github.com/floating-ui/floating-ui
Submitted 8/4/2026, 10:28:02 AM · Status: ok
Risk grade
F
100 / 100
Findings
437
8 critical128 high269 medium30 low2 info0 on CISA KEV0ATT&CK
Showing 437 of 437 findings
Findings
- @vitest/browser: Browser Mode provider commands bypass the file-access permission gategrype
- Authorization Bypass in Next.js MiddlewaregrypeCVE-2025-29927EPSS 99.3%
- fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity namesgrypeCVE-2026-25896EPSS 0.5%
- form-data uses unsafe random function in form-data for choosing boundarygrypeCVE-2025-7783EPSS 1.7%
- Handlebars.js has JavaScript Injection via AST Type ConfusiongrypeCVE-2026-33937EPSS 2.3%
- node-tar: Decompression/parse DoS via unlimited inputgrypeCVE-2026-59873EPSS 0.4%
- shell-quote quote() does not escape newlines in object .op valuesgrypeCVE-2026-9277EPSS 0.9%
- nextjs: Authorization Bypass in Next.js MiddlewareNext.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware…trivyCVE-2025-29927
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious inputgrypeCVE-2026-44728EPSS 0.1%
- Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar ExtractiongrypeCVE-2026-26960EPSS 0.3%
- body-parser vulnerable to denial of service when url encoding is enabledgrypeCVE-2024-45590EPSS 0.8%
- brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsgrypeCVE-2026-13149EPSS 0.4%
- brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsgrypeCVE-2026-13149EPSS 0.4%
- brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashgrypeCVE-2026-14257EPSS 0.3%
- brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashgrypeCVE-2026-14257EPSS 0.3%
- brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationgrypeCVE-2026-69152
- brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationgrypeCVE-2026-69152
- defu: Prototype pollution via `__proto__` key in defaults argumentgrypeCVE-2026-35209EPSS 0.4%
- DOM Clobbering Gadget found in rollup bundled scripts that leads to XSSgrypeCVE-2024-47068EPSS 0.7%
- fast-uri vulnerable to host confusion via backslash authority introducergrypeCVE-2026-18446EPSS 0.2%
- fast-uri vulnerable to host confusion via literal backslash authority delimitergrypeCVE-2026-16221EPSS 0.2%
- fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)grypeCVE-2026-26278EPSS 0.8%
- fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)grypeCVE-2026-33036EPSS 0.6%
- flatted vulnerable to unbounded recursion DoS in parse() revive phasegrypeCVE-2026-32141EPSS 0.8%
- form-data: CRLF injection in form-data via unescaped multipart field names and filenamesgrypeCVE-2026-12143EPSS 0.5%
- glob CLI: Command injection via -c/--cmd executes matches with shell:truegrypeCVE-2025-64756EPSS 3.1%
- Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template CompilationgrypeCVE-2026-33939EPSS 0.6%
- Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and OptionsgrypeCVE-2026-33941EPSS 0.3%
- Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-blockgrypeCVE-2026-33938EPSS 0.7%
- Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partialgrypeCVE-2026-33940EPSS 0.7%
- image-size Denial of Service via Infinite Loop during Image ProcessinggrypeCVE-2025-71319EPSS 0.7%
- Inefficient Regular Expression Complexity in nth-checkgrypeCVE-2021-3803EPSS 2.2%
- ip SSRF improper categorization in isPublicgrypeCVE-2024-29415EPSS 8.3%
- js-yaml: YAML merge-key chains can force quadratic CPU consumptiongrypeCVE-2026-59869EPSS 0.4%
- js-yaml: YAML merge-key chains can force quadratic CPU consumptiongrypeCVE-2026-59869EPSS 0.4%
- lodash vulnerable to Code Injection via `_.template` imports key namesgrypeCVE-2026-4800EPSS 2.6%
- minimatch has a ReDoS via repeated wildcards with non-matching literal in patterngrypeCVE-2026-26996EPSS 0.5%
- minimatch has a ReDoS via repeated wildcards with non-matching literal in patterngrypeCVE-2026-26996EPSS 0.5%
- minimatch has a ReDoS via repeated wildcards with non-matching literal in patterngrypeCVE-2026-26996EPSS 0.5%
- minimatch has a ReDoS via repeated wildcards with non-matching literal in patterngrypeCVE-2026-26996EPSS 0.5%
- minimatch has a ReDoS via repeated wildcards with non-matching literal in patterngrypeCVE-2026-26996EPSS 0.5%
- minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segmentsgrypeCVE-2026-27903EPSS 0.5%
- minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segmentsgrypeCVE-2026-27903EPSS 0.5%
- minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segmentsgrypeCVE-2026-27903EPSS 0.5%
- minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segmentsgrypeCVE-2026-27903EPSS 0.5%
- minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segmentsgrypeCVE-2026-27903EPSS 0.5%
- minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressionsgrypeCVE-2026-27904EPSS 0.5%
- minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressionsgrypeCVE-2026-27904EPSS 0.5%
- minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressionsgrypeCVE-2026-27904EPSS 0.5%
- minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressionsgrypeCVE-2026-27904EPSS 0.5%
- minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressionsgrypeCVE-2026-27904EPSS 0.5%
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-Upgrype
- Next Vulnerable to Denial of Service with Server Componentsgrype
- Next.js authorization bypass vulnerabilitygrypeCVE-2024-51479EPSS 4.0%
- Next.js Cache PoisoninggrypeCVE-2024-46982EPSS 59.2%
- Next.js has a Denial of Service with Server Componentsgrype
- Next.js has a Middleware / Proxy bypass in Pages Router applications using i18ngrypeCVE-2026-44573EPSS 0.6%
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server Componentsgrype
- Next.js Server-Side Request Forgery in Server ActionsgrypeCVE-2024-34351EPSS 5.5%
- Next.js Vulnerable to Denial of Service with Server Componentsgrype
- Next.js vulnerable to server-side request forgery in applications using WebSocket upgradesgrypeCVE-2026-44578EPSS 38.9%
- Next.js: Denial of Service in App Router using Server ActionsgrypeCVE-2026-64641EPSS 0.6%
- Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostnamegrypeCVE-2026-64645EPSS 0.8%
- node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path SanitizationgrypeCVE-2026-23745EPSS 0.3%
- node-tar Symlink Path Traversal via Drive-Relative LinkpathgrypeCVE-2026-31802EPSS 0.3%
- node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path TraversalgrypeCVE-2026-24842EPSS 0.5%
- node-tar: Negative tar entry size causes infinite loop in archive replacegrypeCVE-2026-59874EPSS 0.4%
- path-to-regexp contains a ReDoSgrypeCVE-2024-52798EPSS 0.8%
- path-to-regexp outputs backtracking regular expressionsgrypeCVE-2024-45296EPSS 0.9%
- path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parametersgrypeCVE-2026-4867EPSS 0.5%
- Picomatch has a ReDoS vulnerability via extglob quantifiersgrypeCVE-2026-33671EPSS 0.4%
- Playwright downloads and installs browsers without verifying the authenticity of the SSL certificategrypeCVE-2025-59288EPSS 0.2%
- PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsgrypeCVE-2026-45623EPSS 0.5%
- PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsgrypeCVE-2026-45623EPSS 0.5%
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosuregrype
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosuregrype
- Prototype Pollution via parse() in NodeJS flattedgrypeCVE-2026-33228EPSS 0.8%
- Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFSgrypeCVE-2026-23950EPSS 0.2%
- React Router vulnerable to XSS via Open RedirectsgrypeCVE-2026-22029EPSS 0.8%
- Regular Expression Denial of Service (ReDoS) in cross-spawngrypeCVE-2024-21538EPSS 0.9%
- Rollup 4 has Arbitrary File Write via Path TraversalgrypeCVE-2026-27606EPSS 1.4%
- Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()grype
- sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591grype
- shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)grypeCVE-2026-13311EPSS 0.4%
- SVGO removeScripts plugin leaves some executable scripts intactgrype
- tar has Hardlink Path Traversal via Drive-Relative LinkpathgrypeCVE-2026-29786EPSS 0.4%
- tar-fs can extract outside the specified dir with a specific tarballgrypeCVE-2025-48387EPSS 0.5%
- tar-fs can extract outside the specified dir with a specific tarballgrypeCVE-2025-48387EPSS 0.5%
- tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarballgrypeCVE-2025-59343EPSS 0.5%
- tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarballgrypeCVE-2025-59343EPSS 0.5%
- tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar FilegrypeCVE-2024-12905EPSS 2.2%
- tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar FilegrypeCVE-2024-12905EPSS 2.2%
- tmp has Path Traversal via unsanitized prefix/postfix that enables directory escapegrypeCVE-2026-44705EPSS 0.4%
- tmp has Path Traversal via unsanitized prefix/postfix that enables directory escapegrypeCVE-2026-44705EPSS 0.4%
- Uncontrolled resource consumption in bracesgrypeCVE-2024-4068EPSS 1.5%
- Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special ElementsgrypeCVE-2025-12758EPSS 0.5%
- ws affected by a DoS when handling a request with many HTTP headersgrypeCVE-2024-37890EPSS 1.4%
- ws affected by a DoS when handling a request with many HTTP headersgrypeCVE-2024-37890EPSS 1.4%
- ws: Memory exhaustion DoS from tiny fragments and data chunksgrypeCVE-2026-48779EPSS 0.8%
- ws: Memory exhaustion DoS from tiny fragments and data chunksgrypeCVE-2026-48779EPSS 0.8%
- ws: Memory exhaustion DoS from tiny fragments and data chunksgrypeCVE-2026-48779EPSS 0.8%
- brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexitybrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause sign…trivyCVE-2026-13149
- brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() functionbrace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps…trivyCVE-2026-14257
- brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arraysThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled in…trivyCVE-2026-69152
