$ scanned 37 releases | 2026-10-01 09:35 UTC
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2022-45770 | High | adguard@0.107.79-r0 | arm64 amd64 | Unpatched | Improper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 ... |
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| GHSA-mwwc-3jv2-62j3 | Medium | github.com/AdguardTeam/AdGuardHome@v0.107.79+dirty | arm64 amd64 | 0.108.0-b.16 | AdGuardHome vulnerable to Cross-Site Request Forgery |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| GO-2026-6237 | Unknown | github.com/insomniacslk/dhcp@v0.0.0-20260603135910-a415979eb11e | arm64 amd64 | 0.0.0-20260719225207-c76316d4aa82 | In github.com/insomniacslk/dhcp/dhcpv4/nclient4, BroadcastRawUDPConn.ReadFrom... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2012-4682 | Medium | bitcoin-core@31.1-r0 | arm64 amd64 | Unpatched | Unspecified vulnerability in bitcoind and Bitcoin-Qt allows attackers to caus... |
| CVE-2012-4683 | Medium | bitcoin-core@31.1-r0 | arm64 amd64 | Unpatched | Unspecified vulnerability in bitcoind and Bitcoin-Qt allows attackers to caus... |
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-40200 | High | musl@1.2.6-r4 | arm64 amd64 | Unpatched | An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory... |
| CVE-2026-6042 | Medium | musl@1.2.6-r4 | arm64 amd64 | Unpatched | A security flaw has been discovered in musl libc up to 1.2.6. Affected is the... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-47304 | Critical | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| CVE-2026-47304 | Critical | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| CVE-2026-50648 | High | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| CVE-2026-50648 | High | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| CVE-2026-50525 | High | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| CVE-2026-50525 | High | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| CVE-2026-47302 | High | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| CVE-2026-47302 | High | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| CVE-2026-69304 | Medium | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| CVE-2026-69304 | Medium | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| GHSA-23rf-6693-g89p | Unknown | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| GHSA-8cp2-47hg-mfgh | Unknown | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| GHSA-8q5v-6pqq-x66h | Unknown | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| GHSA-cvvh-rhrc-wg4q | Unknown | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| GHSA-g8r8-53c2-pm3f | Unknown | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| GHSA-23rf-6693-g89p | Unknown | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| GHSA-8cp2-47hg-mfgh | Unknown | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| GHSA-8q5v-6pqq-x66h | Unknown | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| GHSA-cvvh-rhrc-wg4q | Unknown | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 | |
| GHSA-g8r8-53c2-pm3f | Unknown | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.131-r0 |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-87910 | Medium | python-3.14@3.14.7_git20260925-r0 | arm64 amd64 | Unpatched | When tarfile extracts a link on a system that doesn't support links, it ... |
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2025-15367 | Medium | python-3.14@3.14.7_git20260925-r0 | arm64 amd64 | Unpatched | The poplib module, when passed a user-controlled command, can have additional... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-qpgv-g792-wh6x | High | parse_duration@2.1.1 | arm64 amd64 | Unpatched | Uncontrolled Resource Consumption in parse_duration |
| GHSA-2gh3-rmm4-6rq5 | Medium | protobuf@2.28.0 | arm64 amd64 | 3.7.2 | Crash due to uncontrolled recursion in protobuf crate |
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| GHSA-cq8v-f236-94qc | Low | rand@0.8.5 | arm64 amd64 | 0.8.6 | Rand is unsound with a custom logger using rand::rng() |
| GHSA-cq8v-f236-94qc | Low | rand@0.9.2 | arm64 amd64 | 0.9.3 | Rand is unsound with a custom logger using rand::rng() |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-xmrv-pmrh-hhx2 | Medium | github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.6.4 | arm64 amd64 | 1.7.8 | Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder |
| GHSA-xmrv-pmrh-hhx2 | Medium | github.com/aws/aws-sdk-go-v2/service/s3@v1.59.0 | arm64 amd64 | 1.97.3 | Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-23hp-3jrh-7fpw | Critical | tar@7.5.16 | arm64 amd64 | 7.5.19 | node-tar: Decompression/parse DoS via unlimited input |
| GHSA-pfq8-rq6v-vf5m | High | html-minifier@4.0.0 | arm64 amd64 | Unpatched | kangax html-minifier REDoS vulnerability |
| GHSA-8x88-c5mf-7j5w | High | tar@7.5.16 | arm64 amd64 | 7.5.18 | node-tar: Negative tar entry size causes infinite loop in archive replace |
| GHSA-rgw5-rvv9-x895 | High | brace-expansion@1.1.15 | arm64 amd64 | 1.1.18 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-202... |
| GHSA-rgw5-rvv9-x895 | High | brace-expansion@2.1.1 | arm64 amd64 | 2.1.4 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-202... |
| GHSA-mh99-v99m-4gvg | High | brace-expansion@1.1.15 | arm64 amd64 | 1.1.17 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory ... |
| GHSA-mh99-v99m-4gvg | High | brace-expansion@2.1.1 | arm64 amd64 | 2.1.3 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory ... |
| GHSA-4cwx-7wf7-3272 | High | undici@7.28.0 | arm64 amd64 | 7.29.0 | undici vulnerable to cross-user information disclosure and parse-time crash v... |
| GHSA-jmr9-qjv8-65gv | High | extract-zip@2.0.1 | arm64 amd64 | Unpatched | extract-zip unvalidated symlink path traversal |
| GHSA-2883-xcg3-v3hh | High | js-yaml@4.3.0 | arm64 amd64 | 4.3.2 | js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources |
| GHSA-r292-9mhp-454m | High | tar@7.5.16 | arm64 amd64 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable sta... |
| GHSA-3pq3-5fj3-cg6v | High | axios@1.18.1 | arm64 amd64 | 1.20.0 | Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls |
| GHSA-8cf7-32gw-wr33 | High | jsonwebtoken@8.5.1 | arm64 amd64 | 9.0.0 | jsonwebtoken unrestricted key type could lead to legacy keys usage |
| GHSA-535w-7cp7-47q4 | High | multer@2.2.0 | arm64 amd64 | 2.3.0 | multer vulnerable to Denial of Service via oversized array index in field names |
| GHSA-wc9g-mqfw-jrwm | High | multer@2.2.0 | arm64 amd64 | 2.3.0 | multer vulnerable to Denial of Service via crafted multipart field names |
| GHSA-4c8g-83qw-93j6 | High | fast-uri@3.1.2 | arm64 amd64 | 3.1.3 | fast-uri vulnerable to host confusion via failed IDN canonicalization |
| GO-2026-5970 | High | golang.org/x/text@v0.38.0 | arm64 amd64 | 0.39.0 | A norm.Iter can enter an infinite loop when handling input containing invalid... |
| GHSA-5p2g-fcmc-qvqq | High | image-size@1.2.1 | arm64 amd64 | 2.0.3 | image-size: JXL and HEIF parsers allow denial of service through infinite loops |
| GHSA-w3rx-r6r6-pgpr | High | image-size@1.2.1 | arm64 amd64 | 2.0.3 | image-size: ICNS parser allows denial of service through an infinite loop |
| GHSA-mghh-pgcx-3jjj | High | axios@1.18.1 | arm64 amd64 | 1.20.0 | Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via u... |
| GHSA-542g-h47m-68v8 | High | axios@1.18.1 | arm64 amd64 | 1.20.0 | Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 Clie... |
| GHSA-r4gj-5m52-g5wh | High | axios@1.18.1 | arm64 amd64 | 1.20.0 | Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirec... |
| GHSA-c29m-xwm3-cm6r | High | axios@1.18.1 | arm64 amd64 | 1.20.0 | Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) |
| GHSA-rfgv-xxqx-mfg5 | High | undici@6.27.0 | arm64 amd64 | 6.28.1 | undici vulnerable to Denial of Service via unrequested WebSocket subprotocol |
| GHSA-rfgv-xxqx-mfg5 | High | undici@7.28.0 | arm64 amd64 | 7.29.1 | undici vulnerable to Denial of Service via unrequested WebSocket subprotocol |
| GHSA-rfgv-xxqx-mfg5 | High | undici@8.10.0 | arm64 amd64 | 8.10.2 | undici vulnerable to Denial of Service via unrequested WebSocket subprotocol |
| GHSA-x97p-jq2g-jp4f | High | axios@1.18.1 | arm64 amd64 | 1.20.0 | Axios: Prototype Pollution Gadget in axios toFormData Options |
