← Scan another repo

github.com/ChatGPTNextWeb/NextChat

@ 706a18b95b71

Submitted 8/4/2026, 10:25:54 AM · Status: ok

Risk grade
F
100 / 100
Findings
598
4 critical102 high419 medium35 low38 info0 on CISA KEV0ATT&CK
Showing 598 of 598 findings

Findings

  • Authorization Bypass in Next.js Middleware
    grypeCVE-2025-29927EPSS 99.3%
  • form-data uses unsafe random function in form-data for choosing boundary
    grypeCVE-2025-7783EPSS 1.7%
  • form-data: Unsafe random function in form-data
    Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.
    trivyCVE-2025-7783
  • nextjs: Authorization Bypass in Next.js Middleware
    Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware…
    trivyCVE-2025-29927
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input
    grypeCVE-2026-44728EPSS 0.1%
  • Allocation of Resources Without Limits or Throttling in Axios
    grypeCVE-2026-44488EPSS 0.6%
  • Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
    grypeCVE-2026-42264EPSS 0.7%
  • Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
    grypeCVE-2026-25639EPSS 2.5%
  • Axios is vulnerable to DoS attack through lack of data size check
    grypeCVE-2025-58754EPSS 1.1%
  • axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
    grypeCVE-2025-27152EPSS 0.8%
  • axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
    grypeCVE-2026-44495EPSS 0.5%
  • axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
    grypeCVE-2026-44494EPSS 1.0%
  • Axios: Header Injection via Prototype Pollution
    grypeCVE-2026-42035EPSS 0.4%
  • Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
    grypeCVE-2026-42043EPSS 0.7%
  • Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
    grypeCVE-2026-42033EPSS 0.8%
  • Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
    grypeCVE-2026-44487EPSS 0.7%
  • Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
    grypeCVE-2026-44486EPSS 0.7%
  • Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
    grypeCVE-2026-44496EPSS 0.6%
  • DOMPurify allows tampering by prototype pollution
    grypeCVE-2024-45801EPSS 0.8%
  • DOMpurify has a nesting-based mXSS
    grypeCVE-2024-47875EPSS 1.1%
  • form-data: CRLF injection in form-data via unescaped multipart field names and filenames
    grypeCVE-2026-12143EPSS 0.5%
  • Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
    grypeCVE-2026-59880EPSS 0.4%
  • Immutable is vulnerable to Prototype Pollution
    grypeCVE-2026-29063EPSS 1.0%
  • Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
    grypeCVE-2026-59879EPSS 0.4%
  • lodash vulnerable to Code Injection via `_.template` imports key names
    grypeCVE-2026-4800EPSS 2.6%
  • lodash vulnerable to Code Injection via `_.template` imports key names
    grypeCVE-2026-4800EPSS 2.6%
  • Mio's tokens for named pipes may be delivered after deregistration
    grypeCVE-2024-27308EPSS 0.9%
  • Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
    grypeCVE-2025-66414EPSS 0.5%
  • Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
    grype
  • Next Vulnerable to Denial of Service with Server Components
    grype
  • Next.js authorization bypass vulnerability
    grypeCVE-2024-51479EPSS 4.0%
  • Next.js Cache Poisoning
    grypeCVE-2024-46982EPSS 58.8%
  • Next.js has a Denial of Service with Server Components
    grype
  • Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
    grypeCVE-2026-44573EPSS 0.6%
  • Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
    grype
  • Next.js Vulnerable to Denial of Service with Server Components
    grype
  • Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
    grypeCVE-2026-44578EPSS 38.9%
  • Next.js: Denial of Service in App Router using Server Actions
    grypeCVE-2026-64641EPSS 0.5%
  • Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
    grypeCVE-2026-64645EPSS 1.0%
  • Next.js: Server-Side Request Forgery in Server Actions on custom servers
    grypeCVE-2026-64649EPSS 0.6%
  • Picomatch has a ReDoS vulnerability via extglob quantifiers
    grypeCVE-2026-33671EPSS 0.4%
  • PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
    grypeCVE-2026-45623EPSS 0.5%
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    grype
  • Prototype pollution vulnerability found in Mermaid's bundled version of DOMPurify
    grype
  • React Router vulnerable to XSS via Open Redirects
    grypeCVE-2026-22029EPSS 0.8%
  • rust-openssl has incorrect bounds assertion in aes key wrap
    grypeCVE-2026-41678EPSS 0.3%
  • rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
    grypeCVE-2026-42327EPSS 0.2%
  • rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
    grypeCVE-2026-41676EPSS 0.3%
  • rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
    grypeCVE-2026-41681EPSS 0.4%
  • rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
    grypeCVE-2026-41898EPSS 0.3%
  • SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)
    grypeCVE-2026-29074EPSS 0.6%
  • SVGO removeScripts plugin leaves some executable scripts intact
    grype
  • Uncontrolled resource consumption in braces
    grypeCVE-2024-4068EPSS 1.5%
  • ws: Memory exhaustion DoS from tiny fragments and data chunks
    grypeCVE-2026-48779EPSS 0.8%
  • 'apk add' is missing '--no-cache'
    You should use 'apk add' with '--no-cache' to clean package cached data and reduce image size.
    trivyDockerfile:31
  • @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects
    React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can res…
    trivyCVE-2026-22029
  • axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig
    Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providi…
    trivyCVE-2026-25639
  • axios: Axios DoS via lack of data size check
    Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire …
    trivyCVE-2025-58754
  • axios: Axios: Arbitrary HTTP header injection via prototype pollution
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers into outgoing requests. The vulnerability ex…
    trivyCVE-2026-42035
  • axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
    Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments…
    trivyCVE-2026-44496
  • axios: Axios: Denial of Service due to unenforced request and response size limits
    Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments wh…
    trivyCVE-2026-44488
  • axios: Axios: HTTP Transport Hijacking via Prototype Pollution
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON respo…
    trivyCVE-2026-42033
  • axios: Axios: Information disclosure due to prototype pollution vulnerability
    Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transf…
    trivyCVE-2026-44495
  • axios: Axios: Information disclosure of proxy credentials via HTTP redirects
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorizati…
    trivyCVE-2026-44486
  • axios: Axios: Information disclosure of proxy credentials via redirect flows
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial …
