← Scan another repo

github.com/TabbyML/tabby

@ 21b29048d7bc

Submitted 8/4/2026, 10:28:01 AM · Status: ok

Risk grade
F
100 / 100
Findings
2326
15 critical320 high1027 medium98 low866 info2 on CISA KEV0ATT&CK
Showing 2,326 of 2,326 findings

Findings

  • Authorization Bypass in Next.js Middleware
    grypeCVE-2025-29927EPSS 99.3%
  • Authorization Bypass in Next.js Middleware
    grypeCVE-2025-29927EPSS 99.3%
  • form-data uses unsafe random function in form-data for choosing boundary
    grypeCVE-2025-7783EPSS 1.7%
  • Inefficient Regular Expression Complexity in koa
    grypeCVE-2025-25200EPSS 0.8%
  • lettre has TLS hostname verification disabled when using Boring TLS backend
    grypeCVE-2026-46428EPSS 0.2%
  • node-tar: Decompression/parse DoS via unlimited input
    grypeCVE-2026-59873EPSS 0.4%
  • shell-quote quote() does not escape newlines in object .op values
    grypeCVE-2026-9277EPSS 0.9%
  • Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
    grypeCVE-2025-24964EPSS 0.7%
  • websocket-driver: Message corruption via abuse of protocol length headers
    grypeCVE-2026-54466EPSS 0.3%
  • When Vitest UI server is listening, arbitrary file can be read and executed
    grypeCVE-2026-47429EPSS 1.0%
  • form-data: Unsafe random function in form-data
    Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.
    trivyCVE-2025-7783
  • lettre has TLS hostname verification disabled when using Boring TLS backend
    lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently disables TLS hostname verification for callers using the default (strict) configuration. An on-path attacker prese…
    trivyCVE-2026-46428
  • nextjs: Authorization Bypass in Next.js Middleware
    Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware…
    trivyCVE-2025-29927
  • shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators
    shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line te…
    trivyCVE-2026-9277
  • websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...
    websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sendi…
    trivyCVE-2026-54466
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected jwt: Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data
    Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    gitleaks
  • Detected jwt: Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data
    Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    gitleaks
  • Detected jwt: Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data
    Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    gitleaks
  • @actions/download-artifact has an Arbitrary File Write via artifact extraction
    grype
  • @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input
    grypeCVE-2026-44728EPSS 0.1%
  • @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input
    grypeCVE-2026-44728EPSS 0.1%
  • Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction
    grypeCVE-2026-26960EPSS 0.3%
  • auth0/node-jws Improperly Verifies HMAC Signature
    grypeCVE-2025-65945EPSS 0.2%
  • auth0/node-jws Improperly Verifies HMAC Signature
    grypeCVE-2025-65945EPSS 0.2%
  • Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
    grypeCVE-2026-42264EPSS 0.7%
  • Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
    grypeCVE-2026-25639EPSS 2.5%
  • Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
    grypeCVE-2026-25639EPSS 2.5%
  • Axios is vulnerable to DoS attack through lack of data size check
    grypeCVE-2025-58754EPSS 1.1%
  • axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
    grypeCVE-2025-27152EPSS 0.8%
  • axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
    grypeCVE-2025-27152EPSS 0.8%
  • axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
    grypeCVE-2026-44495EPSS 0.5%
  • axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
    grypeCVE-2026-44495EPSS 0.5%
  • axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
    grypeCVE-2026-44494EPSS 1.0%
  • Axios: Header Injection via Prototype Pollution
    grypeCVE-2026-42035EPSS 0.4%
  • Axios: Header Injection via Prototype Pollution
    grypeCVE-2026-42035EPSS 0.4%
  • Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
    grypeCVE-2026-42043EPSS 0.7%
  • Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
    grypeCVE-2026-42043EPSS 0.7%
  • Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
    grypeCVE-2026-42033EPSS 0.8%
  • Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
    grypeCVE-2026-42033EPSS 0.8%
  • Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
    grypeCVE-2026-44487EPSS 0.7%
  • Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
    grypeCVE-2026-44487EPSS 0.7%
  • Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
    grypeCVE-2026-44486EPSS 0.7%
  • Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
    grypeCVE-2026-44486EPSS 0.7%
  • Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
    grypeCVE-2026-44496EPSS 0.6%
  • Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
    grypeCVE-2026-44496EPSS 0.6%
  • axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
    grypeCVE-2026-44492EPSS 0.9%
  • body-parser vulnerable to denial of service when url encoding is enabled
    grypeCVE-2024-45590EPSS 0.8%
  • brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
    grypeCVE-2026-13149EPSS 0.4%
  • brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
    grypeCVE-2026-13149EPSS 0.4%
  • brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
    grypeCVE-2026-14257EPSS 0.3%
  • brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
    grypeCVE-2026-14257EPSS 0.3%
  • brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
    grypeCVE-2026-69152
  • brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
    grypeCVE-2026-69152
  • Command Injection in lodash
    grypeCVE-2021-23337EPSS 21.3%
  • defu: Prototype pollution via `__proto__` key in defaults argument
    grypeCVE-2026-35209EPSS 0.4%
  • Denial of service in http-proxy-middleware
    grypeCVE-2024-21536EPSS 1.0%
  • dset Prototype Pollution vulnerability
    grypeCVE-2024-21529EPSS 0.8%
  • flatted vulnerable to unbounded recursion DoS in parse() revive phase
    grypeCVE-2026-32141EPSS 0.8%
  • Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
    grypeCVE-2026-33896EPSS 0.4%
  • Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
    grypeCVE-2026-33891EPSS 0.6%
  • Forge has signature forgery in Ed25519 due to missing S > L check
    grypeCVE-2026-33895EPSS 0.5%
  • Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
    grypeCVE-2026-33894EPSS 0.5%
  • form-data: CRLF injection in form-data via unescaped multipart field names and filenames
    grypeCVE-2026-12143EPSS 0.5%
  • glob CLI: Command injection via -c/--cmd executes matches with shell:true
    grypeCVE-2025-64756EPSS 3.1%
  • glob CLI: Command injection via -c/--cmd executes matches with shell:true
    grypeCVE-2025-64756EPSS 3.1%
  • glob CLI: Command injection via -c/--cmd executes matches with shell:true
    grypeCVE-2025-64756EPSS 3.1%
  • image-size Denial of Service via Infinite Loop during Image Processing
    grypeCVE-2025-71319EPSS 0.7%
  • Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
    grypeCVE-2026-59880EPSS 0.4%
  • Immutable is vulnerable to Prototype Pollution
    grypeCVE-2026-29063EPSS 1.0%
  • Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
    grypeCVE-2026-59879EPSS 0.4%
  • Inefficient Regular Expression Complexity in marked
    grypeCVE-2022-21681EPSS 2.7%
  • Inefficient Regular Expression Complexity in marked
    grypeCVE-2022-21681EPSS 2.7%
  • Inefficient Regular Expression Complexity in marked
    grypeCVE-2022-21680EPSS 2.8%
  • Inefficient Regular Expression Complexity in marked
    grypeCVE-2022-21680EPSS 2.8%
  • JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
    grypeCVE-2026-46625EPSS 0.5%
  • js-yaml: YAML merge-key chains can force quadratic CPU consumption
    grypeCVE-2026-59869EPSS 0.4%
  • js-yaml: YAML merge-key chains can force quadratic CPU consumption
    grypeCVE-2026-59869EPSS 0.4%
  • js-yaml: YAML merge-key chains can force quadratic CPU consumption
    grypeCVE-2026-59869EPSS 0.4%
  • Koa has Host Header Injection via ctx.hostname
    grypeCVE-2026-27959EPSS 0.3%
  • launch-editor vulnerable to command injection via the crafted request on Windows
    grypeCVE-2024-52011EPSS 0.5%
  • launch-editor vulnerable to command injection via the crafted request on Windows
    grypeCVE-2024-52011EPSS 0.5%
  • linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
    grypeCVE-2026-59887EPSS 0.3%
  • linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