| GHSA-6j4f-fj2g-mc7p | High | brace-expansion@1.1.15 | arm64 amd64 | 1.1.19 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing st... |
| GHSA-qhr7-859c-m2p7 | High | brace-expansion@1.1.15 | arm64 amd64 | 1.1.20 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causin... |
| GHSA-6j4f-fj2g-mc7p | High | brace-expansion@2.1.1 | arm64 amd64 | 2.1.5 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing st... |
| GHSA-qhr7-859c-m2p7 | High | brace-expansion@2.1.1 | arm64 amd64 | 2.1.6 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causin... |
| GHSA-6j4f-fj2g-mc7p | High | brace-expansion@5.0.9 | arm64 amd64 | 5.0.10 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing st... |
| GHSA-qhr7-859c-m2p7 | High | brace-expansion@5.0.9 | arm64 amd64 | 5.0.11 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causin... |
| GHSA-qfvm-cv95-jqjf | High | multer@2.2.0 | arm64 amd64 | 2.3.0 | multer vulnerable to Denial of Service via file descriptor leak on aborted up... |
| GHSA-3jxr-9vmj-r5cp | High | brace-expansion@1.1.15 | arm64 amd64 | 1.1.16 | brace-expansion: DoS via exponential-time expansion of consecutive non-expand... |
| GHSA-3jxr-9vmj-r5cp | High | brace-expansion@2.1.1 | arm64 amd64 | 2.1.2 | brace-expansion: DoS via exponential-time expansion of consecutive non-expand... |
| GHSA-p6gq-j5cr-w38f | High | nodemailer@8.0.11 | arm64 amd64 | 9.0.1 | Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAcc... |
| GHSA-88fw-hqm2-52qc | High | hono@4.12.18 | arm64 amd64 | 4.12.25 | hono: CORS Middleware reflects any Origin with credentials when `origin` defa... |
| GHSA-7pqw-9j4j-h8q3 | High | extract-zip@2.0.1 | arm64 amd64 | Unpatched | extract-zip allows arbitrary file writes through symlink archive entries |
| GHSA-m8m8-qj5v-23w3 | High | axios@1.18.1 | arm64 amd64 | 1.20.0 | Axios: Node HTTP adapter prototype-pollution gadget allows request socket hij... |
| GHSA-v2hh-gcrm-f6hx | High | fast-uri@3.1.2 | arm64 amd64 | 3.1.4 | fast-uri vulnerable to host confusion via literal backslash authority delimiter |
| GHSA-qw65-cvwx-89v3 | High | fast-uri@3.1.2 | arm64 amd64 | 3.1.7 | fast-uri vulnerable to authority injection via an unvalidated port in serialize |
| GHSA-jqff-g426-hqxp | High | fast-uri@3.1.2 | arm64 amd64 | 3.1.6 | fast-uri vulnerable to host confusion via percent-encoded scheme normalization |
| GHSA-7p8r-x3mc-p8w7 | High | fast-uri@3.1.2 | arm64 amd64 | 3.1.5 | fast-uri vulnerable to host confusion via backslash authority introducer |
| GHSA-fph4-wmhf-6fwf | High | fast-uri@3.1.2 | arm64 amd64 | 3.1.6 | fast-uri vulnerable to server-side request forgery via repeated hostname perc... |
| GHSA-f65p-4m7j-42xc | High | fast-uri@3.1.2 | arm64 amd64 | 3.1.6 | fast-uri vulnerable to server-side request forgery via malformed IPv6 normali... |
| GHSA-vp8m-p9jh-q5pm | High | undici@8.10.0 | arm64 amd64 | 8.10.2 | undici vulnerable to cross-origin cache poisoning via missing origin isolatio... |
| GHSA-w293-vg96-wgc3 | High | undici@7.28.0 | arm64 amd64 | 7.29.1 | undici vulnerable to TLS certificate validation bypass via dropped connect op... |
| GHSA-w293-vg96-wgc3 | High | undici@8.10.0 | arm64 amd64 | 8.10.2 | undici vulnerable to TLS certificate validation bypass via dropped connect op... |
| GHSA-5p4m-2wfm-xmqj | High | js-yaml@4.3.0 | arm64 amd64 | 4.3.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2... |
| GHSA-prgh-xp8r-p3m5 | High | nodemailer@10.0.1 | arm64 amd64 | 10.0.5 | Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote... |
| GHSA-v53p-9fqp-m79j | High | nodemailer@10.0.1 | arm64 amd64 | 10.0.6 | Nodemailer: Quadratic backtracking in the addressparser free-text fallback al... |
| GHSA-2x7j-588g-ccc2 | High | nodemailer@8.0.11 | arm64 amd64 | 9.1.0 | Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote ... |
| GHSA-v53p-9fqp-m79j | High | nodemailer@8.0.11 | arm64 amd64 | 10.0.6 | Nodemailer: Quadratic backtracking in the addressparser free-text fallback al... |
| GHSA-rgj7-g3m4-5g8c | High | sharp@0.35.3 | arm64 amd64 | 0.35.4 | sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545 |
| GHSA-hjrf-2m68-5959 | Medium | jsonwebtoken@8.5.1 | arm64 amd64 | 9.0.0 | jsonwebtoken's insecure implementation of key retrieval function could l... |
| GHSA-w8wr-v893-vjvp | Medium | tar@7.5.16 | arm64 amd64 | 7.5.18 | node-tar: Process crash via PAX numeric path type confusion |
| GHSA-4hqw-qxg8-jxx2 | Medium | axios@1.18.1 | arm64 amd64 | 1.20.0 | Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders |
| GHSA-8j4g-w8fx-2239 | Medium | hono@4.12.18 | arm64 amd64 | 4.12.34 | Hono: ReDoS in CORS middleware via Access-Control-Request-Headers |
| GHSA-qwph-4952-7xr6 | Medium | jsonwebtoken@8.5.1 | arm64 amd64 | 9.0.0 | jsonwebtoken vulnerable to signature validation bypass due to insecure defaul... |
| GHSA-3pph-fpjx-jg34 | Medium | multer@2.2.0 | arm64 amd64 | 2.4.0 | multer vulnerable to Denial of Service via orphaned disk writes on aborted up... |
| GHSA-g6gw-c38x-mqfc | Medium | hono@4.12.18 | arm64 amd64 | 4.13.5 | Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaus... |
| GHSA-x5fp-wj9c-mxmx | Medium | qs@6.15.3 | arm64 amd64 | 6.16.0 | qs array-limit bypass via bracket-key comma parsing |
| GHSA-54fx-42gc-7vw4 | Medium | hono@4.12.18 | arm64 amd64 | 4.12.34 | Hono: Algorithmic Complexity DoS in Language Middleware |
| GHSA-gvwx-54wh-qm9j | Medium | tar@7.5.16 | arm64 amd64 | 7.5.17 | node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records |
| GHSA-j8rh-479h-cp32 | Medium | axios@1.18.1 | arm64 amd64 | 1.20.0 | Axios: Header Injection via Inherited headers After Minimal Interceptor |
| GHSA-gqvv-2mrq-wpjv | Medium | hono@4.12.18 | arm64 amd64 | 4.13.5 | Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside... |
| GHSA-9fr6-4gfg-395g | Medium | axios@1.18.1 | arm64 amd64 | 1.20.0 | Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Ob... |
| GHSA-vh66-26gq-q6x8 | Medium | axios@1.18.1 | arm64 amd64 | 1.20.0 | Axios: Prototype pollution gadget in fetch adapter can alter outbound requests |
| GHSA-crvj-82cr-hjcx | Medium | hono@4.12.18 | arm64 amd64 | 4.13.5 | Hono: Query parser reads parameters after the URL fragment, causing cache-key... |
| GHSA-wwfh-h76j-fc44 | Medium | hono@4.12.18 | arm64 amd64 | 4.12.25 | hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) |
| GHSA-727h-3vm5-qwq6 | Medium | mppx@0.6.20 | arm64 amd64 | 0.8.2 | mppx: Gas Draining with padding |
| GHSA-4mjr-xmp4-gh2g | Medium | qs@6.15.3 | arm64 amd64 | 6.16.0 | qs: Denial of Service via Attacker Controlled isBuffer |
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| GHSA-3wwx-pv8p-q78v | Medium | undici@6.27.0 | arm64 amd64 | 6.28.1 | undici vulnerable to Denial of Service via unhandled error in WebSocket perme... |
| GHSA-3wwx-pv8p-q78v | Medium | undici@7.28.0 | arm64 amd64 | 7.29.1 | undici vulnerable to Denial of Service via unhandled error in WebSocket perme... |
| GHSA-3wwx-pv8p-q78v | Medium | undici@8.10.0 | arm64 amd64 | 8.10.2 | undici vulnerable to Denial of Service via unhandled error in WebSocket perme... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| GHSA-3xpg-4rpp-hhhm | Medium | undici@7.28.0 | arm64 amd64 | 7.29.1 | undici vulnerable to Denial of Service via unbounded decompression of compres... |
| GHSA-3xpg-4rpp-hhhm | Medium | undici@8.10.0 | arm64 amd64 | 8.10.2 | undici vulnerable to Denial of Service via unbounded decompression of compres... |
| GHSA-jr45-8vmc-qm54 | Medium | undici@7.28.0 | arm64 amd64 | 7.29.0 | undici vulnerable to cross-user information disclosure via whitespace around ... |
| GHSA-rx4f-c7p8-82vq | Medium | undici@7.28.0 | arm64 amd64 | 7.29.1 | undici vulnerable to Denial of Service via WebSocketStream unclean close |
| GHSA-rx4f-c7p8-82vq | Medium | undici@8.10.0 | arm64 amd64 | 8.10.2 | undici vulnerable to Denial of Service via WebSocketStream unclean close |
| GHSA-pmjh-fq2x-6v4x | Medium | undici@7.28.0 | arm64 amd64 | 7.29.1 | undici vulnerable to Denial of Service via orphaned RetryHandler response body |
| GHSA-pmjh-fq2x-6v4x | Medium | undici@8.10.0 | arm64 amd64 | 8.10.2 | undici vulnerable to Denial of Service via orphaned RetryHandler response body |