- braces: fails to limit the number of characters it can handleThe NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program …trivyCVE-2024-4068
- fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authorityfast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authorit…trivyCVE-2026-18446
- glob: glob: Command Injection Vulnerability via Malicious FilenamesGlob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, the glob CLI contains a command injection vulnerability in its -c/--cmd option that allows arbitrary command execution when processing files with malicious names.…trivyCVE-2025-64756
- Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https cl…trivyCVE-2026-16221
- minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patternsminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-a…trivyCVE-2026-27903
- minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressionsminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), wh…trivyCVE-2026-27904
- minimatch: minimatch: Denial of Service via specially crafted glob patternsminimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal charact…trivyCVE-2026-26996
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-UpIt was discovered that the fix for [CVE-2025-55184](https://github.com/advisories/GHSA-2m3v-v2m8-q956) in React Server Components was incomplete and did not fully mitigate denial-of-service conditions across all payload types. As a result, certain crafted inputs could still trig…trivy
- Next Vulnerable to Denial of Service with Server ComponentsA vulnerability affects certain React packages for versions 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, and 19.2.1 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is tracked upstream as [CVE-2025-55184](https://ww…trivy
- next: Next.js Server-Side Request Forgery in Server ActionsNext.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able …trivyCVE-2024-34351
- next: Next.js: Denial of Service via crafted requests to App Router with Server ActionsNext.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processi…trivyCVE-2026-64641
- next: Next.js: Server-Side Request Forgery vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostn…trivyCVE-2026-64645
- Next.js Cache PoisoningNext.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is sent it…trivyCVE-2024-46982
- Next.js has a Denial of Service with Server ComponentsA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react…trivy
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server ComponentsA vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://git…trivy
- Next.js Vulnerable to Denial of Service with Server ComponentsA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react…trivy
- next.js: next: authorization bypass in Next.jsNext.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root …trivyCVE-2024-51479
- next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-l…trivyCVE-2026-44573
- Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requestsNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker ca…trivyCVE-2026-44578
- picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patternsPicomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when c…trivyCVE-2026-33671
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…trivy
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…trivy
- postcss: PostCSS: Information disclosure and denial of service via crafted CSS inputPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferen…trivyCVE-2026-45623
- postcss: PostCSS: Information disclosure and denial of service via crafted CSS inputPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferen…trivyCVE-2026-45623
- sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591### Impact A number of vulnerabilities, two rated as "High" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency. Those processing untrusted input with versions of sharp prior to 0.35.0 are affected. ### Patches #### Using prebuilt binaries…trivy
- tar-fs: link following and path traversal via maliciously crafted tar fileAn Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrit…trivyCVE-2024-12905
- tar-fs: link following and path traversal via maliciously crafted tar fileAn Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrit…trivyCVE-2024-12905
- tar-fs: tar-fs has issue where extract can write outside the specified dir with a specific tarballtar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore o…trivyCVE-2025-48387
- tar-fs: tar-fs has issue where extract can write outside the specified dir with a specific tarballtar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore o…trivyCVE-2025-48387
- tar-fs: tar-fs symlink validation bypasstar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A worka…trivyCVE-2025-59343
- tar-fs: tar-fs symlink validation bypasstar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A worka…trivyCVE-2025-59343
This report is public.