← Scan another repo

github.com/jaredpalmer/formik

@ 91475adbf335

Submitted 8/4/2026, 10:28:00 AM · Status: ok

Risk grade
F
100 / 100
Findings
494
24 critical102 high337 medium28 low3 info1 on CISA KEV0ATT&CK
Showing 494 of 494 findings

Findings

  • Authorization Bypass in Next.js Middleware
    grypeCVE-2025-29927EPSS 99.3%
  • Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
    grypeCVE-2023-45133EPSS 0.5%
  • Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
    grypeCVE-2023-45133EPSS 0.5%
  • Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
    grypeCVE-2023-45133EPSS 0.5%
  • form-data uses unsafe random function in form-data for choosing boundary
    grypeCVE-2025-7783EPSS 1.7%
  • form-data uses unsafe random function in form-data for choosing boundary
    grypeCVE-2025-7783EPSS 1.7%
  • Improper Neutralization of Special Elements used in a Command in Shell-quote
    grypeCVE-2021-42740EPSS 4.1%
  • json-schema is vulnerable to Prototype Pollution
    grypeCVE-2021-3918EPSS 3.6%
  • Prototype Pollution in minimist
    grypeCVE-2021-44906EPSS 4.6%
  • Prototype Pollution in minimist
    grypeCVE-2021-44906EPSS 4.6%
  • Prototype Pollution in minimist
    grypeCVE-2021-44906EPSS 4.6%
  • Prototype pollution in Plist before 3.0.5 can cause denial of service
    grypeCVE-2022-22912EPSS 2.5%
  • Prototype Pollution in simple-plist
    grypeCVE-2022-26260EPSS 1.3%
  • Prototype pollution in webpack loader-utils
    grypeCVE-2022-37601EPSS 2.7%
  • shell-quote quote() does not escape newlines in object .op values
    grypeCVE-2026-9277EPSS 0.9%
  • shell-quote quote() does not escape newlines in object .op values
    grypeCVE-2026-9277EPSS 0.9%
  • xmldom allows multiple root nodes in a DOM
    grypeCVE-2022-39353EPSS 1.2%
  • babel: arbitrary code execution
    Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when …
    trivyCVE-2023-45133
  • babel: arbitrary code execution
    Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when …
    trivyCVE-2023-45133
  • form-data: Unsafe random function in form-data
    Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.
    trivyCVE-2025-7783
  • loader-utils: prototype pollution in function parseQuery in parseQuery.js
    Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
    trivyCVE-2022-37601
  • minimist: prototype pollution
    Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
    trivyCVE-2021-44906
  • nextjs: Authorization Bypass in Next.js Middleware
    Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware…
    trivyCVE-2025-29927
  • nodejs-json-schema: Prototype pollution vulnerability
    json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
    trivyCVE-2021-3918
  • tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs.KEV
    grypeCVE-2025-30066EPSS 72.4%
  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • body-parser vulnerable to denial of service when url encoding is enabled
    grypeCVE-2024-45590EPSS 0.8%
  • body-parser vulnerable to denial of service when url encoding is enabled
    grypeCVE-2024-45590EPSS 0.8%
  • brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
    grypeCVE-2026-13149EPSS 0.4%
  • brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
    grypeCVE-2026-14257EPSS 0.3%
  • brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
    grypeCVE-2026-69152
  • decode-uri-component vulnerable to Denial of Service (DoS)
    grypeCVE-2022-38900EPSS 24.9%
  • DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS
    grypeCVE-2024-47068EPSS 0.7%
  • flatted vulnerable to unbounded recursion DoS in parse() revive phase
    grypeCVE-2026-32141EPSS 0.8%
  • flatted vulnerable to unbounded recursion DoS in parse() revive phase
    grypeCVE-2026-32141EPSS 0.8%
  • form-data: CRLF injection in form-data via unescaped multipart field names and filenames
    grypeCVE-2026-12143EPSS 0.5%
  • form-data: CRLF injection in form-data via unescaped multipart field names and filenames
    grypeCVE-2026-12143EPSS 0.5%
  • Insecure serialization leading to RCE in serialize-javascript
    grypeCVE-2020-7660EPSS 2.6%
  • loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)
    grypeCVE-2022-37599EPSS 2.1%
  • loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) via url variable
    grypeCVE-2022-37603EPSS 2.1%
  • lodash vulnerable to Code Injection via `_.template` imports key names
    grypeCVE-2026-4800EPSS 2.6%
  • minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
    grypeCVE-2026-26996EPSS 0.5%
  • minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
    grypeCVE-2026-26996EPSS 0.5%
  • minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