| GHSA-4p3w-j4w9-5jqw | Medium | moment@2.30.1 | arm64 amd64 | 2.31.0 | moment vulnerable to Path Traversal via crafted non-string locale name |
| GHSA-vc9j-9wph-qghj | Medium | mppx@0.6.20 | arm64 amd64 | 0.8.2 | mppx: Gas Draining with access list |
| GHSA-w62v-xxxg-mg59 | Medium | hono@4.12.18 | arm64 amd64 | 4.12.27 | Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| GHSA-2jfj-6hjv-fm6j | Medium | undici@7.28.0 | arm64 amd64 | 7.29.1 | undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in s... |
| GHSA-2jfj-6hjv-fm6j | Medium | undici@8.10.0 | arm64 amd64 | 8.10.2 | undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in s... |
| GHSA-hvrm-45r6-mjfj | Medium | hono@4.12.18 | arm64 amd64 | 4.12.27 | hono/jsx does not isolate context per request, leading to cross-request data ... |
| GHSA-2gcr-mfcq-wcc3 | Medium | hono@4.12.18 | arm64 amd64 | 4.12.21 | Hono: app.mount() strips mount prefix using undecoded path, causing incorrect... |
| GHSA-j6c9-x7qj-28xf | Medium | hono@4.12.18 | arm64 amd64 | 4.12.25 | hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value,... |
| GHSA-xrhx-7g5j-rcj5 | Medium | hono@4.12.18 | arm64 amd64 | 4.12.21 | Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 |
| GHSA-q2hr-2g5m-vwhr | Medium | brace-expansion@1.1.15 | arm64 amd64 | 1.1.21 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU ... |
| GHSA-q2hr-2g5m-vwhr | Medium | brace-expansion@2.1.1 | arm64 amd64 | 2.1.7 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU ... |
| GHSA-q2hr-2g5m-vwhr | Medium | brace-expansion@5.0.9 | arm64 amd64 | 5.0.12 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU ... |
| GHSA-f23p-vx2j-j53r | Medium | hono@4.12.18 | arm64 amd64 | 4.12.34 | Hono: `memo()` retains SSR output across requests, leading to cross-user data... |
| GHSA-3hrh-pfw6-9m5x | Medium | hono@4.12.18 | arm64 amd64 | 4.12.21 | Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Coo... |
| GHSA-hrr3-gc8f-f4qj | Medium | fast-uri@3.1.2 | arm64 amd64 | 3.1.8 | fast-uri vulnerable to inconsistent host case normalization via percent-encod... |
| GHSA-f577-qrjj-4474 | Medium | hono@4.12.18 | arm64 amd64 | 4.12.21 | Hono: JWT middleware accepts any Authorization scheme, not only Bearer |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| GHSA-hxh3-vqpv-xpqv | Medium | hono@4.12.18 | arm64 amd64 | 4.13.7 | hono/jsx renders plain strings unescaped in boundary components, leading to XSS |
| GHSA-v3r7-h72x-cjcm | Medium | undici@6.27.0 | arm64 amd64 | 6.28.0 | undici vulnerable to cookie attribute injection via unsanitized domain and un... |
| GHSA-v3r7-h72x-cjcm | Medium | undici@7.28.0 | arm64 amd64 | 7.29.0 | undici vulnerable to cookie attribute injection via unsanitized domain and un... |
| GHSA-m8rv-5g2x-5cg5 | Medium | undici@6.27.0 | arm64 amd64 | 6.28.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property |
| GHSA-m8rv-5g2x-5cg5 | Medium | undici@7.28.0 | arm64 amd64 | 7.29.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property |
| GHSA-xgm2-5f3f-mvvc | Medium | hono@4.12.18 | arm64 amd64 | 4.12.27 | Hono: API Gateway v1 adapter can drop a distinct repeated request header valu... |
| GHSA-wgpf-jwqj-8h8p | Medium | hono@4.12.18 | arm64 amd64 | 4.12.25 | hono: Lambda@Edge adapter keeps only the last value of a repeated request hea... |
| GHSA-8xcm-r25x-g524 | Medium | undici@6.27.0 | arm64 amd64 | 6.28.0 | undici vulnerable to downstream response desynchronization via retry interceptor |
| GHSA-8xcm-r25x-g524 | Medium | undici@7.28.0 | arm64 amd64 | 7.29.0 | undici vulnerable to downstream response desynchronization via retry interceptor |
| GHSA-rv63-4mwf-qqc2 | Medium | hono@4.12.18 | arm64 amd64 | 4.12.25 | hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Co... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| GHSA-44g4-m2mj-wpvx | Medium | axios@1.18.1 | arm64 amd64 | 1.20.0 | Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass... |
| GHSA-984p-xq9m-4rjw | Medium | express-brute@1.0.1 | arm64 amd64 | Unpatched | Rate Limiting Bypass in express-brute |
| GHSA-253c-mchw-3w2r | Medium | markdown-it@14.3.0 | arm64 amd64 | 14.3.1 | markdown-it linkify: true has two quadratic paths, so a few hundred KB of mar... |
| GHSA-6vj9-mwq6-2f5v | Medium | nodemailer@10.0.1 | arm64 amd64 | 10.0.2 | Nodemailer: Process-global DNS cache reuses TLS `servername` across transport... |
| GHSA-8vvx-rff5-p5rq | Medium | nodemailer@10.0.1 | arm64 amd64 | 10.0.2 | Nodemailer: Nested structured recipient arrays bypass the parser depth limit ... |
| GHSA-g57g-f23g-4646 | Medium | nodemailer@10.0.1 | arm64 amd64 | 10.0.9 | Nodemailer: Quoted local-part can produce malformed envelope recipient throug... |
| GHSA-6vj9-mwq6-2f5v | Medium | nodemailer@8.0.11 | arm64 amd64 | 10.0.2 | Nodemailer: Process-global DNS cache reuses TLS `servername` across transport... |
| GHSA-8m3c-c648-2xjj | Medium | nodemailer@8.0.11 | arm64 amd64 | 9.1.1 | Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disa... |
| GHSA-8vvx-rff5-p5rq | Medium | nodemailer@8.0.11 | arm64 amd64 | 10.0.2 | Nodemailer: Nested structured recipient arrays bypass the parser depth limit ... |
| GHSA-cc9r-2j5m-2m83 | Medium | nodemailer@8.0.11 | arm64 amd64 | 9.1.0 | Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsi... |
| GHSA-wmmp-3585-3rmp | Medium | nodemailer@8.0.11 | arm64 amd64 | 9.1.0 | Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to ... |
| GHSA-79qm-7rj5-m7r9 | Low | hono@4.12.18 | arm64 amd64 | 4.12.34 | Hono: Proxy Helper does not remove response headers listed in the `Connection... |
| GHSA-r53p-7pc4-xj5r | Low | undici@6.27.0 | arm64 amd64 | 6.28.1 | undici vulnerable to downstream response splitting via retry interceptor |
| GHSA-r53p-7pc4-xj5r | Low | undici@7.28.0 | arm64 amd64 | 7.29.1 | undici vulnerable to downstream response splitting via retry interceptor |
| GHSA-r53p-7pc4-xj5r | Low | undici@8.10.0 | arm64 amd64 | 8.10.2 | undici vulnerable to downstream response splitting via retry interceptor |
| GHSA-qvfw-j98x-7q72 | Low | multer@2.2.0 | arm64 amd64 | 2.3.0 | multer vulnerable to file size limit bypass via async fileFilter race condition |
| GHSA-2gqq-gqf2-x968 | Low | undici@7.28.0 | arm64 amd64 | 7.29.1 | undici vulnerable to response truncation via oversized chunked responses in t... |
| GHSA-2gqq-gqf2-x968 | Low | undici@8.10.0 | arm64 amd64 | 8.10.2 | undici vulnerable to response truncation via oversized chunked responses in t... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| GHSA-8436-99hf-9mmv | Low | undici@7.28.0 | arm64 amd64 | 7.29.1 | undici vulnerable to caching and replay of unsafe HTTP method responses |
| GHSA-8436-99hf-9mmv | Low | undici@8.10.0 | arm64 amd64 | 8.10.2 | undici vulnerable to caching and replay of unsafe HTTP method responses |
| GHSA-p98j-92pf-mc4p | Low | dompurify@3.4.13 | arm64 amd64 | 3.4.16 | DOMPurify: IN_PLACE: node-removing afterSanitize hook leaves detached subtree... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-g7hc-96xr-gvvx | Medium | MimeKit@4.14.0 | arm64 amd64 | 4.15.1 | MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Inj... |
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| GHSA-9j88-vvj5-vhgr | Medium | MailKit@4.14.0 | arm64 amd64 | 4.16.0 | MailKit has STARTTLS Response Injection via unflushed stream buffer that enab... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-p77j-4mvh-x3m3 | Critical | google.golang.org/grpc@v1.59.0 | arm64 amd64 | 1.79.3 | gRPC-Go has an authorization bypass via missing leading slash in :path |
| GHSA-xgrm-4fwx-7qm8 | Critical | github.com/jackc/pgx/v5@v5.7.4 | arm64 amd64 | 5.9.0 | pgx contains memory-safety vulnerability |
| GHSA-jqcq-xjh3-6g23 | High | github.com/jackc/pgproto3/v2@v2.3.3 | arm64 amd64 | Unpatched | Denial of service in github.com/jackc/pgproto3/v2 |
| GO-2026-6107 | High | go.etcd.io/etcd/client/pkg/v3@v3.5.12 | arm64 amd64 | 3.5.33, 3.6.14, 3.7.1 | In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handsh... |
| GO-2026-5026 | High | golang.org/x/net@v0.39.0 | arm64 amd64 | 0.55.0 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded label... |
| GHSA-2v4p-qf9q-27wj | High | google.golang.org/grpc@v1.59.0 | arm64 amd64 | 1.82.2 | gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:autho... |
