.5 and 8.0.0 - 8.0.2. | 0.0.0 - 7.5.27.6.0 - 7.6.58.0.0 - 8.0.2 | Medium |
CVE-2026-63462 New unleash-server is vulnerable to Uncontrolled Recursion in versions 0.0.0 - 7.5.2, 7.6.0 - 7.6.5 and 8.0.0 - 8.0.2. | 0.0.0 - 7.5.27.6.0 - 7.6.58.0.0 - 8.0.2 | High |
AIKIDO-2025-10721 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. unleash-server is vulnerable to Generation of Error Message Containing Sensitive Information in versions 4.23.0 - 7.2.2. | 4.23.0 - 7.2.2 | Low |
AIKIDO-2025-10374 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. unleash-server is vulnerable to Use of Weak Hash in versions 6.5.0 - 7.0.0. | 6.5.0 - 7.0.0 | Low |
| Dependency | Last Release | Score |
|---|---|---|
ky Version ^1.14.3 | — | — |
pg Version ^8.20.0 | — | — |
ajv Version ^8.20.0 | — | — |
joi Version ^18.1.2 | — | — |
cors Version ^2.8.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant