github.com/hoppscotch/hoppscotch
Submitted 8/4/2026, 10:25:55 AM · Status: ok
Risk grade
F
100 / 100
Findings
936
2 critical96 high550 medium61 low227 info2 on CISA KEV0ATT&CK
Showing 936 of 936 findings
Findings
- shell-quote quote() does not escape newlines in object .op valuesgrypeCVE-2026-9277EPSS 0.9%
- shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminatorsshell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line te…trivyCVE-2026-9277
- Detected aws-access-token: Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platformsIdentified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.gitleaks
- Detected aws-access-token: Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platformsIdentified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- Detected jwt: Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user dataUncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.gitleaks
- Detected jwt: Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user dataUncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.gitleaks
- Detected jwt: Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user dataUncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.gitleaks
- Detected jwt: Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user dataUncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.gitleaks
- Detected private-key: Identified a Private Key, which may compromise cryptographic security and sensitive data encryptionIdentified a Private Key, which may compromise cryptographic security and sensitive data encryption.gitleaks
- Detected stripe-access-token: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial dataFound a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.gitleaks
- @actions/download-artifact has an Arbitrary File Write via artifact extractiongrype
- @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious inputgrypeCVE-2026-44728EPSS 0.1%
- glob CLI: Command injection via -c/--cmd executes matches with shell:truegrypeCVE-2025-64756EPSS 3.1%
- Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/SetgrypeCVE-2026-59880EPSS 0.4%
- Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/SetgrypeCVE-2026-59880EPSS 0.4%
- Immutable is vulnerable to Prototype PollutiongrypeCVE-2026-29063EPSS 1.0%
- Immutable.js `List` 32-bit trie overflow → unrecoverable DoSgrypeCVE-2026-59879EPSS 0.4%
- Immutable.js `List` 32-bit trie overflow → unrecoverable DoSgrypeCVE-2026-59879EPSS 0.4%
- js-yaml: YAML merge-key chains can force quadratic CPU consumptiongrypeCVE-2026-59869EPSS 0.4%
- launch-editor vulnerable to command injection via the crafted request on WindowsgrypeCVE-2024-52011EPSS 0.5%
- lodash vulnerable to Code Injection via `_.template` imports key namesgrypeCVE-2026-4800EPSS 2.6%
- Picomatch has a ReDoS vulnerability via extglob quantifiersgrypeCVE-2026-33671EPSS 0.4%
- Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassemblygrype
- rust-openssl has incorrect bounds assertion in aes key wrapgrypeCVE-2026-41678EPSS 0.3%
- rust-openssl has incorrect bounds assertion in aes key wrapgrypeCVE-2026-41678EPSS 0.3%
- rust-openssl has incorrect bounds assertion in aes key wrapgrypeCVE-2026-41678EPSS 0.3%
- rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLsgrypeCVE-2026-42327EPSS 0.2%
- rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLsgrypeCVE-2026-42327EPSS 0.2%
- rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLsgrypeCVE-2026-42327EPSS 0.2%
- rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLsgrypeCVE-2026-42327EPSS 0.2%
- rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1grypeCVE-2026-41676EPSS 0.3%
- rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1grypeCVE-2026-41676EPSS 0.3%
- rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1grypeCVE-2026-41676EPSS 0.3%
- rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length checkgrypeCVE-2026-41681EPSS 0.4%
- rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length checkgrypeCVE-2026-41681EPSS 0.4%
- rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length checkgrypeCVE-2026-41681EPSS 0.4%
- rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peergrypeCVE-2026-41898EPSS 0.3%
- rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peergrypeCVE-2026-41898EPSS 0.3%
- rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peergrypeCVE-2026-41898EPSS 0.3%
- rustls-webpki: Denial of service via panic on malformed CRL BIT STRINGgrype
- rustls-webpki: Denial of service via panic on malformed CRL BIT STRINGgrype
- rustls-webpki: Denial of service via panic on malformed CRL BIT STRINGgrype
- shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)grypeCVE-2026-13311EPSS 0.4%
- socket.io allows an unbounded number of binary attachmentsgrypeCVE-2026-33151EPSS 0.5%
- vite: `server.fs.deny` bypass on Windows alternate pathsgrypeCVE-2026-53571EPSS 0.6%
- vite: `server.fs.deny` bypass on Windows alternate pathsgrypeCVE-2026-53571EPSS 0.6%
- zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File WritegrypeCVE-2025-29787EPSS 0.5%
- Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret stCommitted PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret store / mounted volume instead. (First-party socbox rule; Apache-2.0.)semgreppackages/hoppscotch-common/src/components/http/authorization/JWT.vue:283
- Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret stCommitted PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret store / mounted volume instead. (First-party socbox rule; Apache-2.0.)semgreppackages/hoppscotch-common/src/helpers/auth/types/__tests__/jwt.spec.ts:129
- Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret stCommitted PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret store / mounted volume instead. (First-party socbox rule; Apache-2.0.)semgreppackages/hoppscotch-common/src/helpers/auth/types/__tests__/jwt.spec.ts:147
- Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)semgreppackages/hoppscotch-js-sandbox/src/web/pre-request/worker.ts:14
- Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)semgreppackages/hoppscotch-js-sandbox/src/web/test-runner/worker.ts:24
- Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, aHardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)semgreppackages/hoppscotch-common/src/helpers/auth/types/__tests__/jwt.spec.ts:59
- Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, aHardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)semgreppackages/hoppscotch-common/src/helpers/curl/__tests__/curlparser.spec.js:370
- Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, aHardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)semgreppackages/hoppscotch-common/src/helpers/curl/__tests__/curlparser.spec.js:379
- Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, aHardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)semgreppackages/hoppscotch-common/src/helpers/curl/__tests__/curlparser.spec.js:391
- Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, aHardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)semgreppackages/hoppscotch-common/src/helpers/auth/types/__tests__/jwt.spec.ts:25
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivypackages/hoppscotch-backend/Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivypackages/hoppscotch-selfhost-web/Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivypackages/hoppscotch-sh-admin/Dockerfile:0
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivyprod.Dockerfile:0
- Immutable.js provides many Persistent Immutable data structures. Prior ...Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, ca…trivyCVE-2026-59879
- Immutable.js provides many Persistent Immutable data structures. Prior ...Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.Set keep keys that share the same 32-bit hash in a HashCollisionNode collision bucket that is scanned linearly, allowing an attacker who controls keys inserted i…trivyCVE-2026-59880
- lodash: lodash: Arbitrary code execution via untrusted input in template importsImpact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…trivyCVE-2026-4800
- Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly## Summary The `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to p…trivy
- Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly## Summary The `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to p…trivy
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519,…trivyCVE-2026-41676
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, …trivyCVE-2026-41678
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the sta…trivyCVE-2026-41681
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the use…trivyCVE-2026-41898
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519,…trivyCVE-2026-41676
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, …trivyCVE-2026-41678
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the sta…trivyCVE-2026-41681
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the use…trivyCVE-2026-41898
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519,…trivyCVE-2026-41676
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, …trivyCVE-2026-41678
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the sta…trivyCVE-2026-41681
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the use…trivyCVE-2026-41898
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the use…trivyCVE-2026-41898
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the sta…trivyCVE-2026-41681
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, …trivyCVE-2026-41678
- rust-openssl provides OpenSSL bindings for the Rust programming langua ...rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519,…trivyCVE-2026-41676
- rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificaterust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unch…trivyCVE-2026-42327
- rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificaterust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unch…trivyCVE-2026-42327
- rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificaterust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unch…trivyCVE-2026-42327
- rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificaterust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unch…trivyCVE-2026-42327
- rustls-webpki: Denial of service via panic on malformed CRL BIT STRING### Summary `bit_string_flags()` in `src/der.rs` panics with an index-out-of-bounds when given a BIT STRING whose content is exactly `[0x00]` (one byte: zero padding bits, zero data bytes). This is reachable through the public API `BorrowedCertRevocationList::from_der()` via the…trivy
- rustls-webpki: Denial of service via panic on malformed CRL BIT STRING### Summary `bit_string_flags()` in `src/der.rs` panics with an index-out-of-bounds when given a BIT STRING whose content is exactly `[0x00]` (one byte: zero padding bits, zero data bytes). This is reachable through the public API `BorrowedCertRevocationList::from_der()` via the…trivy
- rustls-webpki: Denial of service via panic on malformed CRL BIT STRING### Summary `bit_string_flags()` in `src/der.rs` panics with an index-out-of-bounds when given a BIT STRING whose content is exactly `[0x00]` (one byte: zero padding bits, zero data bytes). This is reachable through the public API `BorrowedCertRevocationList::from_der()` via the…trivy
- shell-quote: shell-quote/parse: shell-quote: Denial of Service due to inefficient input parsingshell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacke…trivyCVE-2026-13311
- vite: `server.fs.deny` bypass on Windows alternate pathsVite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, includin…trivyCVE-2026-53571
- zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write`zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routine of affected versions of the `zip` crate starting with version 1.3.0 and prior to version 2.3.0, symbolic links earlier in the archive are allowed to be used f…trivyCVE-2025-29787
- zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write`zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routine of affected versions of the `zip` crate starting with version 1.3.0 and prior to version 2.3.0, symbolic links earlier in the archive are allowed to be used f…trivyCVE-2025-29787
This report is public.