| GHSA-4f99-4q7p-p3gh | High | github.com/sirupsen/logrus@v1.9.2 | arm64 amd64 | 1.9.3 | Logrus is vulnerable to DoS when using Entry.Writer() |
| GHSA-vp52-pcj8-j9qc | High | google.golang.org/grpc@v1.59.0 | arm64 amd64 | 1.83.1 | gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation |
| GO-2026-6114 | High | go.etcd.io/etcd/server/v3@v3.5.12 | arm64 amd64 | 3.5.33, 3.6.14, 3.7.1 | In go.etcd.io/etcd/server/v3 before 3.5.33, 3.6.14, and 3.7.1, an authenticat... |
| GHSA-cgrx-mc8f-2prm | High | github.com/opencontainers/runc@v1.1.14 | arm64 amd64 | 1.2.8 | runc container escape and denial of service due to arbitrary write gadgets an... |
| GO-2026-5970 | High | golang.org/x/text@v0.24.0 | arm64 amd64 | 0.39.0 | A norm.Iter can enter an infinite loop when handling input containing invalid... |
| GHSA-hfvc-g4fc-pqhx | High | go.opentelemetry.io/otel/sdk@v1.35.0 | arm64 amd64 | 1.43.0 | opentelemetry-go: BSD kenv command not using absolute path enables PATH hijac... |
| GHSA-9h8m-3fm2-qjrq | High | go.opentelemetry.io/otel/sdk@v1.35.0 | arm64 amd64 | 1.40.0 | OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking |
| GO-2026-4887 | High | github.com/docker/docker@v28.1.1+incompatible | arm64 amd64 | Unpatched | Moby has AuthZ plugin bypass when provided oversized request bodies in github... |
| GHSA-hrxh-6v49-42gf | High | google.golang.org/grpc@v1.59.0 | arm64 amd64 | 1.82.1 | gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities |
| GHSA-pxq6-2prw-chj9 | Medium | github.com/docker/docker@v28.1.1+incompatible | arm64 amd64 | Unpatched | Moby has an Off-by-one error in its plugin privilege validation |
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| GHSA-2464-8j7c-4cjm | Medium | github.com/go-viper/mapstructure/v2@v2.3.0 | arm64 amd64 | 2.4.0 | go-viper's mapstructure May Leak Sensitive Information in Logs When Proc... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| GO-2026-5736 | Medium | go.etcd.io/etcd/server/v3@v3.5.12 | arm64 amd64 | 3.4.44, 3.5.30, 3.6.11 | Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| GHSA-xjvp-4fhw-gc47 | Medium | github.com/opencontainers/runc@v1.1.14 | arm64 amd64 | 1.3.6 | runc: Malicious image with /dev symlink can trigger limited host filesystem i... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| GHSA-w67g-5rqw-f597 | Medium | github.com/gorilla/websocket@v1.5.0 | arm64 amd64 | 1.5.3 | Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key |
| GHSA-j88v-2chj-qfwx | Low | github.com/jackc/pgx/v4@v4.18.3 | arm64 amd64 | Unpatched | pgx: SQL Injection via placeholder confusion with dollar quoted string literals |
| GHSA-j88v-2chj-qfwx | Low | github.com/jackc/pgx/v5@v5.7.4 | arm64 amd64 | 5.9.2 | pgx: SQL Injection via placeholder confusion with dollar quoted string literals |
| GHSA-8wmf-6v46-5gfg | Low | go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.20.0 | arm64 amd64 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| GHSA-8wmf-6v46-5gfg | Low | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.20.0 | arm64 amd64 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| GHSA-8wmf-6v46-5gfg | Low | go.opentelemetry.io/otel/sdk@v1.35.0 | arm64 amd64 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-p293-qw3h-jr36 | Critical | next@16.2.6 | arm64 amd64 | 16.3.3 | Next.js: Unauthenticated Remote Code Execution on windows-hosted servers |
| GHSA-2w6w-674q-4c4q | Critical | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has JavaScript Injection via AST Type Confusion |
| GHSA-23hp-3jrh-7fpw | Critical | tar@6.2.1 | arm64 amd64 | 7.5.19 | node-tar: Decompression/parse DoS via unlimited input |
| GHSA-23hp-3jrh-7fpw | Critical | tar@7.5.13 | arm64 amd64 | 7.5.19 | node-tar: Decompression/parse DoS via unlimited input |
| GHSA-2xp9-vwfh-vxw4 | Critical | next@16.2.6 | arm64 amd64 | 16.3.3 | Next.js: Unauthenticated Remote Code Execution in Image Optimization API when... |
| GHSA-vcvr-r3jv-pc5j | Critical | next@16.2.6 | arm64 amd64 | 16.3.6 | Next.js: Remote Code Execution in next/og ImageResponse |
| GHSA-r5fr-rjxr-66jc | High | lodash-es@4.17.23 | arm64 amd64 | 4.18.0 | lodash vulnerable to Code Injection via `_.template` imports key names |
| GHSA-35jp-ww65-95wh | High | axios@1.15.0 | arm64 amd64 | 1.16.0 | axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in ... |
| GHSA-3g43-6gmg-66jw | High | axios@1.15.0 | arm64 amd64 | 1.15.2 | axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pol... |
| GHSA-qpx9-hpmf-5gmw | High | underscore@1.13.7 | arm64 amd64 | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for ... |
| GHSA-hfxv-24rg-xrqf | High | axios@1.15.0 | arm64 amd64 | 1.16.0 | Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection |
| GHSA-q8qp-cvcw-x6jj | High | axios@1.15.0 | arm64 amd64 | 1.15.2 | Axios has prototype pollution read-side gadgets in HTTP adapter that allow cr... |
| GHSA-777c-7fjr-54vf | High | axios@1.15.0 | arm64 amd64 | 1.16.0 | Allocation of Resources Without Limits or Throttling in Axios |
| GHSA-pf86-5x62-jrwf | High | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, a... |
| GHSA-m99w-x7hq-7vfj | High | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Denial of Service in App Router using Server Actions |
| GHSA-3mfm-83xf-c92r | High | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @p... |
| GHSA-pjwm-pj3p-43mv | High | axios@1.15.0 | arm64 amd64 | 1.16.0 | axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses,... |
| GHSA-xhpv-hc6g-r9c6 | High | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has JavaScript Injection via AST Type Confusion when passing an... |
| GHSA-p92q-9vqr-4j8v | High | axios@1.15.0 | arm64 amd64 | 1.16.0 | Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HT... |
| GHSA-vxpw-j846-p89q | High | undici@6.25.0 | arm64 amd64 | 6.27.0 | undici WebSocket client vulnerable to denial of service via fragment count by... |
| GHSA-vxpw-j846-p89q | High | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici WebSocket client vulnerable to denial of service via fragment count by... |
| GHSA-q3j6-qgpj-74h6 | High | fast-uri@3.1.0 | arm64 amd64 | 3.1.1 | fast-uri vulnerable to path traversal via percent-encoded dot segments |
| GHSA-j5f8-grm9-p9fc | High | axios@1.15.0 | arm64 amd64 | 1.16.0 | Axios: Proxy-Authorization header leaks to redirect target when proxy is re-e... |
| GHSA-9cx6-37pm-9jff | High | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has Denial of Service via Malformed Decorator Syntax in Templat... |
| GHSA-hmw2-7cc7-3qxx | High | form-data@4.0.5 | arm64 amd64 | 4.0.6 | form-data: CRLF injection in form-data via unescaped multipart field names an... |
| GHSA-v39h-62p7-jpjc | High | fast-uri@3.1.0 | arm64 amd64 | 3.1.2 | fast-uri vulnerable to host confusion via percent-encoded authority delimiters |
| GHSA-mwp4-54f8-5fhr | High | ip-address@10.1.0 | arm64 amd64 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers d... |
| GHSA-mwp4-54f8-5fhr | High | ip-address@10.2.0 | arm64 amd64 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers d... |
| GHSA-mwp4-54f8-5fhr | High | ip-address@9.0.5 | arm64 amd64 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers d... |
| GHSA-8x88-c5mf-7j5w | High | tar@6.2.1 | arm64 amd64 | 7.5.18 | node-tar: Negative tar entry size causes infinite loop in archive replace |
| GHSA-8x88-c5mf-7j5w | High | tar@7.5.13 | arm64 amd64 | 7.5.18 | node-tar: Negative tar entry size causes infinite loop in archive replace |
| GHSA-6gpp-xcg3-4w24 | High | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Middleware / Proxy bypass in App Router applications using Turbopack... |
| GHSA-73wf-gq98-2v4g | High | browserslist@4.28.2 | arm64 amd64 | 4.28.7 | Browserslist: Uncaught crash / prototype write via untrusted browserslist-sta... |
| GHSA-c83g-rgw3-j3cx | High | browserslist@4.28.2 | arm64 amd64 | 4.28.7 | Browserslist: Unbounded memory growth (no cache eviction) via distinct query ... |
| GHSA-rgw5-rvv9-x895 | High | brace-expansion@1.1.12 | arm64 amd64 | 1.1.18 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-202... |
| GHSA-rgw5-rvv9-x895 | High | brace-expansion@2.0.2 | arm64 amd64 | 2.1.4 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-202... |