    grypeCVE-2026-59887EPSS 0.3%
  • LinkifyIt#match scan loop has quadratic algorithmic complexity
    grypeCVE-2026-48801EPSS 0.3%
  • LinkifyIt#match scan loop has quadratic algorithmic complexity
    grypeCVE-2026-48801EPSS 0.3%
  • lodash vulnerable to Code Injection via `_.template` imports key names
    grypeCVE-2026-4800EPSS 2.6%
  • lodash vulnerable to Code Injection via `_.template` imports key names
    grypeCVE-2026-4800EPSS 2.6%
  • lodash vulnerable to Code Injection via `_.template` imports key names
    grypeCVE-2026-4800EPSS 2.6%
  • lz4_flex's decompression can leak information from uninitialized memory or reused output buffer
    grypeCVE-2026-32829EPSS 0.6%
  • minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
    grypeCVE-2026-26996EPSS 0.5%
  • minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
    grypeCVE-2026-26996EPSS 0.5%
  • minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
    grypeCVE-2026-26996EPSS 0.5%
  • minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
    grypeCVE-2026-26996EPSS 0.5%
  • minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
    grypeCVE-2026-26996EPSS 0.5%
  • minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
    grypeCVE-2026-26996EPSS 0.5%
  • minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
    grypeCVE-2026-26996EPSS 0.5%
  • minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
    grypeCVE-2026-26996EPSS 0.5%
  • minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
    grypeCVE-2026-27903EPSS 0.5%
  • minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
    grypeCVE-2026-27903EPSS 0.5%
  • minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
    grypeCVE-2026-27903EPSS 0.5%
  • minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
    grypeCVE-2026-27903EPSS 0.5%
  • minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
    grypeCVE-2026-27903EPSS 0.5%
  • minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
    grypeCVE-2026-27903EPSS 0.5%
  • minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
    grypeCVE-2026-27903EPSS 0.5%
  • minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
    grypeCVE-2026-27903EPSS 0.5%
  • minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
    grypeCVE-2026-27904EPSS 0.5%
  • minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
    grypeCVE-2026-27904EPSS 0.5%
  • minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
    grypeCVE-2026-27904EPSS 0.5%
  • minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
    grypeCVE-2026-27904EPSS 0.5%
  • minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
    grypeCVE-2026-27904EPSS 0.5%
  • minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
    grypeCVE-2026-27904EPSS 0.5%
  • minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
    grypeCVE-2026-27904EPSS 0.5%
  • minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
    grypeCVE-2026-27904EPSS 0.5%
  • Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
    grype
  • Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
    grype
  • Next Vulnerable to Denial of Service with Server Components
    grype
  • Next Vulnerable to Denial of Service with Server Components
    grype
  • Next.js authorization bypass vulnerability
    grypeCVE-2024-51479EPSS 4.0%
  • Next.js authorization bypass vulnerability
    grypeCVE-2024-51479EPSS 4.0%
  • Next.js Cache Poisoning
    grypeCVE-2024-46982EPSS 59.2%
  • Next.js Cache Poisoning
    grypeCVE-2024-46982EPSS 59.2%
  • Next.js has a Denial of Service with Server Components
    grype
  • Next.js has a Denial of Service with Server Components
    grype
  • Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
    grypeCVE-2026-44573EPSS 0.6%
  • Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
    grypeCVE-2026-44573EPSS 0.6%
  • Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
    grype
  • Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
    grype
  • Next.js Server-Side Request Forgery in Server Actions
    grypeCVE-2024-34351EPSS 5.5%
  • Next.js Vulnerable to Denial of Service with Server Components
    grype
  • Next.js Vulnerable to Denial of Service with Server Components
    grype
  • Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
    grypeCVE-2026-44578EPSS 38.9%
  • Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