    grypeCVE-2026-27903EPSS 0.5%
  • minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
    grypeCVE-2026-27903EPSS 0.5%
  • minimatch ReDoS vulnerability
    grypeCVE-2022-3517EPSS 1.8%
  • minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
    grypeCVE-2026-27904EPSS 0.5%
  • minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
    grypeCVE-2026-27904EPSS 0.5%
  • Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
    grype
  • Next Vulnerable to Denial of Service with Server Components
    grype
  • Next.js authorization bypass vulnerability
    grypeCVE-2024-51479EPSS 4.0%
  • Next.js Denial of Service (DoS) condition
    grypeCVE-2024-39693EPSS 0.5%
  • Next.js has a Denial of Service with Server Components
    grype
  • Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
    grypeCVE-2026-44573EPSS 0.6%
  • Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
    grype
  • Next.js Server-Side Request Forgery in Server Actions
    grypeCVE-2024-34351EPSS 5.5%
  • Next.js Vulnerable to Denial of Service with Server Components
    grype
  • Next.js Vulnerable to HTTP Request Smuggling
    grypeCVE-2024-34350EPSS 1.2%
  • Next.js: Denial of Service in App Router using Server Actions
    grypeCVE-2026-64641EPSS 0.6%
  • Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
    grypeCVE-2026-64645EPSS 0.8%
  • path-to-regexp contains a ReDoS
    grypeCVE-2024-52798EPSS 0.8%
  • path-to-regexp outputs backtracking regular expressions
    grypeCVE-2024-45296EPSS 0.9%
  • path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters
    grypeCVE-2026-4867EPSS 0.5%
  • PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
    grypeCVE-2026-45623EPSS 0.5%
  • PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
    grypeCVE-2026-45623EPSS 0.5%
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    grype
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    grype
  • Prototype Pollution in async
    grypeCVE-2021-43138EPSS 3.4%
  • Prototype Pollution in JSON5 via Parse Method
    grypeCVE-2022-46175EPSS 9.3%
  • Prototype Pollution in JSON5 via Parse Method
    grypeCVE-2022-46175EPSS 9.3%
  • Prototype Pollution in merge
    grypeCVE-2020-28499EPSS 1.4%
  • Prototype Pollution in y18n
    grypeCVE-2020-7774EPSS 69.1%
  • Prototype Pollution in y18n
    grypeCVE-2020-7774EPSS 69.1%
  • Prototype Pollution via parse() in NodeJS flatted
    grypeCVE-2026-33228EPSS 0.8%
  • Prototype Pollution via parse() in NodeJS flatted
    grypeCVE-2026-33228EPSS 0.8%
  • qs vulnerable to Prototype Pollution
    grypeCVE-2022-24999EPSS 14.7%
  • Regular Expression Denial of Service (ReDoS) in ua-parser-js
    grypeCVE-2021-27292EPSS 3.4%
  • Regular Expression Denial of Service in Acorn
    grype
  • Regular Expression Denial of Service in Acorn
    grype
  • Regular expression denial of service in react-native
    grypeCVE-2020-1920EPSS 1.4%
  • Regular Expression Denial of Service in trim
    grypeCVE-2020-7753EPSS 3.8%
  • Rollup 4 has Arbitrary File Write via Path Traversal
    grypeCVE-2026-27606EPSS 1.4%
  • Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
    grype
  • shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
    grypeCVE-2026-13311EPSS 0.4%
  • shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
    grypeCVE-2026-13311EPSS 0.4%
  • Terser insecure use of regular expressions leads to ReDoS
    grypeCVE-2022-25858EPSS 3.0%
  • tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
    grypeCVE-2026-44705EPSS 0.4%
  • tmpl vulnerable to Inefficient Regular Expression Complexity which may lead to resource exhaustion
    grypeCVE-2021-3777EPSS 1.3%
  • ua-parser-js Regular Expression Denial of Service vulnerability
    grypeCVE-2020-7793EPSS 3.9%
  • ws affected by a DoS when handling a request with many HTTP headers
    grypeCVE-2024-37890EPSS 1.4%
  • ws affected by a DoS when handling a request with many HTTP headers
    grypeCVE-2024-37890EPSS 1.4%
  • ws: Memory exhaustion DoS from tiny fragments and data chunks
    grypeCVE-2026-48779EPSS 0.8%
  • ws: Memory exhaustion DoS from tiny fragments and data chunks
    grypeCVE-2026-48779EPSS 0.8%
  • ws: Memory exhaustion DoS from tiny fragments and data chunks
    grypeCVE-2026-48779EPSS 0.8%
  • xmldom has XML injection through unvalidated DocumentType serialization
    grypeCVE-2026-41674EPSS 0.5%
  • xmldom has XML node injection through unvalidated comment serialization
    grypeCVE-2026-41672EPSS 0.4%
  • xmldom has XML node injection through unvalidated processing instruction serialization
    grypeCVE-2026-41675EPSS 0.4%
  • xmldom: Uncontrolled recursion in XML serialization leads to DoS
    grypeCVE-2026-41673EPSS 0.6%
  • xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
    grypeCVE-2026-34601EPSS 0.5%
  • express: "qs" prototype poisoning causes the hang of the node process
    qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payloa…
    trivyCVE-2022-24999
  • form-data: form-data: Form field override via CRLF injection
    form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line fee…
    trivyCVE-2026-12143
  • js-yaml: js-yaml: Denial of Service via crafted YAML documents
    js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This i…
    trivyCVE-2026-59869
  • json5: Prototype Pollution in JSON5 via Parse Method
    JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 does not restrict parsing of keys named `__proto__`, allowing …
    trivyCVE-2022-46175
  • json5: Prototype Pollution in JSON5 via Parse Method
    JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 does not restrict parsing of keys named `__proto__`, allowing …
    trivyCVE-2022-46175
  • loader-utils: Regular expression denial of service
    A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
    trivyCVE-2022-37603
  • loader-utils: regular expression denial of service in interpolateName.js
    A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
    trivyCVE-2022-37599
  • lodash: lodash: Arbitrary code execution via untrusted input in template imports
    Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…
    trivyCVE-2026-4800
  • lodash: lodash: Arbitrary code execution via untrusted input in template imports
    Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…
    trivyCVE-2026-4800
  • lodash: lodash: Arbitrary code execution via untrusted input in template imports
    Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…
    trivyCVE-2026-4800
  • Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
    It was discovered that the fix for [CVE-2025-55184](https://github.com/advisories/GHSA-2m3v-v2m8-q956) in React Server Components was incomplete and did not fully mitigate denial-of-service conditions across all payload types. As a result, certain crafted inputs could still trig…
    trivy
  • Next Vulnerable to Denial of Service with Server Components
    A vulnerability affects certain React packages for versions 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, and 19.2.1 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is tracked upstream as [CVE-2025-55184](https://ww…
    trivy
  • next: Next.js Server-Side Request Forgery in Server Actions
    Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able …
    trivyCVE-2024-34351
  • next: Next.js: Denial of Service via crafted requests to App Router with Server Actions
    Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processi…
    trivyCVE-2026-64641
  • next: Next.js: Server-Side Request Forgery vulnerability
    Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostn…
    trivyCVE-2026-64645
  • Next.js Denial of Service (DoS) condition
    Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can trigger a crash, affecting the availability of the server. his vulnerability was resolved in Next.js 13.5 and later.
    trivyCVE-2024-39693
  • Next.js has a Denial of Service with Server Components
    A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react…
    trivy
  • Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
    A vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://git…
    trivy
  • Next.js Vulnerable to Denial of Service with Server Components
    A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react…
    trivy
  • Next.js Vulnerable to HTTP Request Smuggling
    Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchro…
    trivyCVE-2024-34350
  • next.js: next: authorization bypass in Next.js
    Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root …
    trivyCVE-2024-51479
  • next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n
    Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-l…
    trivyCVE-2026-44573
  • nodejs-lodash: command injection via template
    Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
    trivyCVE-2021-23337
  • nodejs-semver: Regular expression denial of service
    Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
    trivyCVE-2022-25883
  • nodejs-trim: Regular Expression Denial of Service (ReDoS) in trim function
    All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().
    trivyCVE-2020-7753
  • PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
    ## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…
    trivy
  • postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferen…
    trivyCVE-2026-45623

This report is public.