| GHSA-rgw5-rvv9-x895 | High | brace-expansion@5.0.4 | arm64 amd64 | 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-202... |
| GHSA-34x7-hfp2-rc4v | High | tar@6.2.1 | arm64 amd64 | 7.5.7 | node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Tr... |
| GHSA-v245-v573-v5vm | High | linkify-it@5.0.0 | arm64 amd64 | 5.0.2 | linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on... |
| GHSA-mh99-v99m-4gvg | High | brace-expansion@1.1.12 | arm64 amd64 | 1.1.17 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory ... |
| GHSA-mh99-v99m-4gvg | High | brace-expansion@2.0.2 | arm64 amd64 | 2.1.3 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory ... |
| GHSA-mh99-v99m-4gvg | High | brace-expansion@5.0.4 | arm64 amd64 | 5.0.8 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory ... |
| GHSA-6g55-p6wh-862q | High | postcss@8.4.31 | arm64 amd64 | 8.5.12 | PostCSS: Arbitrary file read and information disclosure via attacker-controll... |
| GHSA-7r86-cg39-jmmj | High | minimatch@9.0.5 | arm64 amd64 | 9.0.7 | minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-a... |
| GHSA-52cp-r559-cp3m | High | js-yaml@4.1.1 | arm64 amd64 | 4.3.0 | js-yaml: YAML merge-key chains can force quadratic CPU consumption |
| GHSA-3ppc-4f35-3m26 | High | minimatch@9.0.5 | arm64 amd64 | 9.0.6 | minimatch has a ReDoS via repeated wildcards with non-matching literal in pat... |
| GHSA-2v37-7h3g-55p8 | High | nanoid@3.3.12 | arm64 amd64 | 3.3.18 | nanoid: custom generators can loop indefinitely when size is zero |
| GHSA-pmwg-cvhr-8vh7 | High | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via R... |
| GHSA-4cwx-7wf7-3272 | High | undici@8.1.0 | arm64 amd64 | 8.9.0 | undici vulnerable to cross-user information disclosure and parse-time crash v... |
| GHSA-22p9-wv53-3rq4 | High | linkify-it@5.0.0 | arm64 amd64 | 5.0.1 | LinkifyIt#match scan loop has quadratic algorithmic complexity |
| GHSA-rcmh-qjqh-p98v | High | nodemailer@6.10.0 | arm64 amd64 | 7.0.11 | Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls |
| GHSA-rcmh-qjqh-p98v | High | nodemailer@6.9.16 | arm64 amd64 | 7.0.11 | Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls |
| GHSA-vmh5-mc38-953g | High | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici vulnerable to TLS certificate validation bypass via dropped requestTls... |
| GHSA-w27v-7q3p-w38r | High | svgo@3.3.3 | arm64 amd64 | 3.3.5 | SVGO: removeScripts allows executable links through namespace and control-cha... |
| GHSA-2883-xcg3-v3hh | High | js-yaml@4.1.1 | arm64 amd64 | 4.3.2 | js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources |
| GHSA-r292-9mhp-454m | High | tar@6.2.1 | arm64 amd64 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable sta... |
| GHSA-r292-9mhp-454m | High | tar@7.5.13 | arm64 amd64 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable sta... |
| GHSA-r28c-9q8g-f849 | High | postcss@8.4.31 | arm64 amd64 | 8.5.18 | PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL... |
| GHSA-3pq3-5fj3-cg6v | High | axios@1.15.0 | arm64 amd64 | 1.20.0 | Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls |
| GHSA-23c5-xmqv-rm74 | High | minimatch@9.0.5 | arm64 amd64 | 9.0.7 | minimatch ReDoS: nested *() extglobs generate catastrophically backtracking r... |
| GHSA-38rv-x7px-6hhq | High | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici WebSocket client vulnerable to denial of service via cumulative fragme... |
| GHSA-535w-7cp7-47q4 | High | multer@2.1.1 | arm64 amd64 | 2.3.0 | multer vulnerable to Denial of Service via oversized array index in field names |
| GHSA-wc9g-mqfw-jrwm | High | multer@2.1.1 | arm64 amd64 | 2.3.0 | multer vulnerable to Denial of Service via crafted multipart field names |
| GHSA-72gw-mp4g-v24j | High | multer@2.1.1 | arm64 amd64 | 2.2.0 | Multer vulnerable to Denial of Service via deeply nested field names |
| GHSA-89xv-2m56-2m9x | High | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Server-Side Request Forgery in Server Actions on custom servers |
| GHSA-4c8g-83qw-93j6 | High | fast-uri@3.1.0 | arm64 amd64 | 3.1.3 | fast-uri vulnerable to host confusion via failed IDN canonicalization |
| GHSA-2p49-hgcm-8545 | High | svgo@3.3.3 | arm64 amd64 | 3.3.4 | SVGO removeScripts plugin leaves some executable scripts intact |
| GHSA-p9j2-gv94-2wf4 | High | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Server-Side Request Forgery in rewrites via attacker-controlled dest... |
| GHSA-mghh-pgcx-3jjj | High | axios@1.15.0 | arm64 amd64 | 1.20.0 | Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via u... |
| GHSA-qffp-2rhf-9h96 | High | tar@6.2.1 | arm64 amd64 | 7.5.10 | tar has Hardlink Path Traversal via Drive-Relative Linkpath |
| GHSA-542g-h47m-68v8 | High | axios@1.15.0 | arm64 amd64 | 1.20.0 | Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 Clie... |
| GHSA-8qq5-rm4j-mr97 | High | tar@6.2.1 | arm64 amd64 | 7.5.3 | node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via ... |
| GHSA-rfgv-xxqx-mfg5 | High | undici@6.25.0 | arm64 amd64 | 6.28.1 | undici vulnerable to Denial of Service via unrequested WebSocket subprotocol |
| GHSA-rfgv-xxqx-mfg5 | High | undici@8.1.0 | arm64 amd64 | 8.10.2 | undici vulnerable to Denial of Service via unrequested WebSocket subprotocol |
| GHSA-hm92-r4w5-c3mj | High | undici@8.1.0 | arm64 amd64 | 8.2.0 | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse |
| GHSA-6chq-wfr3-2hj9 | High | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: Header Injection via Prototype Pollution |
| GHSA-6j4f-fj2g-mc7p | High | brace-expansion@1.1.12 | arm64 amd64 | 1.1.19 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing st... |
| GHSA-qhr7-859c-m2p7 | High | brace-expansion@1.1.12 | arm64 amd64 | 1.1.20 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causin... |
| GHSA-6j4f-fj2g-mc7p | High | brace-expansion@2.0.2 | arm64 amd64 | 2.1.5 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing st... |
| GHSA-qhr7-859c-m2p7 | High | brace-expansion@2.0.2 | arm64 amd64 | 2.1.6 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causin... |
| GHSA-6j4f-fj2g-mc7p | High | brace-expansion@5.0.4 | arm64 amd64 | 5.0.10 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing st... |
| GHSA-qhr7-859c-m2p7 | High | brace-expansion@5.0.4 | arm64 amd64 | 5.0.11 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causin... |
| GHSA-3jxr-9vmj-r5cp | High | brace-expansion@1.1.12 | arm64 amd64 | 1.1.16 | brace-expansion: DoS via exponential-time expansion of consecutive non-expand... |
| GHSA-3jxr-9vmj-r5cp | High | brace-expansion@2.0.2 | arm64 amd64 | 2.1.2 | brace-expansion: DoS via exponential-time expansion of consecutive non-expand... |
| GHSA-3jxr-9vmj-r5cp | High | brace-expansion@5.0.4 | arm64 amd64 | 5.0.7 | brace-expansion: DoS via exponential-time expansion of consecutive non-expand... |
| GHSA-p6gq-j5cr-w38f | High | nodemailer@6.10.0 | arm64 amd64 | 9.0.1 | Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAcc... |
| GHSA-p6gq-j5cr-w38f | High | nodemailer@6.9.16 | arm64 amd64 | 9.0.1 | Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAcc... |
| GHSA-p6gq-j5cr-w38f | High | nodemailer@7.0.12 | arm64 amd64 | 9.0.1 | Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAcc... |
| GHSA-p6gq-j5cr-w38f | High | nodemailer@8.0.5 | arm64 amd64 | 9.0.1 | Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAcc... |
| GHSA-28wg-ghj8-5hjv | High | nanoid@3.3.12 | arm64 amd64 | 3.3.16 | nanoid: non-secure generators can loop indefinitely with negative size |
| GHSA-28wg-ghj8-5hjv | High | nanoid@5.1.11 | arm64 amd64 | 5.1.16 | nanoid: non-secure generators can loop indefinitely with negative size |
| GHSA-r6q2-hw4h-h46w | High | tar@6.2.1 | arm64 amd64 | 7.5.4 | Race Condition in node-tar Path Reservations via Unicode Ligature Collisions ... |
| GHSA-v2hh-gcrm-f6hx | High | fast-uri@3.1.0 | arm64 amd64 | 3.1.4 | fast-uri vulnerable to host confusion via literal backslash authority delimiter |
| GHSA-qw65-cvwx-89v3 | High | fast-uri@3.1.0 | arm64 amd64 | 3.1.7 | fast-uri vulnerable to authority injection via an unvalidated port in serialize |
| GHSA-jqff-g426-hqxp | High | fast-uri@3.1.0 | arm64 amd64 | 3.1.6 | fast-uri vulnerable to host confusion via percent-encoded scheme normalization |
