← Scan another repo

github.com/hoppscotch/hoppscotch

@ 1acb8a3a7581

Submitted 8/4/2026, 10:25:55 AM · Status: ok

Risk grade
F
100 / 100
Findings
936
2 critical96 high550 medium61 low227 info2 on CISA KEV0ATT&CK
Showing 936 of 936 findings

Findings

  • shell-quote quote() does not escape newlines in object .op values
    grypeCVE-2026-9277EPSS 0.9%
  • shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators
    shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line te…
    trivyCVE-2026-9277
  • Detected aws-access-token: Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms
    Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.
    gitleaks
  • Detected aws-access-token: Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms
    Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • Detected jwt: Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data
    Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    gitleaks
  • Detected jwt: Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data
    Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    gitleaks
  • Detected jwt: Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data
    Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    gitleaks
  • Detected jwt: Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data
    Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.
    gitleaks
  • Detected private-key: Identified a Private Key, which may compromise cryptographic security and sensitive data encryption
    Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    gitleaks
  • Detected stripe-access-token: Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data
    Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data.
    gitleaks
  • @actions/download-artifact has an Arbitrary File Write via artifact extraction
    grype
  • @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input
    grypeCVE-2026-44728EPSS 0.1%
  • glob CLI: Command injection via -c/--cmd executes matches with shell:true
    grypeCVE-2025-64756EPSS 3.1%
  • Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
    grypeCVE-2026-59880EPSS 0.4%
  • Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
    grypeCVE-2026-59880EPSS 0.4%
  • Immutable is vulnerable to Prototype Pollution
    grypeCVE-2026-29063EPSS 1.0%
  • Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
    grypeCVE-2026-59879EPSS 0.4%
  • Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
    grypeCVE-2026-59879EPSS 0.4%
  • js-yaml: YAML merge-key chains can force quadratic CPU consumption
    grypeCVE-2026-59869EPSS 0.4%
  • launch-editor vulnerable to command injection via the crafted request on Windows
    grypeCVE-2024-52011EPSS 0.5%
  • lodash vulnerable to Code Injection via `_.template` imports key names
    grypeCVE-2026-4800EPSS 2.6%
  • Picomatch has a ReDoS vulnerability via extglob quantifiers
    grypeCVE-2026-33671EPSS 0.4%
  • Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
    grype
  • rust-openssl has incorrect bounds assertion in aes key wrap
    grypeCVE-2026-41678EPSS 0.3%
  • rust-openssl has incorrect bounds assertion in aes key wrap
    grypeCVE-2026-41678EPSS 0.3%
  • rust-openssl has incorrect bounds assertion in aes key wrap
    grypeCVE-2026-41678EPSS 0.3%
  • rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
    grypeCVE-2026-42327EPSS 0.2%
  • rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
    grypeCVE-2026-42327EPSS 0.2%
  • rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
    grypeCVE-2026-42327EPSS 0.2%
  • rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
    grypeCVE-2026-42327EPSS 0.2%
  • rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
    grypeCVE-2026-41676EPSS 0.3%
  • rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
    grypeCVE-2026-41676EPSS 0.3%
  • rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
    grypeCVE-2026-41676EPSS 0.3%
  • rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
    grypeCVE-2026-41681EPSS 0.4%
  • rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
    grypeCVE-2026-41681EPSS 0.4%
  • rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
    grypeCVE-2026-41681EPSS 0.4%
  • rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
    grypeCVE-2026-41898EPSS 0.3%
  • rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
    grypeCVE-2026-41898EPSS 0.3%
  • rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
    grypeCVE-2026-41898EPSS 0.3%
  • rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
    grype
  • rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
    grype
  • rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
    grype
  • shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
    grypeCVE-2026-13311EPSS 0.4%
  • socket.io allows an unbounded number of binary attachments
    grypeCVE-2026-33151EPSS 0.5%
  • vite: `server.fs.deny` bypass on Windows alternate paths
    grypeCVE-2026-53571EPSS 0.6%
  • vite: `server.fs.deny` bypass on Windows alternate paths
    grypeCVE-2026-53571EPSS 0.6%
  • zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
    grypeCVE-2025-29787EPSS 0.5%
  • Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret st
    Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret store / mounted volume instead. (First-party socbox rule; Apache-2.0.)
    semgreppackages/hoppscotch-common/src/components/http/authorization/JWT.vue:283
  • Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret st
    Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret store / mounted volume instead. (First-party socbox rule; Apache-2.0.)
    semgreppackages/hoppscotch-common/src/helpers/auth/types/__tests__/jwt.spec.ts:129
  • Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret st
    Committed PEM private-key material (a "-----BEGIN ... PRIVATE KEY-----" block). Anyone with repo read access holds the key: rotate it, remove it from history, and load keys at runtime from a secret store / mounted volume instead. (First-party socbox rule; Apache-2.0.)
    semgreppackages/hoppscotch-common/src/helpers/auth/types/__tests__/jwt.spec.ts:147
  • Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)
    Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)
    semgreppackages/hoppscotch-js-sandbox/src/web/pre-request/worker.ts:14
  • Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)
    Dynamic code execution via eval()/new Function() — arbitrary-code-execution risk if any operand is attacker-influenced. Avoid; parse explicitly. (Apache-2.0.)
    semgreppackages/hoppscotch-js-sandbox/src/web/test-runner/worker.ts:24
  • Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, a
    Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)
    semgreppackages/hoppscotch-common/src/helpers/auth/types/__tests__/jwt.spec.ts:59
  • Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, a
    Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)
    semgreppackages/hoppscotch-common/src/helpers/curl/__tests__/curlparser.spec.js:370
  • Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, a
    Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)
    semgreppackages/hoppscotch-common/src/helpers/curl/__tests__/curlparser.spec.js:379
  • Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, a
    Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)
    semgreppackages/hoppscotch-common/src/helpers/curl/__tests__/curlparser.spec.js:391
  • Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, a
    Hardcoded JSON Web Token (a "eyJ...eyJ...sig" literal). A committed JWT is a live bearer credential until it expires — anyone with repo read access can replay it. Remove it, rotate/revoke the token, and inject tokens at runtime. (First-party socbox rule; Apache-2.0.)
    semgreppackages/hoppscotch-common/src/helpers/auth/types/__tests__/jwt.spec.ts:25
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivypackages/hoppscotch-backend/Dockerfile:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivypackages/hoppscotch-selfhost-web/Dockerfile:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivypackages/hoppscotch-sh-admin/Dockerfile:0
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivyprod.Dockerfile:0
  • Immutable.js provides many Persistent Immutable data structures. Prior ...
    Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, ca…
    trivyCVE-2026-59879
  • Immutable.js provides many Persistent Immutable data structures. Prior ...
    Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.Set keep keys that share the same 32-bit hash in a HashCollisionNode collision bucket that is scanned linearly, allowing an attacker who controls keys inserted i…
    trivyCVE-2026-59880
  • lodash: lodash: Arbitrary code execution via untrusted input in template imports
    Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…
    trivyCVE-2026-4800
  • Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
    ## Summary The `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to p…
    trivy
  • Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
    ## Summary The `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to p…
    trivy
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519,…
    trivyCVE-2026-41676
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, …
    trivyCVE-2026-41678
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the sta…
    trivyCVE-2026-41681
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the use…
    trivyCVE-2026-41898
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519,…
    trivyCVE-2026-41676
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, …
    trivyCVE-2026-41678
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the sta…
    trivyCVE-2026-41681
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the use…
    trivyCVE-2026-41898
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519,…
    trivyCVE-2026-41676
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, …
    trivyCVE-2026-41678
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the sta…
    trivyCVE-2026-41681
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the use…
    trivyCVE-2026-41898
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the use…
    trivyCVE-2026-41898
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the sta…
    trivyCVE-2026-41681
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, …
    trivyCVE-2026-41678
  • rust-openssl provides OpenSSL bindings for the Rust programming langua ...
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519,…
    trivyCVE-2026-41676
  • rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificate
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unch…
    trivyCVE-2026-42327
  • rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificate
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unch…
    trivyCVE-2026-42327
  • rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificate
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unch…
    trivyCVE-2026-42327
  • rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificate
    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unch…
    trivyCVE-2026-42327
  • rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
    ### Summary `bit_string_flags()` in `src/der.rs` panics with an index-out-of-bounds when given a BIT STRING whose content is exactly `[0x00]` (one byte: zero padding bits, zero data bytes). This is reachable through the public API `BorrowedCertRevocationList::from_der()` via the…
    trivy
  • rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
    ### Summary `bit_string_flags()` in `src/der.rs` panics with an index-out-of-bounds when given a BIT STRING whose content is exactly `[0x00]` (one byte: zero padding bits, zero data bytes). This is reachable through the public API `BorrowedCertRevocationList::from_der()` via the…
    trivy
  • rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
    ### Summary `bit_string_flags()` in `src/der.rs` panics with an index-out-of-bounds when given a BIT STRING whose content is exactly `[0x00]` (one byte: zero padding bits, zero data bytes). This is reachable through the public API `BorrowedCertRevocationList::from_der()` via the…
    trivy
  • shell-quote: shell-quote/parse: shell-quote: Denial of Service due to inefficient input parsing
    shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacke…
    trivyCVE-2026-13311
  • vite: `server.fs.deny` bypass on Windows alternate paths
    Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, includin…
    trivyCVE-2026-53571
  • zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
    `zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routine of affected versions of the `zip` crate starting with version 1.3.0 and prior to version 2.3.0, symbolic links earlier in the archive are allowed to be used f…
    trivyCVE-2025-29787
  • zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
    `zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routine of affected versions of the `zip` crate starting with version 1.3.0 and prior to version 2.3.0, symbolic links earlier in the archive are allowed to be used f…
    trivyCVE-2025-29787

This report is public.