github.com/jaredpalmer/formik
Submitted 8/4/2026, 10:28:00 AM · Status: ok
Risk grade
F
100 / 100
Findings
494
24 critical102 high337 medium28 low3 info1 on CISA KEV0ATT&CK
Showing 494 of 494 findings
Findings
- Authorization Bypass in Next.js MiddlewaregrypeCVE-2025-29927EPSS 99.3%
- Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codegrypeCVE-2023-45133EPSS 0.5%
- Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codegrypeCVE-2023-45133EPSS 0.5%
- Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious codegrypeCVE-2023-45133EPSS 0.5%
- form-data uses unsafe random function in form-data for choosing boundarygrypeCVE-2025-7783EPSS 1.7%
- form-data uses unsafe random function in form-data for choosing boundarygrypeCVE-2025-7783EPSS 1.7%
- Improper Neutralization of Special Elements used in a Command in Shell-quotegrypeCVE-2021-42740EPSS 4.1%
- json-schema is vulnerable to Prototype PollutiongrypeCVE-2021-3918EPSS 3.6%
- Prototype Pollution in minimistgrypeCVE-2021-44906EPSS 4.6%
- Prototype Pollution in minimistgrypeCVE-2021-44906EPSS 4.6%
- Prototype Pollution in minimistgrypeCVE-2021-44906EPSS 4.6%
- Prototype pollution in Plist before 3.0.5 can cause denial of servicegrypeCVE-2022-22912EPSS 2.5%
- Prototype Pollution in simple-plistgrypeCVE-2022-26260EPSS 1.3%
- Prototype pollution in webpack loader-utilsgrypeCVE-2022-37601EPSS 2.7%
- shell-quote quote() does not escape newlines in object .op valuesgrypeCVE-2026-9277EPSS 0.9%
- shell-quote quote() does not escape newlines in object .op valuesgrypeCVE-2026-9277EPSS 0.9%
- xmldom allows multiple root nodes in a DOMgrypeCVE-2022-39353EPSS 1.2%
- babel: arbitrary code executionBabel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when …trivyCVE-2023-45133
- babel: arbitrary code executionBabel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when …trivyCVE-2023-45133
- form-data: Unsafe random function in form-dataUse of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.trivyCVE-2025-7783
- loader-utils: prototype pollution in function parseQuery in parseQuery.jsPrototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.trivyCVE-2022-37601
- minimist: prototype pollutionMinimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).trivyCVE-2021-44906
- nextjs: Authorization Bypass in Next.js MiddlewareNext.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware…trivyCVE-2025-29927
- nodejs-json-schema: Prototype pollution vulnerabilityjson-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')trivyCVE-2021-3918
- tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs.KEVgrypeCVE-2025-30066EPSS 72.4%
- Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operationsDetected a Generic API Key, potentially exposing access to various services and sensitive operations.gitleaks
- body-parser vulnerable to denial of service when url encoding is enabledgrypeCVE-2024-45590EPSS 0.8%
- body-parser vulnerable to denial of service when url encoding is enabledgrypeCVE-2024-45590EPSS 0.8%
- brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsgrypeCVE-2026-13149EPSS 0.4%
- brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crashgrypeCVE-2026-14257EPSS 0.3%
- brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigationgrypeCVE-2026-69152
- decode-uri-component vulnerable to Denial of Service (DoS)grypeCVE-2022-38900EPSS 24.9%
- DOM Clobbering Gadget found in rollup bundled scripts that leads to XSSgrypeCVE-2024-47068EPSS 0.7%
- flatted vulnerable to unbounded recursion DoS in parse() revive phasegrypeCVE-2026-32141EPSS 0.8%
- flatted vulnerable to unbounded recursion DoS in parse() revive phasegrypeCVE-2026-32141EPSS 0.8%
- form-data: CRLF injection in form-data via unescaped multipart field names and filenamesgrypeCVE-2026-12143EPSS 0.5%
- form-data: CRLF injection in form-data via unescaped multipart field names and filenamesgrypeCVE-2026-12143EPSS 0.5%
- Insecure serialization leading to RCE in serialize-javascriptgrypeCVE-2020-7660EPSS 2.6%
- loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)grypeCVE-2022-37599EPSS 2.1%
- loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) via url variablegrypeCVE-2022-37603EPSS 2.1%
- lodash vulnerable to Code Injection via `_.template` imports key namesgrypeCVE-2026-4800EPSS 2.6%
- minimatch has a ReDoS via repeated wildcards with non-matching literal in patterngrypeCVE-2026-26996EPSS 0.5%
- minimatch has a ReDoS via repeated wildcards with non-matching literal in patterngrypeCVE-2026-26996EPSS 0.5%
- minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segmentsgrypeCVE-2026-27903EPSS 0.5%
- minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segmentsgrypeCVE-2026-27903EPSS 0.5%
- minimatch ReDoS vulnerabilitygrypeCVE-2022-3517EPSS 1.8%
- minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressionsgrypeCVE-2026-27904EPSS 0.5%
- minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressionsgrypeCVE-2026-27904EPSS 0.5%
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-Upgrype
- Next Vulnerable to Denial of Service with Server Componentsgrype
- Next.js authorization bypass vulnerabilitygrypeCVE-2024-51479EPSS 4.0%
- Next.js Denial of Service (DoS) conditiongrypeCVE-2024-39693EPSS 0.5%
- Next.js has a Denial of Service with Server Componentsgrype
- Next.js has a Middleware / Proxy bypass in Pages Router applications using i18ngrypeCVE-2026-44573EPSS 0.6%
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server Componentsgrype
- Next.js Server-Side Request Forgery in Server ActionsgrypeCVE-2024-34351EPSS 5.5%
- Next.js Vulnerable to Denial of Service with Server Componentsgrype
- Next.js Vulnerable to HTTP Request SmugglinggrypeCVE-2024-34350EPSS 1.2%
- Next.js: Denial of Service in App Router using Server ActionsgrypeCVE-2026-64641EPSS 0.6%
- Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostnamegrypeCVE-2026-64645EPSS 0.8%
- path-to-regexp contains a ReDoSgrypeCVE-2024-52798EPSS 0.8%
- path-to-regexp outputs backtracking regular expressionsgrypeCVE-2024-45296EPSS 0.9%
- path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parametersgrypeCVE-2026-4867EPSS 0.5%
- PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsgrypeCVE-2026-45623EPSS 0.5%
- PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsgrypeCVE-2026-45623EPSS 0.5%
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosuregrype
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosuregrype
- Prototype Pollution in asyncgrypeCVE-2021-43138EPSS 3.4%
- Prototype Pollution in JSON5 via Parse MethodgrypeCVE-2022-46175EPSS 9.3%
- Prototype Pollution in JSON5 via Parse MethodgrypeCVE-2022-46175EPSS 9.3%
- Prototype Pollution in mergegrypeCVE-2020-28499EPSS 1.4%
- Prototype Pollution in y18ngrypeCVE-2020-7774EPSS 69.1%
- Prototype Pollution in y18ngrypeCVE-2020-7774EPSS 69.1%
- Prototype Pollution via parse() in NodeJS flattedgrypeCVE-2026-33228EPSS 0.8%
- Prototype Pollution via parse() in NodeJS flattedgrypeCVE-2026-33228EPSS 0.8%
- qs vulnerable to Prototype PollutiongrypeCVE-2022-24999EPSS 14.7%
- Regular Expression Denial of Service (ReDoS) in ua-parser-jsgrypeCVE-2021-27292EPSS 3.4%
- Regular Expression Denial of Service in Acorngrype
- Regular Expression Denial of Service in Acorngrype
- Regular expression denial of service in react-nativegrypeCVE-2020-1920EPSS 1.4%
- Regular Expression Denial of Service in trimgrypeCVE-2020-7753EPSS 3.8%
- Rollup 4 has Arbitrary File Write via Path TraversalgrypeCVE-2026-27606EPSS 1.4%
- Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()grype
- shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)grypeCVE-2026-13311EPSS 0.4%
- shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)grypeCVE-2026-13311EPSS 0.4%
- Terser insecure use of regular expressions leads to ReDoSgrypeCVE-2022-25858EPSS 3.0%
- tmp has Path Traversal via unsanitized prefix/postfix that enables directory escapegrypeCVE-2026-44705EPSS 0.4%
- tmpl vulnerable to Inefficient Regular Expression Complexity which may lead to resource exhaustiongrypeCVE-2021-3777EPSS 1.3%
- ua-parser-js Regular Expression Denial of Service vulnerabilitygrypeCVE-2020-7793EPSS 3.9%
- ws affected by a DoS when handling a request with many HTTP headersgrypeCVE-2024-37890EPSS 1.4%
- ws affected by a DoS when handling a request with many HTTP headersgrypeCVE-2024-37890EPSS 1.4%
- ws: Memory exhaustion DoS from tiny fragments and data chunksgrypeCVE-2026-48779EPSS 0.8%
- ws: Memory exhaustion DoS from tiny fragments and data chunksgrypeCVE-2026-48779EPSS 0.8%
- ws: Memory exhaustion DoS from tiny fragments and data chunksgrypeCVE-2026-48779EPSS 0.8%
- xmldom has XML injection through unvalidated DocumentType serializationgrypeCVE-2026-41674EPSS 0.5%
- xmldom has XML node injection through unvalidated comment serializationgrypeCVE-2026-41672EPSS 0.4%
- xmldom has XML node injection through unvalidated processing instruction serializationgrypeCVE-2026-41675EPSS 0.4%
- xmldom: Uncontrolled recursion in XML serialization leads to DoSgrypeCVE-2026-41673EPSS 0.6%
- xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertiongrypeCVE-2026-34601EPSS 0.5%
- express: "qs" prototype poisoning causes the hang of the node processqs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payloa…trivyCVE-2022-24999