| GHSA-xjpj-3mr7-gcpf | High | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names... |
| GHSA-7p8r-x3mc-p8w7 | High | fast-uri@3.1.0 | arm64 amd64 | 3.1.5 | fast-uri vulnerable to host confusion via backslash authority introducer |
| GHSA-f65p-4m7j-42xc | High | fast-uri@3.1.0 | arm64 amd64 | 3.1.6 | fast-uri vulnerable to server-side request forgery via malformed IPv6 normali... |
| GHSA-83g3-92jg-28cx | High | tar@6.2.1 | arm64 amd64 | 7.5.8 | Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in... |
| GHSA-9ppj-qmqm-q256 | High | tar@6.2.1 | arm64 amd64 | 7.5.11 | node-tar Symlink Path Traversal via Drive-Relative Linkpath |
| GHSA-fv7c-fp4j-7gwp | High | @babel/plugin-transform-modules-systemjs@7.24.7 | arm64 amd64 | 7.29.4 | @babel/plugin-transform-modules-systemjs generates arbitrary code when compil... |
| GHSA-w293-vg96-wgc3 | High | undici@8.1.0 | arm64 amd64 | 8.10.2 | undici vulnerable to TLS certificate validation bypass via dropped connect op... |
| GHSA-5p4m-2wfm-xmqj | High | js-yaml@4.1.1 | arm64 amd64 | 4.3.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2... |
| GHSA-2x7j-588g-ccc2 | High | nodemailer@6.10.0 | arm64 amd64 | 9.1.0 | Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote ... |
| GHSA-v53p-9fqp-m79j | High | nodemailer@6.10.0 | arm64 amd64 | 10.0.6 | Nodemailer: Quadratic backtracking in the addressparser free-text fallback al... |
| GHSA-2x7j-588g-ccc2 | High | nodemailer@6.9.16 | arm64 amd64 | 9.1.0 | Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote ... |
| GHSA-v53p-9fqp-m79j | High | nodemailer@6.9.16 | arm64 amd64 | 10.0.6 | Nodemailer: Quadratic backtracking in the addressparser free-text fallback al... |
| GHSA-2x7j-588g-ccc2 | High | nodemailer@7.0.12 | arm64 amd64 | 9.1.0 | Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote ... |
| GHSA-v53p-9fqp-m79j | High | nodemailer@7.0.12 | arm64 amd64 | 10.0.6 | Nodemailer: Quadratic backtracking in the addressparser free-text fallback al... |
| GHSA-2x7j-588g-ccc2 | High | nodemailer@8.0.5 | arm64 amd64 | 9.1.0 | Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote ... |
| GHSA-v53p-9fqp-m79j | High | nodemailer@8.0.5 | arm64 amd64 | 10.0.6 | Nodemailer: Quadratic backtracking in the addressparser free-text fallback al... |
| GHSA-f88m-g3jw-g9cj | High | sharp@0.34.5 | arm64 amd64 | 0.35.0 | sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, C... |
| GHSA-rgj7-g3m4-5g8c | High | sharp@0.34.5 | arm64 amd64 | 0.35.4 | sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545 |
| GHSA-62hf-57xw-28j9 | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: unbounded recursion in toFormData causes DoS via deeply nested request... |
| GHSA-3w6x-2g7m-8v23 | Medium | axios@1.15.0 | arm64 amd64 | 1.15.2 | Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `p... |
| GHSA-w9j2-pvgh-6h63 | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatu... |
| GHSA-q8wf-6r8g-63ch | Medium | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Denial of Service in the Image Optimization API using SVGs |
| GHSA-f886-m6hf-6m8v | Medium | brace-expansion@1.1.12 | arm64 amd64 | 1.1.13 | brace-expansion: Zero-step sequence causes process hang and memory exhaustion |
| GHSA-f886-m6hf-6m8v | Medium | brace-expansion@2.0.2 | arm64 amd64 | 2.0.3 | brace-expansion: Zero-step sequence causes process hang and memory exhaustion |
| GHSA-f886-m6hf-6m8v | Medium | brace-expansion@5.0.4 | arm64 amd64 | 5.0.5 | brace-expansion: Zero-step sequence causes process hang and memory exhaustion |
| GHSA-mwf2-3pr3-8698 | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: HTTP/2 streamed uploads bypass `maxBodyLength` |
| GHSA-jqh4-m9w3-8hp9 | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength` |
| GHSA-w8wr-v893-vjvp | Medium | tar@6.2.1 | arm64 amd64 | 7.5.18 | node-tar: Process crash via PAX numeric path type confusion |
| GHSA-w8wr-v893-vjvp | Medium | tar@7.5.13 | arm64 amd64 | 7.5.18 | node-tar: Process crash via PAX numeric path type confusion |
| GHSA-4hqw-qxg8-jxx2 | Medium | axios@1.15.0 | arm64 amd64 | 1.20.0 | Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders |
| GHSA-378v-28hj-76wf | Medium | bn.js@4.12.2 | arm64 amd64 | 4.12.3 | bn.js affected by an infinite loop |
| GHSA-4c39-4ccg-62r3 | Medium | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Unbounded Server Action payload in Edge runtime |
| GHSA-pmv8-rq9r-6j72 | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: Deep formToJSON Key Recursion Can Cause Denial of Service |
| GHSA-42h9-826w-cgv3 | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: Excessive recursion in formDataToJSON can cause denial of service |
| GHSA-w5vr-8v7q-w6rv | Medium | baseline-browser-mapping@2.10.23 | arm64 amd64 | 2.11.0 | baseline-browser-mapping process termination on invalid input causes denial o... |
| GHSA-955p-x3mx-jcvp | Medium | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Unauthenticated disclosure of internal Server Function endpoints |
| GHSA-4xrf-jv44-h6hh | Medium | ip-address@10.2.0 | arm64 amd64 | 10.2.2 | ip-address: a CIDR suffix on the parsed address suppresses special-use classi... |
| GHSA-mm7p-fcc7-pg87 | Medium | nodemailer@6.10.0 | arm64 amd64 | 7.0.7 | Nodemailer: Email to an unintended domain can occur due to Interpretation Con... |
| GHSA-mm7p-fcc7-pg87 | Medium | nodemailer@6.9.16 | arm64 amd64 | 7.0.7 | Nodemailer: Email to an unintended domain can occur due to Interpretation Con... |
| GHSA-f4gw-2p7v-4548 | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios |
| GHSA-9h5v-pfqq-x599 | Medium | ua-parser-js@2.0.9 | arm64 amd64 | 2.0.10 | UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withCl... |
| GHSA-v2v4-37r5-5v8g | Medium | ip-address@10.1.0 | arm64 amd64 | 10.1.1 | ip-address has XSS in Address6 HTML-emitting methods |
| GHSA-v2v4-37r5-5v8g | Medium | ip-address@9.0.5 | arm64 amd64 | 10.1.1 | ip-address has XSS in Address6 HTML-emitting methods |
| GHSA-gvwx-54wh-qm9j | Medium | tar@6.2.1 | arm64 amd64 | 7.5.17 | node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records |
| GHSA-gvwx-54wh-qm9j | Medium | tar@7.5.13 | arm64 amd64 | 7.5.17 | node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records |
| GHSA-22jq-vg5j-6vgg | Medium | ip-address@10.2.0 | arm64 amd64 | 10.2.1 | ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass ... |
| GHSA-fxqj-rqcc-2cmp | Medium | postcss@8.4.31 | arm64 amd64 | 8.5.23 | PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMa... |
| GHSA-j8rh-479h-cp32 | Medium | axios@1.15.0 | arm64 amd64 | 1.20.0 | Axios: Header Injection via Inherited headers After Minimal Interceptor |
| GHSA-3p4h-7m6x-2hcm | Medium | multer@2.1.1 | arm64 amd64 | 2.2.0 | Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads |
| GHSA-48c2-rrv3-qjmp | Medium | yaml@1.10.2 | arm64 amd64 | 1.10.3 | yaml is vulnerable to Stack Overflow via deeply nested YAML collections |
| GHSA-5c9x-8gcm-mpgx | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedire... |
| GHSA-vf2m-468p-8v99 | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: HTTP adapter streamed responses bypass maxContentLength |
| GHSA-9fr6-4gfg-395g | Medium | axios@1.15.0 | arm64 amd64 | 1.20.0 | Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Ob... |
| GHSA-vh66-26gq-q6x8 | Medium | axios@1.15.0 | arm64 amd64 | 1.20.0 | Axios: Prototype pollution gadget in fetch adapter can alter outbound requests |
| GHSA-mmx7-hfxf-jppx | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: Prototype pollution gadgets can alter axios request construction |
| GHSA-4vpr-x523-8j87 | Medium | svgo@3.3.3 | arm64 amd64 | 3.3.5 | SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObje... |
| GHSA-2vr4-cq9g-pvrc | Medium | ip-address@10.2.0 | arm64 amd64 | 10.5.1 | ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48... |
| GHSA-pr7r-676h-xcf6 | Medium | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici vulnerable to cross-user information disclosure via shared cache white... |
| GHSA-q8mj-m7cp-5q26 | Medium | qs@6.14.1 | arm64 amd64 | 6.15.2 | qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on nul... |
| GHSA-4mjr-xmp4-gh2g | Medium | qs@6.14.1 | arm64 amd64 | 6.16.0 | qs: Denial of Service via Attacker Controlled isBuffer |
