github.com/explosion/spaCy
Submitted 8/4/2026, 10:28:01 AM · Status: ok
Risk grade
F
100 / 100
Findings
358
8 critical102 high223 medium24 low1 info0 on CISA KEV0ATT&CK
Showing 358 of 358 findings
Findings
- Authorization Bypass in Next.js MiddlewaregrypeCVE-2025-29927EPSS 99.3%
- Authorization Bypass Through User-Controlled Key in url-parsegrypeCVE-2022-0686EPSS 1.8%
- Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codegrypeCVE-2023-45133EPSS 0.5%
- Cross-realm object access in Webpack 5grypeCVE-2023-28154EPSS 1.4%
- babel: arbitrary code executionBabel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when …trivyCVE-2023-45133
- nextjs: Authorization Bypass in Next.js MiddlewareNext.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware…trivyCVE-2025-29927
- npm-url-parse: Authorization bypass through user-controlled keyAuthorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.trivyCVE-2022-0686
- webpack: avoid cross-realm objectsWebpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.trivyCVE-2023-28154
- Detected aws-access-token: Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platformsIdentified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.gitleaks
- @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious inputgrypeCVE-2026-44728EPSS 0.1%
- brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsgrypeCVE-2026-13149EPSS 0.4%
- brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsgrypeCVE-2026-13149EPSS 0.4%
- brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashgrypeCVE-2026-14257EPSS 0.3%
- brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashgrypeCVE-2026-14257EPSS 0.3%
- brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationgrypeCVE-2026-69152
- brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationgrypeCVE-2026-69152
- DOM Clobbering Gadget found in rollup bundled scripts that leads to XSSgrypeCVE-2024-47068EPSS 0.7%
- flatted vulnerable to unbounded recursion DoS in parse() revive phasegrypeCVE-2026-32141EPSS 0.8%
- http-cache-semantics vulnerable to Regular Expression Denial of ServicegrypeCVE-2022-25881EPSS 1.6%
- Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/SetgrypeCVE-2026-59880EPSS 0.4%
- Immutable is vulnerable to Prototype PollutiongrypeCVE-2026-29063EPSS 1.0%
- Immutable.js `List` 32-bit trie overflow → unrecoverable DoSgrypeCVE-2026-59879EPSS 0.4%
- js-yaml: YAML merge-key chains can force quadratic CPU consumptiongrypeCVE-2026-59869EPSS 0.4%
- lodash vulnerable to Code Injection via `_.template` imports key namesgrypeCVE-2026-4800EPSS 2.6%
- minimatch has a ReDoS via repeated wildcards with non-matching literal in patterngrypeCVE-2026-26996EPSS 0.5%
- minimatch has a ReDoS via repeated wildcards with non-matching literal in patterngrypeCVE-2026-26996EPSS 0.5%
- minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segmentsgrypeCVE-2026-27903EPSS 0.5%
- minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segmentsgrypeCVE-2026-27903EPSS 0.5%
- minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressionsgrypeCVE-2026-27904EPSS 0.5%
- minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressionsgrypeCVE-2026-27904EPSS 0.5%
- Moment.js vulnerable to Inefficient Regular Expression ComplexitygrypeCVE-2022-31129EPSS 4.9%
- Next.js authorization bypass vulnerabilitygrypeCVE-2024-51479EPSS 4.0%
- Next.js has a Denial of Service with Server Componentsgrype
- Next.js has a Middleware / Proxy bypass in Pages Router applications using i18ngrypeCVE-2026-44573EPSS 0.6%
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server Componentsgrype
- Next.js Vulnerable to Denial of Service with Server Componentsgrype
- Next.js: Denial of Service in App Router using Server ActionsgrypeCVE-2026-64641EPSS 0.6%
- Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostnamegrypeCVE-2026-64645EPSS 0.8%
- Path Traversal: 'dir/../../filename' in moment.localegrypeCVE-2022-24785EPSS 5.5%
- Picomatch has a ReDoS vulnerability via extglob quantifiersgrypeCVE-2026-33671EPSS 0.4%
- PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsgrypeCVE-2026-45623EPSS 0.5%
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosuregrype
- Prototype Pollution in JSON5 via Parse MethodgrypeCVE-2022-46175EPSS 9.3%
- Prototype Pollution in JSON5 via Parse MethodgrypeCVE-2022-46175EPSS 9.3%
- Prototype Pollution via parse() in NodeJS flattedgrypeCVE-2026-33228EPSS 0.8%
- Prototype Pollution Vulnerability in parse-git-configgrypeCVE-2025-25975EPSS 0.4%
- Regular Expression Denial of Service (ReDoS) in cross-spawngrypeCVE-2024-21538EPSS 0.9%
- Regular Expression Denial of Service (ReDoS) in cross-spawngrypeCVE-2024-21538EPSS 0.9%
- Rollup 4 has Arbitrary File Write via Path TraversalgrypeCVE-2026-27606EPSS 1.4%