    grypeCVE-2026-44578EPSS 38.9%
  • Next.js: Denial of Service in App Router using Server Actions
    grypeCVE-2026-64641EPSS 0.6%
  • Next.js: Denial of Service in App Router using Server Actions
    grypeCVE-2026-64641EPSS 0.6%
  • Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
    grypeCVE-2026-64645EPSS 0.8%
  • Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
    grypeCVE-2026-64645EPSS 0.8%
  • Next.js: Server-Side Request Forgery in Server Actions on custom servers
    grypeCVE-2026-64649EPSS 0.4%
  • node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization
    grypeCVE-2025-12816EPSS 0.8%
  • node-forge has ASN.1 Unbounded Recursion
    grypeCVE-2025-66031EPSS 0.4%
  • node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
    grypeCVE-2026-23745EPSS 0.3%
  • node-tar Symlink Path Traversal via Drive-Relative Linkpath
    grypeCVE-2026-31802EPSS 0.3%
  • node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
    grypeCVE-2026-24842EPSS 0.5%
  • node-tar: Negative tar entry size causes infinite loop in archive replace
    grypeCVE-2026-59874EPSS 0.4%
  • oneshot has potential Use After Free when used asynchronously
    grype
  • path-to-regexp contains a ReDoS
    grypeCVE-2024-52798EPSS 0.8%
  • path-to-regexp outputs backtracking regular expressions
    grypeCVE-2024-45296EPSS 0.9%
  • path-to-regexp outputs backtracking regular expressions
    grypeCVE-2024-45296EPSS 0.9%
  • path-to-regexp outputs backtracking regular expressions
    grypeCVE-2024-45296EPSS 0.9%
  • path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters
    grypeCVE-2026-4867EPSS 0.5%
  • Picomatch has a ReDoS vulnerability via extglob quantifiers
    grypeCVE-2026-33671EPSS 0.4%
  • Picomatch has a ReDoS vulnerability via extglob quantifiers
    grypeCVE-2026-33671EPSS 0.4%
  • Playwright downloads and installs browsers without verifying the authenticity of the SSL certificate
    grypeCVE-2025-59288EPSS 0.2%
  • PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
    grypeCVE-2026-45623EPSS 0.5%
  • PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
    grypeCVE-2026-45623EPSS 0.5%
  • PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
    grypeCVE-2026-45623EPSS 0.5%
  • PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
    grypeCVE-2026-45623EPSS 0.5%
  • PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
    grypeCVE-2026-45623EPSS 0.5%
  • PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
    grypeCVE-2026-45623EPSS 0.5%
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    grype
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    grype
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    grype
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    grype
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    grype
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    grype
  • Prototype Pollution in async
    grypeCVE-2021-43138EPSS 3.4%
  • Prototype Pollution via parse() in NodeJS flatted
    grypeCVE-2026-33228EPSS 0.8%
  • Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
    grypeCVE-2026-23950EPSS 0.2%
  • Regular Expression Denial of Service (ReDoS) in cross-spawn
    grypeCVE-2024-21538EPSS 0.9%
  • Regular Expression Denial of Service (ReDoS) in cross-spawn
    grypeCVE-2024-21538EPSS 0.9%
  • Rollup 4 has Arbitrary File Write via Path Traversal
    grypeCVE-2026-27606EPSS 1.4%
  • Rollup 4 has Arbitrary File Write via Path Traversal
    grypeCVE-2026-27606EPSS 1.4%
  • Rollup 4 has Arbitrary File Write via Path Traversal
    grypeCVE-2026-27606EPSS 1.4%
  • rust-openssl has incorrect bounds assertion in aes key wrap
    grypeCVE-2026-41678EPSS 0.3%
  • rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
    grypeCVE-2026-42327EPSS 0.2%
  • rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
    grypeCVE-2026-41676EPSS 0.3%
  • rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
    grypeCVE-2026-41681EPSS 0.4%
  • rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
    grypeCVE-2026-41898EPSS 0.3%
  • rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
    grype
  • Sanitize-html Vulnerable To REDoS Attacks
    grypeCVE-2022-25887EPSS 1.1%
  • semver vulnerable to Regular Expression Denial of Service
    grypeCVE-2022-25883EPSS 2.8%
  • semver vulnerable to Regular Expression Denial of Service