| GHSA-w5hq-g745-h8pq | Medium | uuid@9.0.1 | arm64 amd64 | 11.1.1 | uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided |
| GHSA-m7pr-hjqh-92cm | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: no_proxy bypass via IP alias allows SSRF |
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| GHSA-3wwx-pv8p-q78v | Medium | undici@6.25.0 | arm64 amd64 | 6.28.1 | undici vulnerable to Denial of Service via unhandled error in WebSocket perme... |
| GHSA-3wwx-pv8p-q78v | Medium | undici@8.1.0 | arm64 amd64 | 8.10.2 | undici vulnerable to Denial of Service via unhandled error in WebSocket perme... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| GHSA-3xpg-4rpp-hhhm | Medium | undici@8.1.0 | arm64 amd64 | 8.10.2 | undici vulnerable to Denial of Service via unbounded decompression of compres... |
| GHSA-rpw4-54j3-4h4q | Medium | ip-address@10.1.0 | arm64 amd64 | 10.5.1 | ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10... |
| GHSA-rpw4-54j3-4h4q | Medium | ip-address@10.2.0 | arm64 amd64 | 10.5.1 | ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10... |
| GHSA-rpw4-54j3-4h4q | Medium | ip-address@9.0.5 | arm64 amd64 | 10.5.1 | ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10... |
| GHSA-f23m-r3pf-42rh | Medium | lodash-es@4.17.23 | arm64 amd64 | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` a... |
| GHSA-jr45-8vmc-qm54 | Medium | undici@8.1.0 | arm64 amd64 | 8.9.0 | undici vulnerable to cross-user information disclosure via whitespace around ... |
| GHSA-h67p-54hq-rp68 | Medium | js-yaml@4.1.1 | arm64 amd64 | 4.2.0 | JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases |
| GHSA-j6r3-76f7-8jcv | Medium | ip-address@10.1.0 | arm64 amd64 | 10.7.1 | ip-address: isInSubnet() and isHostInSubnet() compare addresses of different ... |
| GHSA-j6r3-76f7-8jcv | Medium | ip-address@10.2.0 | arm64 amd64 | 10.7.1 | ip-address: isInSubnet() and isHostInSubnet() compare addresses of different ... |
| GHSA-j6r3-76f7-8jcv | Medium | ip-address@9.0.5 | arm64 amd64 | 10.7.1 | ip-address: isInSubnet() and isHostInSubnet() compare addresses of different ... |
| GHSA-jxxr-4gwj-5jf2 | Medium | brace-expansion@5.0.4 | arm64 amd64 | 5.0.6 | brace-expansion: Large numeric range defeats documented `max` DoS protection |
| GHSA-rx4f-c7p8-82vq | Medium | undici@8.1.0 | arm64 amd64 | 8.10.2 | undici vulnerable to Denial of Service via WebSocketStream unclean close |
| GHSA-898c-q2cr-xwhg | Medium | axios@1.15.0 | arm64 amd64 | 1.16.0 | axios has DoS & Header Injection via Prototype Pollution Read-Side Gadget... |
| GHSA-pmjh-fq2x-6v4x | Medium | undici@8.1.0 | arm64 amd64 | 8.10.2 | undici vulnerable to Denial of Service via orphaned RetryHandler response body |
| GHSA-4p3w-j4w9-5jqw | Medium | moment@2.30.1 | arm64 amd64 | 2.31.0 | moment vulnerable to Path Traversal via crafted non-string locale name |
| GHSA-68g3-v927-f742 | Medium | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Cache confusion of response bodies for requests with bodies |
| GHSA-2qvq-rjwj-gvw9 | Medium | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has Prototype Pollution Leading to XSS through Partial Template... |
| GHSA-p88m-4jfj-68fv | Medium | undici@6.25.0 | arm64 amd64 | 6.27.0 | undici vulnerable to HTTP header injection via Set-Cookie percent-decoding |
| GHSA-p88m-4jfj-68fv | Medium | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici vulnerable to HTTP header injection via Set-Cookie percent-decoding |
| GHSA-7q8q-rj6j-mhjq | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: Nested axios option objects can consume polluted prototype values |
| GHSA-4633-3j49-mh5q | Medium | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Cache confusion of response bodies for requests with bodies containi... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| GHSA-2jfj-6hjv-fm6j | Medium | undici@8.1.0 | arm64 amd64 | 8.10.2 | undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in s... |
| GHSA-445q-vr5w-6q77 | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type i... |
| GHSA-h3mg-xc3c-68pw | Medium | ip-address@10.1.0 | arm64 amd64 | 10.7.1 | ip-address: Address6 builds a parse diagnostic proportional to the input with... |
| GHSA-h3mg-xc3c-68pw | Medium | ip-address@10.2.0 | arm64 amd64 | 10.7.1 | ip-address: Address6 builds a parse diagnostic proportional to the input with... |
| GHSA-h3mg-xc3c-68pw | Medium | ip-address@9.0.5 | arm64 amd64 | 10.7.1 | ip-address: Address6 builds a parse diagnostic proportional to the input with... |
| GHSA-xx6v-rp6x-q39c | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `wit... |
| GHSA-q2hr-2g5m-vwhr | Medium | brace-expansion@1.1.12 | arm64 amd64 | 1.1.21 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU ... |
| GHSA-q2hr-2g5m-vwhr | Medium | brace-expansion@2.0.2 | arm64 amd64 | 2.1.7 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU ... |
| GHSA-q2hr-2g5m-vwhr | Medium | brace-expansion@5.0.4 | arm64 amd64 | 5.0.12 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU ... |
| GHSA-qx2v-qp2m-jg93 | Medium | postcss@8.4.31 | arm64 amd64 | 8.5.10 | PostCSS has XSS via Unescaped </style> in its CSS Stringify Output |
| GHSA-hrr3-gc8f-f4qj | Medium | fast-uri@3.1.0 | arm64 amd64 | 3.1.8 | fast-uri vulnerable to inconsistent host case normalization via percent-encod... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| GHSA-v3r7-h72x-cjcm | Medium | undici@6.25.0 | arm64 amd64 | 6.28.0 | undici vulnerable to cookie attribute injection via unsanitized domain and un... |
| GHSA-v3r7-h72x-cjcm | Medium | undici@8.1.0 | arm64 amd64 | 8.9.0 | undici vulnerable to cookie attribute injection via unsanitized domain and un... |
| GHSA-vmf3-w455-68vh | Medium | tar@6.2.1 | arm64 amd64 | 7.5.16 | node-tar applies PAX size override to intermediary GNU long-name/long-link he... |
| GHSA-vmf3-w455-68vh | Medium | tar@7.5.13 | arm64 amd64 | 7.5.16 | node-tar applies PAX size override to intermediary GNU long-name/long-link he... |
| GHSA-m8rv-5g2x-5cg5 | Medium | undici@6.25.0 | arm64 amd64 | 6.28.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property |
| GHSA-m8rv-5g2x-5cg5 | Medium | undici@8.1.0 | arm64 amd64 | 8.9.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property |
| GHSA-8xcm-r25x-g524 | Medium | undici@6.25.0 | arm64 amd64 | 6.28.0 | undici vulnerable to downstream response desynchronization via retry interceptor |
| GHSA-8xcm-r25x-g524 | Medium | undici@8.1.0 | arm64 amd64 | 8.9.0 | undici vulnerable to downstream response desynchronization via retry interceptor |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| GHSA-44g4-m2mj-wpvx | Medium | axios@1.15.0 | arm64 amd64 | 1.20.0 | Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass... |
| GHSA-7rx3-28cr-v5wh | Medium | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupS... |
| GHSA-268h-hp4c-crq3 | Medium | nodemailer@6.10.0 | arm64 amd64 | 8.0.9 | Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitr... |
| GHSA-6vj9-mwq6-2f5v | Medium | nodemailer@6.10.0 | arm64 amd64 | 10.0.2 | Nodemailer: Process-global DNS cache reuses TLS `servername` across transport... |
| GHSA-8m3c-c648-2xjj | Medium | nodemailer@6.10.0 | arm64 amd64 | 9.1.1 | Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disa... |
| GHSA-8vvx-rff5-p5rq | Medium | nodemailer@6.10.0 | arm64 amd64 | 10.0.2 | Nodemailer: Nested structured recipient arrays bypass the parser depth limit ... |
| GHSA-cc9r-2j5m-2m83 | Medium | nodemailer@6.10.0 | arm64 amd64 | 9.1.0 | Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsi... |
| GHSA-r7g4-qg5f-qqm2 | Medium | nodemailer@6.10.0 | arm64 amd64 | 8.0.8 | Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables... |
| GHSA-vvjj-xcjg-gr5g | Medium | nodemailer@6.10.0 | arm64 amd64 | 8.0.5 | Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Op... |
| GHSA-wmmp-3585-3rmp | Medium | nodemailer@6.10.0 | arm64 amd64 | 9.1.0 | Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to ... |
| GHSA-wqvq-jvpq-h66f | Medium | nodemailer@6.10.0 | arm64 amd64 | 8.0.9 | Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess duri... |
| GHSA-268h-hp4c-crq3 | Medium | nodemailer@6.9.16 | arm64 amd64 | 8.0.9 | Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitr... |