    trivyCVE-2026-44487
  • axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
    Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-…
    trivyCVE-2026-44494
  • axios: Axios: NO_PROXY bypass via crafted URL
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vu…
    trivyCVE-2026-42043
  • axios: Axios: Prototype pollution allows information disclosure and request manipulation
    Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnPropert…
    trivyCVE-2026-42264
  • axios: Possible SSRF and Credential Leakage via Absolute URL in axios Requests
    axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leaka…
    trivyCVE-2025-27152
  • Babel is a compiler for writing next generation JavaScript. From 7.12. ...
    Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed …
    trivyCVE-2026-44728
  • braces: fails to limit the number of characters it can handle
    The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program …
    trivyCVE-2024-4068
  • CVE-2024-27308 affecting package rpm-ostree for versions less than 2024.4-1
    Mio is a Metal I/O library for Rust. When using named pipes on Windows, mio will under some circumstances return invalid tokens that correspond to named pipes that have already been deregistered from the mio registry. The impact of this vulnerability depends on how mio is used. F…
    trivyCVE-2024-27308
  • dompurify: nesting-based mutation XSS vulnerability
    DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
    trivyCVE-2024-47875
  • dompurify: XSS vulnerability via prototype pollution
    DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollut…
    trivyCVE-2024-45801
  • form-data: form-data: Form field override via CRLF injection
    form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line fee…
    trivyCVE-2026-12143
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivyDockerfile:0
  • immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution
    Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8…
    trivyCVE-2026-29063
  • Immutable.js provides many Persistent Immutable data structures. Prior ...
    Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.Set keep keys that share the same 32-bit hash in a HashCollisionNode collision bucket that is scanned linearly, allowing an attacker who controls keys inserted i…
    trivyCVE-2026-59880
  • Immutable.js provides many Persistent Immutable data structures. Prior ...
    Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, ca…
    trivyCVE-2026-59879
  • lodash: lodash: Arbitrary code execution via untrusted input in template imports
    Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…
    trivyCVE-2026-4800
  • lodash: lodash: Arbitrary code execution via untrusted input in template imports
    Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…
    trivyCVE-2026-4800
  • Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
    MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on l…
    trivyCVE-2025-66414
  • Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
    It was discovered that the fix for [CVE-2025-55184](https://github.com/advisories/GHSA-2m3v-v2m8-q956) in React Server Components was incomplete and did not fully mitigate denial-of-service conditions across all payload types. As a result, certain crafted inputs could still trig…
    trivy
  • Next Vulnerable to Denial of Service with Server Components
    A vulnerability affects certain React packages for versions 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, and 19.2.1 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is tracked upstream as [CVE-2025-55184](https://ww…
    trivy
  • next: Next.js: Denial of Service via crafted requests to App Router with Server Actions
    Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processi…
    trivyCVE-2026-64641
  • next: Next.js: Server-Side Request Forgery via malicious host redirection in Server Actions
    Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-S…
    trivyCVE-2026-64649
  • next: Next.js: Server-Side Request Forgery vulnerability
    Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostn…
    trivyCVE-2026-64645
  • Next.js Cache Poisoning
    Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is sent it…
    trivyCVE-2024-46982
  • Next.js has a Denial of Service with Server Components
    A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react…
    trivy
  • Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
    A vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://git…
    trivy
  • Next.js Vulnerable to Denial of Service with Server Components
    A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react…
    trivy
  • next.js: next: authorization bypass in Next.js
    Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root …
    trivyCVE-2024-51479
  • next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n
    Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-l…
    trivyCVE-2026-44573
  • Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests
    Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker ca…
    trivyCVE-2026-44578
  • picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns
    Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when c…
    trivyCVE-2026-33671
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    ## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…
    trivy
  • postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferen…
    trivyCVE-2026-45623
  • Prototype pollution vulnerability found in Mermaid's bundled version of DOMPurify
    The following bundled files within the Mermaid NPM package contain a bundled version of DOMPurify that is vulnerable to https://github.com/cure53/DOMPurify/security/advisories/GHSA-mmhx-hmjr-r674, potentially resulting in an XSS attack. This affects the built: - `dist/mermaid.m…
    trivy
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the use…
    trivyCVE-2026-41898
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the sta…
    trivyCVE-2026-41681
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, …
    trivyCVE-2026-41678
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519,…
    trivyCVE-2026-41676
  • rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificate
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unch…
    trivyCVE-2026-42327
  • SVGO removeScripts plugin leaves some executable scripts intact
    ### Summary SVGO's removeScripts plugin (disabled by default) removes scripts from the SVG, however executable scripts were left intact in some cases. If a consumer relied on this plugin for sanitization and served them to users, these SVGs could open up doors to XSS. ### Detai…
    trivy
  • svgo: SVGO: Denial of Service via XML entity expansion
    SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards again…
    trivyCVE-2026-29074

This report is public.