    grypeCVE-2022-25883EPSS 2.8%
  • semver vulnerable to Regular Expression Denial of Service
    grypeCVE-2022-25883EPSS 2.8%
  • semver vulnerable to Regular Expression Denial of Service
    grypeCVE-2022-25883EPSS 2.8%
  • semver vulnerable to Regular Expression Denial of Service
    grypeCVE-2022-25883EPSS 2.8%
  • Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
    grype
  • Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
    grype
  • Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
    grype
  • Server-Side Request Forgery in axios
    grypeCVE-2024-39338EPSS 1.2%
  • shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
    grypeCVE-2026-13311EPSS 0.4%
  • socket.io allows an unbounded number of binary attachments
    grypeCVE-2026-33151EPSS 0.5%
  • Socket.IO: Engine.IO Polling Transport Connection Exhaustion
    grypeCVE-2026-59725EPSS 0.4%
  • Socket.IO: Zero-attachment Memory Exhaustion
    grypeCVE-2026-69185
  • SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)
    grypeCVE-2026-29074EPSS 0.6%
  • SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)
    grypeCVE-2026-29074EPSS 0.6%
  • SVGO removeScripts plugin leaves some executable scripts intact
    grype
  • SVGO removeScripts plugin leaves some executable scripts intact
    grype
  • tar has Hardlink Path Traversal via Drive-Relative Linkpath
    grypeCVE-2026-29786EPSS 0.4%
  • tar-fs can extract outside the specified dir with a specific tarball
    grypeCVE-2025-48387EPSS 0.5%
  • tar-fs can extract outside the specified dir with a specific tarball
    grypeCVE-2025-48387EPSS 0.5%
  • tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
    grypeCVE-2025-59343EPSS 0.5%
  • tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
    grypeCVE-2025-59343EPSS 0.5%
  • tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File
    grypeCVE-2024-12905EPSS 2.2%
  • tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File
    grypeCVE-2024-12905EPSS 2.2%
  • tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
    grypeCVE-2026-44705EPSS 0.4%
  • tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
    grypeCVE-2026-44705EPSS 0.4%
  • Uncontrolled resource consumption in braces
    grypeCVE-2024-4068EPSS 1.5%
  • Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
    grypeCVE-2026-27601EPSS 0.9%
  • Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
    grypeCVE-2026-1526EPSS 1.1%
  • Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
    grypeCVE-2026-2229EPSS 0.9%
  • undici WebSocket client vulnerable to denial of service via fragment count bypass
    grypeCVE-2026-12151EPSS 0.8%
  • Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
    grypeCVE-2026-1528EPSS 0.5%
  • vite: `server.fs.deny` bypass on Windows alternate paths
    grypeCVE-2026-53571EPSS 0.6%
  • ws affected by a DoS when handling a request with many HTTP headers
    grypeCVE-2024-37890EPSS 1.4%
  • ws affected by a DoS when handling a request with many HTTP headers
    grypeCVE-2024-37890EPSS 1.4%
  • ws affected by a DoS when handling a request with many HTTP headers
    grypeCVE-2024-37890EPSS 1.4%
  • ws affected by a DoS when handling a request with many HTTP headers
    grypeCVE-2024-37890EPSS 1.4%
  • ws: Memory exhaustion DoS from tiny fragments and data chunks
    grypeCVE-2026-48779EPSS 0.8%
  • ws: Memory exhaustion DoS from tiny fragments and data chunks
    grypeCVE-2026-48779EPSS 0.8%
  • ws: Memory exhaustion DoS from tiny fragments and data chunks
    grypeCVE-2026-48779EPSS 0.8%
  • ws: Memory exhaustion DoS from tiny fragments and data chunks
    grypeCVE-2026-48779EPSS 0.8%
  • Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, a
    Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)
    semgrepee/tabby-webserver/src/service/license.rs:184
  • Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, a
    Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)
    semgrepee/tabby-webserver/src/service/license.rs:183
  • Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, a
    Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)
    semgrepee/tabby-webserver/src/service/license.rs:182
  • os.system() runs a string through the shell — command injection if any part is influenced by input. Use subprocess with an argv list. (Apache-2.0.)