| GHSA-6vj9-mwq6-2f5v | Medium | nodemailer@6.9.16 | arm64 amd64 | 10.0.2 | Nodemailer: Process-global DNS cache reuses TLS `servername` across transport... |
| GHSA-8m3c-c648-2xjj | Medium | nodemailer@6.9.16 | arm64 amd64 | 9.1.1 | Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disa... |
| GHSA-8vvx-rff5-p5rq | Medium | nodemailer@6.9.16 | arm64 amd64 | 10.0.2 | Nodemailer: Nested structured recipient arrays bypass the parser depth limit ... |
| GHSA-cc9r-2j5m-2m83 | Medium | nodemailer@6.9.16 | arm64 amd64 | 9.1.0 | Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsi... |
| GHSA-r7g4-qg5f-qqm2 | Medium | nodemailer@6.9.16 | arm64 amd64 | 8.0.8 | Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables... |
| GHSA-vvjj-xcjg-gr5g | Medium | nodemailer@6.9.16 | arm64 amd64 | 8.0.5 | Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Op... |
| GHSA-wmmp-3585-3rmp | Medium | nodemailer@6.9.16 | arm64 amd64 | 9.1.0 | Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to ... |
| GHSA-wqvq-jvpq-h66f | Medium | nodemailer@6.9.16 | arm64 amd64 | 8.0.9 | Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess duri... |
| GHSA-268h-hp4c-crq3 | Medium | nodemailer@7.0.12 | arm64 amd64 | 8.0.9 | Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitr... |
| GHSA-6vj9-mwq6-2f5v | Medium | nodemailer@7.0.12 | arm64 amd64 | 10.0.2 | Nodemailer: Process-global DNS cache reuses TLS `servername` across transport... |
| GHSA-8m3c-c648-2xjj | Medium | nodemailer@7.0.12 | arm64 amd64 | 9.1.1 | Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disa... |
| GHSA-8vvx-rff5-p5rq | Medium | nodemailer@7.0.12 | arm64 amd64 | 10.0.2 | Nodemailer: Nested structured recipient arrays bypass the parser depth limit ... |
| GHSA-cc9r-2j5m-2m83 | Medium | nodemailer@7.0.12 | arm64 amd64 | 9.1.0 | Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsi... |
| GHSA-r7g4-qg5f-qqm2 | Medium | nodemailer@7.0.12 | arm64 amd64 | 8.0.8 | Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables... |
| GHSA-vvjj-xcjg-gr5g | Medium | nodemailer@7.0.12 | arm64 amd64 | 8.0.5 | Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Op... |
| GHSA-wmmp-3585-3rmp | Medium | nodemailer@7.0.12 | arm64 amd64 | 9.1.0 | Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to ... |
| GHSA-wqvq-jvpq-h66f | Medium | nodemailer@7.0.12 | arm64 amd64 | 8.0.9 | Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess duri... |
| GHSA-268h-hp4c-crq3 | Medium | nodemailer@8.0.5 | arm64 amd64 | 8.0.9 | Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitr... |
| GHSA-6vj9-mwq6-2f5v | Medium | nodemailer@8.0.5 | arm64 amd64 | 10.0.2 | Nodemailer: Process-global DNS cache reuses TLS `servername` across transport... |
| GHSA-8m3c-c648-2xjj | Medium | nodemailer@8.0.5 | arm64 amd64 | 9.1.1 | Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disa... |
| GHSA-8vvx-rff5-p5rq | Medium | nodemailer@8.0.5 | arm64 amd64 | 10.0.2 | Nodemailer: Nested structured recipient arrays bypass the parser depth limit ... |
| GHSA-cc9r-2j5m-2m83 | Medium | nodemailer@8.0.5 | arm64 amd64 | 9.1.0 | Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsi... |
| GHSA-r7g4-qg5f-qqm2 | Medium | nodemailer@8.0.5 | arm64 amd64 | 8.0.8 | Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables... |
| GHSA-wmmp-3585-3rmp | Medium | nodemailer@8.0.5 | arm64 amd64 | 9.1.0 | Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to ... |
| GHSA-wqvq-jvpq-h66f | Medium | nodemailer@8.0.5 | arm64 amd64 | 8.0.9 | Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess duri... |
| GHSA-w7fw-mjwx-w883 | Low | qs@6.14.1 | arm64 amd64 | 6.14.2 | qs's arrayLimit bypass in comma parsing allows denial of service |
| GHSA-7gmj-h9xc-mcxc | Low | mailparser@3.7.2 | arm64 amd64 | 3.9.3 | mailparser vulnerable to Cross-site Scripting |
| GHSA-v422-hmwv-36x6 | Low | body-parser@2.2.2 | arm64 amd64 | 2.3.0 | body-parser vulnerable to denial of service when invalid limit value silently... |
| GHSA-35p6-xmwp-9g52 | Low | undici@6.25.0 | arm64 amd64 | 6.27.0 | undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse |
| GHSA-35p6-xmwp-9g52 | Low | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse |
| GHSA-xhjh-pmcv-23jw | Low | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams |
| GHSA-r53p-7pc4-xj5r | Low | undici@6.25.0 | arm64 amd64 | 6.28.1 | undici vulnerable to downstream response splitting via retry interceptor |
| GHSA-r53p-7pc4-xj5r | Low | undici@8.1.0 | arm64 amd64 | 8.10.2 | undici vulnerable to downstream response splitting via retry interceptor |
| GHSA-g8m3-5g58-fq7m | Low | undici@6.25.0 | arm64 amd64 | 6.27.0 | undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive s... |
| GHSA-g8m3-5g58-fq7m | Low | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive s... |
| GHSA-qvfw-j98x-7q72 | Low | multer@2.1.1 | arm64 amd64 | 2.3.0 | multer vulnerable to file size limit bypass via async fileFilter race condition |
| GHSA-2gqq-gqf2-x968 | Low | undici@8.1.0 | arm64 amd64 | 8.10.2 | undici vulnerable to response truncation via oversized chunked responses in t... |
| GHSA-4x5r-pxfx-6jf8 | Low | @babel/core@7.29.0 | arm64 amd64 | 7.29.6 | @babel/core: Arbitrary File Read via sourceMappingURL Comment |
| GHSA-vpq2-c234-7xj6 | Low | @tootallnate/once@1.1.2 | arm64 amd64 | 2.0.1 | @tootallnate/once vulnerable to Incorrect Control Flow Scoping |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| GHSA-8436-99hf-9mmv | Low | undici@8.1.0 | arm64 amd64 | 8.10.2 | undici vulnerable to caching and replay of unsafe HTTP method responses |
| GHSA-442j-39wm-28r2 | Low | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has a Property Access Validation Bypass in container.lookup |
| GHSA-c7w3-x93f-qmm8 | Low | nodemailer@6.10.0 | arm64 amd64 | 8.0.4 | Nodemailer has SMTP command injection due to unsanitized `envelope.size` para... |
| GHSA-c7w3-x93f-qmm8 | Low | nodemailer@6.9.16 | arm64 amd64 | 8.0.4 | Nodemailer has SMTP command injection due to unsanitized `envelope.size` para... |
| GHSA-c7w3-x93f-qmm8 | Low | nodemailer@7.0.12 | arm64 amd64 | 8.0.4 | Nodemailer has SMTP command injection due to unsanitized `envelope.size` para... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-8g4q-xg66-9fp4 | High | System.Text.Json@6.0.9 | arm64 amd64 | 6.0.10 | Microsoft Security Advisory CVE-2024-43485 | .NET Denial of Service Vulnerabi... |
| GHSA-59j7-ghrg-fj52 | Medium | Microsoft.IdentityModel.JsonWebTokens@6.8.0 | arm64 amd64 | 6.34.0 | Microsoft ASP.NET Core project templates vulnerable to denial of service |
| GHSA-59j7-ghrg-fj52 | Medium | System.IdentityModel.Tokens.Jwt@6.8.0 | arm64 amd64 | 6.34.0 | Microsoft ASP.NET Core project templates vulnerable to denial of service |
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-87910 | Medium | python-3.14@3.14.7_git20260925-r0 | arm64 amd64 | Unpatched | When tarfile extracts a link on a system that doesn't support links, it ... |
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2025-15367 | Medium | python-3.14@3.14.7_git20260925-r0 | arm64 amd64 | Unpatched | The poplib module, when passed a user-controlled command, can have additional... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-82j2-j2ch-gfr8 | High | rustls-webpki@0.101.7 | arm64 amd64 | 0.103.13 | rustls-webpki: Denial of service via panic on malformed CRL BIT STRING |
| CVE-2026-80489 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character... |
| CVE-2026-77117 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide charact... |
| CVE-2026-8674 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALD... |
| CVE-2026-89092 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack... |
| CVE-2026-86805 | Medium | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader ... |
| CVE-2026-95818 | Low | glibc-2.44@2.44-r7 | arm64 amd64 | Unpatched | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Libr... |
| GHSA-965h-392x-2mh5 | Low | rustls-webpki@0.101.7 | arm64 amd64 | 0.103.12 | webpki: Name constraints for URI names were incorrectly accepted |
| GHSA-xgp8-3hg3-c2mh | Low | rustls-webpki@0.101.7 | arm64 amd64 | 0.103.12 | webpki: Name constraints were accepted for certificates asserting a wildcard ... |