- form-data: form-data: Form field override via CRLF injectionform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line fee…trivyCVE-2026-12143
- js-yaml: js-yaml: Denial of Service via crafted YAML documentsjs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This i…trivyCVE-2026-59869
- json5: Prototype Pollution in JSON5 via Parse MethodJSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 does not restrict parsing of keys named `__proto__`, allowing …trivyCVE-2022-46175
- json5: Prototype Pollution in JSON5 via Parse MethodJSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 does not restrict parsing of keys named `__proto__`, allowing …trivyCVE-2022-46175
- loader-utils: Regular expression denial of serviceA Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.trivyCVE-2022-37603
- loader-utils: regular expression denial of service in interpolateName.jsA Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.trivyCVE-2022-37599
- lodash: lodash: Arbitrary code execution via untrusted input in template importsImpact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…trivyCVE-2026-4800
- lodash: lodash: Arbitrary code execution via untrusted input in template importsImpact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…trivyCVE-2026-4800
- lodash: lodash: Arbitrary code execution via untrusted input in template importsImpact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an a…trivyCVE-2026-4800
- Next has a Denial of Service with Server Components - Incomplete Fix Follow-UpIt was discovered that the fix for [CVE-2025-55184](https://github.com/advisories/GHSA-2m3v-v2m8-q956) in React Server Components was incomplete and did not fully mitigate denial-of-service conditions across all payload types. As a result, certain crafted inputs could still trig…trivy
- Next Vulnerable to Denial of Service with Server ComponentsA vulnerability affects certain React packages for versions 19.0.0, 19.0.1, 19.1.0, 19.1.1, 19.1.2, 19.2.0, and 19.2.1 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is tracked upstream as [CVE-2025-55184](https://ww…trivy
- next: Next.js Server-Side Request Forgery in Server ActionsNext.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able …trivyCVE-2024-34351
- next: Next.js: Denial of Service via crafted requests to App Router with Server ActionsNext.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processi…trivyCVE-2026-64641
- next: Next.js: Server-Side Request Forgery vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostn…trivyCVE-2026-64645
- Next.js Denial of Service (DoS) conditionNext.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can trigger a crash, affecting the availability of the server. his vulnerability was resolved in Next.js 13.5 and later.trivyCVE-2024-39693
- Next.js has a Denial of Service with Server ComponentsA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react…trivy
- Next.js HTTP request deserialization can lead to DoS when using insecure React Server ComponentsA vulnerability affects certain React Server Components packages for versions 19.0.x, 19.1.x, and 19.2.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23864](https://git…trivy
- Next.js Vulnerable to Denial of Service with Server ComponentsA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react…trivy
- Next.js Vulnerable to HTTP Request SmugglingNext.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchro…trivyCVE-2024-34350
- next.js: next: authorization bypass in Next.jsNext.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root …trivyCVE-2024-51479
- next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-l…trivyCVE-2026-44573
- nodejs-lodash: command injection via templateLodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.trivyCVE-2021-23337
- nodejs-semver: Regular expression denial of serviceVersions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.trivyCVE-2022-25883
- nodejs-trim: Regular Expression Denial of Service (ReDoS) in trim functionAll versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().trivyCVE-2020-7753
- PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure## Vulnerability Details **File**: `lib/previous-map.js` **Line**: 87-98 (`loadFile`), 129-144 (`loadMap`) ### Root Cause PostCSS auto-detects a `/*# sourceMappingURL=... */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`…trivy
- postcss: PostCSS: Information disclosure and denial of service via crafted CSS inputPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferen…trivyCVE-2026-45623
This report is public.