- semver vulnerable to Regular Expression Denial of ServicegrypeCVE-2022-25883EPSS 2.8%
- semver vulnerable to Regular Expression Denial of ServicegrypeCVE-2022-25883EPSS 2.8%
- semver vulnerable to Regular Expression Denial of ServicegrypeCVE-2022-25883EPSS 2.8%
- Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()grype
- Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()grype
- tmp has Path Traversal via unsanitized prefix/postfix that enables directory escapegrypeCVE-2026-44705EPSS 0.4%
- Uncaught Exception in yamlgrypeCVE-2023-2251EPSS 1.1%
- Uncontrolled resource consumption in bracesgrypeCVE-2024-4068EPSS 1.5%
- ws affected by a DoS when handling a request with many HTTP headersgrypeCVE-2024-37890EPSS 1.4%
- ws: Memory exhaustion DoS from tiny fragments and data chunksgrypeCVE-2026-48779EPSS 0.8%
- subprocess invoked through the shell (shell=True) or with a command string that is interpolated/concatenated/.split() instead of a fixed argv list — command injection risk. Pass a literal argv list ansubprocess invoked through the shell (shell=True) or with a command string that is interpolated/concatenated/.split() instead of a fixed argv list — command injection risk. Pass a literal argv list and shell=False. (First-party socbox; Apache-2.0.)semgrepspacy/util.py:1090
- Babel is a compiler for writing next generation JavaScript. From 7.12. ...Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed …trivyCVE-2026-44728
- brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexitybrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause sign…trivyCVE-2026-13149
- brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexitybrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause sign…trivyCVE-2026-13149
- brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() functionbrace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps…trivyCVE-2026-14257
- brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() functionbrace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps…trivyCVE-2026-14257
- brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arraysThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled in…trivyCVE-2026-69152
- brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arraysThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled in…trivyCVE-2026-69152
- braces: fails to limit the number of characters it can handleThe NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program …trivyCVE-2024-4068
- cross-spawn: regular expression denial of serviceVersions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted …trivyCVE-2024-21538
- cross-spawn: regular expression denial of serviceVersions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted …trivyCVE-2024-21538
- flatted: Flatted: Prototype pollution vulnerability allows arbitrary code execution via crafted JSON.flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, a…trivyCVE-2026-33228
- flatted: flatted: Unbounded recursion DoS in parse() revive phaseflatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, caus…trivyCVE-2026-32141
- http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerabilityThis affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.trivyCVE-2022-25881
- immutable-js: Immutable.js: Arbitrary code execution via Prototype PollutionImmutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8…trivyCVE-2026-29063
- Immutable.js provides many Persistent Immutable data structures. Prior ...Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, ca…trivyCVE-2026-59879
- Immutable.js provides many Persistent Immutable data structures. Prior ...Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.Set keep keys that share the same 32-bit hash in a HashCollisionNode collision bucket that is scanned linearly, allowing an attacker who controls keys inserted i…trivyCVE-2026-59880
- js-yaml: js-yaml: Denial of Service via crafted YAML documentsjs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This i…trivyCVE-2026-59869
- json5: Prototype Pollution in JSON5 via Parse MethodJSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 does not restrict parsing of keys named `__proto__`, allowing …trivyCVE-2022-46175
- json5: Prototype Pollution in JSON5 via Parse MethodJSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 does not restrict parsing of keys named `__proto__`, allowing …trivyCVE-2022-46175
- lodash: lodash: Arbitrary code execution via untrusted input in template importsImpact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…trivyCVE-2026-4800
- minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patternsminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-a…trivyCVE-2026-27903
- minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patternsminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-a…trivyCVE-2026-27903
- minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressionsminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), wh…trivyCVE-2026-27904
- minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressionsminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), wh…trivyCVE-2026-27904
- minimatch: minimatch: Denial of Service via specially crafted glob patternsminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal charact…trivyCVE-2026-26996
- minimatch: minimatch: Denial of Service via specially crafted glob patternsminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal charact…trivyCVE-2026-26996
- moment: inefficient parsing algorithm resulting in DoSmoment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried …trivyCVE-2022-31129
- Moment.js: Path traversal in moment.localeMoment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch mom…trivyCVE-2022-24785
- next: Next.js: Denial of Service via crafted requests to App Router with Server ActionsNext.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processi…trivyCVE-2026-64641
- next: Next.js: Server-Side Request Forgery vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostn…trivyCVE-2026-64645
- Next.js has a Denial of Service with Server ComponentsA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react…trivy
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server ComponentsA vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://git…trivy
- Next.js Vulnerable to Denial of Service with Server ComponentsA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react…trivy
- next.js: next: authorization bypass in Next.jsNext.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root …trivyCVE-2024-51479
- next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-l…trivyCVE-2026-44573
- nodejs-semver: Regular expression denial of serviceVersions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.trivyCVE-2022-25883
- nodejs-semver: Regular expression denial of serviceVersions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.trivyCVE-2022-25883
- nodejs-semver: Regular expression denial of serviceVersions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.trivyCVE-2022-25883
- nodejs-ws: denial of service when handling a request with many HTTP headersws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to crash a ws server. The vulnerability was fixed in ws@8.17.1 (e55e510) and backported to ws@7.5.10 (22c2876), ws@6.2.3 (e…trivyCVE-2024-37890
- parse-git-config: Prototype Pollution Vulneralbility in parse-git-configAn issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys functiontrivyCVE-2025-25975
- picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patternsPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when c…trivyCVE-2026-33671
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…trivy
- postcss: PostCSS: Information disclosure and denial of service via crafted CSS inputPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferen…trivyCVE-2026-45623
- rollup: DOM Clobbering Gadget found in rollup bundled scripts that leads to XSSRollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobbering vulnerability when bundling scripts with properties from `import.meta` (e.g., `import.meta.url`) in `cjs`/`umd`/`iife` format. The DOM Clobbering gadget can…trivyCVE-2024-47068
- rollup: Rollup: Remote Code Execution via Path Traversal VulnerabilityRollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine a…trivyCVE-2026-27606
- Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()### Impact The serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660. While `RegExp.source` is sanitized, `RegExp.flags` is interpolated directly into the generated output without escaping. A simi…trivy
- Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()### Impact The serialize-javascript npm package (versions <= 7.0.2) contains a code injection vulnerability. It is an incomplete fix for CVE-2020-7660. While `RegExp.source` is sanitized, `RegExp.flags` is interpolated directly into the generated output without escaping. A simi…trivy
- tmp is a temporary file and directory creator for node.js. Prior to 0. ...tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal vulnerability that allows escaping the intended temporary directory when untrusted data flows into the prefix, postfix, or dir options. By embedding traversal …trivyCVE-2026-44705
- Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5.trivyCVE-2023-2251
- ws: ws: Denial of Service via memory exhaustion from small WebSocket fragmentsws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume…trivyCVE-2026-48779
This report is public.