    os.system() runs a string through the shell — command injection if any part is influenced by input. Use subprocess with an argv list. (Apache-2.0.)
    semgrepwebsite/docs/references/cloud-deployment/bentoml/service.py:85
  • os.system() runs a string through the shell — command injection if any part is influenced by input. Use subprocess with an argv list. (Apache-2.0.)
    os.system() runs a string through the shell — command injection if any part is influenced by input. Use subprocess with an argv list. (Apache-2.0.)
    semgrepwebsite/docs/references/cloud-deployment/bentoml/service.py:77
  • async: Prototype Pollution in async
    In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.
    trivyCVE-2021-43138
  • axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig
    Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providi…
    trivyCVE-2026-25639
  • axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig
    Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providi…
    trivyCVE-2026-25639
  • axios: Axios DoS via lack of data size check
    Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire …
    trivyCVE-2025-58754
  • axios: Axios: Arbitrary HTTP header injection via prototype pollution
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers into outgoing requests. The vulnerability ex…
    trivyCVE-2026-42035
  • axios: Axios: Arbitrary HTTP header injection via prototype pollution
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers into outgoing requests. The vulnerability ex…
    trivyCVE-2026-42035
  • axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
    Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments…
    trivyCVE-2026-44496
  • axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
    Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments…
    trivyCVE-2026-44496
  • axios: Axios: HTTP Transport Hijacking via Prototype Pollution
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON respo…
    trivyCVE-2026-42033
  • axios: Axios: HTTP Transport Hijacking via Prototype Pollution
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON respo…
    trivyCVE-2026-42033
  • axios: Axios: Information disclosure due to prototype pollution vulnerability
    Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transf…
    trivyCVE-2026-44495
  • axios: Axios: Information disclosure due to prototype pollution vulnerability
    Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transf…
    trivyCVE-2026-44495
  • axios: Axios: Information disclosure of proxy credentials via HTTP redirects
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorizati…
    trivyCVE-2026-44486
  • axios: Axios: Information disclosure of proxy credentials via HTTP redirects
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorizati…
    trivyCVE-2026-44486
  • axios: Axios: Information disclosure of proxy credentials via redirect flows
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial …
    trivyCVE-2026-44487
  • axios: Axios: Information disclosure of proxy credentials via redirect flows
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial …
    trivyCVE-2026-44487
  • axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
    Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-…
    trivyCVE-2026-44494
  • axios: Axios: NO_PROXY bypass via crafted URL
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vu…
    trivyCVE-2026-42043
  • axios: Axios: NO_PROXY bypass via crafted URL
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vu…
    trivyCVE-2026-42043
  • axios: Axios: Prototype pollution allows information disclosure and request manipulation
    Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnPropert…
    trivyCVE-2026-42264
  • axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
    Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:…
    trivyCVE-2026-44492
  • axios: axios: Server-Side Request Forgery
    axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.
    trivyCVE-2024-39338
  • axios: Possible SSRF and Credential Leakage via Absolute URL in axios Requests
    axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leaka…
    trivyCVE-2025-27152
  • axios: Possible SSRF and Credential Leakage via Absolute URL in axios Requests
    axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leaka…
    trivyCVE-2025-27152
  • Babel is a compiler for writing next generation JavaScript. From 7.12. ...
    Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed …
    trivyCVE-2026-44728
  • Babel is a compiler for writing next generation JavaScript. From 7.12. ...
    Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed …
    trivyCVE-2026-44728
  • body-parser: Denial of Service Vulnerability in body-parser
    body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This is…
    trivyCVE-2024-45590
  • brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
    brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause sign…
    trivyCVE-2026-13149
  • brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function
    brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps…
    trivyCVE-2026-14257
  • brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays
    The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled in…
    trivyCVE-2026-69152
  • braces: fails to limit the number of characters it can handle
    The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program …
    trivyCVE-2024-4068
  • cross-spawn: regular expression denial of service
    Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted …
    trivyCVE-2024-21538
  • form-data: form-data: Form field override via CRLF injection
    form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line fee…
    trivyCVE-2026-12143
  • http-proxy-middleware: Denial of Service
    Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to …
    trivyCVE-2024-21536
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivydocker/Dockerfile.cuda:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivydocker/Dockerfile.rocm:0
  • image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images.
    image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loo…
    trivyCVE-2025-71319
  • js-yaml: js-yaml: Denial of Service via crafted YAML documents
    js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This i…
    trivyCVE-2026-59869
  • js-yaml: js-yaml: Denial of Service via crafted YAML documents
    js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This i…
    trivyCVE-2026-59869
  • js-yaml: js-yaml: Denial of Service via crafted YAML documents
    js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This i…
    trivyCVE-2026-59869
  • launch-editor: vite: launch-editor: Arbitrary command execution via insufficient file argument sanitization
    launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contain…
    trivyCVE-2024-52011
  • linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability
    linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices inp…
    trivyCVE-2026-48801
  • linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
    linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumpt…
    trivyCVE-2026-59887
  • lodash: lodash: Arbitrary code execution via untrusted input in template imports
    Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…
    trivyCVE-2026-4800
  • lodash: lodash: Arbitrary code execution via untrusted input in template imports
    Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…
    trivyCVE-2026-4800
  • lodash: lodash: Arbitrary code execution via untrusted input in template imports
    Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…
    trivyCVE-2026-4800
  • lodash: lodash: Arbitrary code execution via untrusted input in template imports
    Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…
    trivyCVE-2026-4800
  • marked: regular expression block.def may lead Denial of Service
    Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable versi…
    trivyCVE-2022-21680
  • marked: regular expression block.def may lead Denial of Service
    Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable versi…
    trivyCVE-2022-21680
  • marked: regular expression inline.reflinkSearch may lead Denial of Service
    Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings and lead to a denial of service (DoS). Anyone who runs untrusted markdown through a vulnerable version of mark…
    trivyCVE-2022-21681
  • marked: regular expression inline.reflinkSearch may lead Denial of Service
    Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings and lead to a denial of service (DoS). Anyone who runs untrusted markdown through a vulnerable version of mark…
    trivyCVE-2022-21681
  • minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns
    minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-a…
    trivyCVE-2026-27903
  • minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions
    minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), wh…
    trivyCVE-2026-27904
  • minimatch: minimatch: Denial of Service via specially crafted glob patterns
    minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal charact…
    trivyCVE-2026-26996
  • Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
    It was discovered that the fix for [CVE-2025-55184](https://github.com/advisories/GHSA-2m3v-v2m8-q956) in React Server Components was incomplete and did not fully mitigate denial-of-service conditions across all payload types. As a result, certain crafted inputs could still trig…
    trivy
  • Next Vulnerable to Denial of Service with Server Components
    A vulnerability affects certain React packages for versions 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, and 19.2.1 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is tracked upstream as [CVE-2025-55184](https://ww…
    trivy
  • next: Next.js Server-Side Request Forgery in Server Actions
    Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able …
    trivyCVE-2024-34351
  • next: Next.js: Denial of Service via crafted requests to App Router with Server Actions
    Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processi…
    trivyCVE-2026-64641
  • next: Next.js: Server-Side Request Forgery vulnerability
    Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostn…
    trivyCVE-2026-64645
  • Next.js Cache Poisoning
    Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is sent it…
    trivyCVE-2024-46982
  • Next.js has a Denial of Service with Server Components
    A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react…
    trivy
  • Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
    A vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://git…
    trivy
  • Next.js Vulnerable to Denial of Service with Server Components
    A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react…
    trivy
  • next.js: next: authorization bypass in Next.js
    Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root …
    trivyCVE-2024-51479
  • next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n
    Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-l…
    trivyCVE-2026-44573
  • Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests
    Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker ca…
    trivyCVE-2026-44578
  • node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance
    Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints`…
    trivyCVE-2026-33896
  • node-forge: Forge: Authentication bypass via forged Ed25519 cryptographic signatures
    Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L`). A valid signa…
    trivyCVE-2026-33895
  • node-forge: Forge: Signature Forgery via Weak RSASSA PKCS#1 v1.5 Verification
    Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attackers can forge signatures by stuffing “garba…
    trivyCVE-2026-33894
  • node-forge: node-forge ASN.1 Unbounded Recursion
    Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded re…
    trivyCVE-2025-66031
  • node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse()
    Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from …
    trivyCVE-2026-33891
  • node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications
    An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and s…
    trivyCVE-2025-12816
  • nodejs-lodash: command injection via template
    Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
    trivyCVE-2021-23337
  • nodejs-semver: Regular expression denial of service
    Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
    trivyCVE-2022-25883
  • nodejs-semver: Regular expression denial of service
    Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
    trivyCVE-2022-25883
  • nodejs-semver: Regular expression denial of service
    Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
    trivyCVE-2022-25883
  • nodejs-semver: Regular expression denial of service
    Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
    trivyCVE-2022-25883
  • nodejs-semver: Regular expression denial of service
    Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
    trivyCVE-2022-25883
  • nodejs-ws: denial of service when handling a request with many HTTP headers
    ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in ws@8.17.1 (e55e510) and backported to ws@7.5.10 (22c2876), ws@6.2.3 (e…
    trivyCVE-2024-37890
  • nodejs-ws: denial of service when handling a request with many HTTP headers
    ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in ws@8.17.1 (e55e510) and backported to ws@7.5.10 (22c2876), ws@6.2.3 (e…
    trivyCVE-2024-37890
  • path-to-regexp: Backtracking regular expressions cause ReDoS
    path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will…
    trivyCVE-2024-45296
  • path-to-regexp: Backtracking regular expressions cause ReDoS
    path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will…
    trivyCVE-2024-45296
  • path-to-regexp: Backtracking regular expressions cause ReDoS
    path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will…
    trivyCVE-2024-45296
  • path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x
    path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path…
    trivyCVE-2024-52798
  • path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters
    Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in path-to-regexp@0.1.12 only prevents ambigu…
    trivyCVE-2026-4867
  • picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns
    Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when c…
    trivyCVE-2026-33671
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    ## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…
    trivy
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    ## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…
    trivy
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    ## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…
    trivy
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    ## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…
    trivy
  • postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferen…
    trivyCVE-2026-45623
  • postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferen…
    trivyCVE-2026-45623
  • postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferen…
    trivyCVE-2026-45623
  • postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferen…
    trivyCVE-2026-45623
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the use…
    trivyCVE-2026-41898
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the sta…
    trivyCVE-2026-41681
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, …
    trivyCVE-2026-41678
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519,…
    trivyCVE-2026-41676
  • rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificate
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unch…
    trivyCVE-2026-42327
  • rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
    ### Summary `bit_string_flags()` in `src/der.rs` panics with an index-out-of-bounds when given a BIT STRING whose content is exactly `[0x00]` (one byte: zero padding bits, zero data bytes). This is reachable through the public API `BorrowedCertRevocationList::from_der()` via the…
    trivy
  • sanitize-html: insecure global regular expression replacement logic may lead to ReDoS
    The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.
    trivyCVE-2022-25887
  • Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
    ### Impact The serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660. While `RegExp.source` is sanitized, `RegExp.flags` is interpolated directly into the generated output without escaping. A simi…
    trivy
  • shell-quote: shell-quote/parse: shell-quote: Denial of Service due to inefficient input parsing
    shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacke…
    trivyCVE-2026-13311
  • SVGO removeScripts plugin leaves some executable scripts intact
    ### Summary SVGO's removeScripts plugin (disabled by default) removes scripts from the SVG, however executable scripts were left intact in some cases. If a consumer relied on this plugin for sanitization and served them to users, these SVGs could open up doors to XSS. ### Detai…
    trivy
  • svgo: SVGO: Denial of Service via XML entity expansion
    SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards again…
    trivyCVE-2026-29074
  • ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments
    ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume…
    trivyCVE-2026-48779
  • ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments
    ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume…
    trivyCVE-2026-48779

This report is public.