$ scanned 37 releases | 2026-08-17 03:59 UTC
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GO-2026-5026 | High | stdlib@go1.26.5 | arm64 amd64 | 1.25.13, 1.26.6, 1.27.0-rc.3 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded label... |
| CVE-2022-45770 | High | adguard@0.107.78-r0 | arm64 amd64 | Unpatched | Improper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 ... |
| GO-2026-6089 | High | stdlib@go1.26.5 | arm64 amd64 | 1.25.13, 1.26.6, 1.27.0-rc.3 | When a server is configured to support unencrypted HTTP/2, it reads a few byt... |
| GO-2026-6088 | High | stdlib@go1.26.5 | arm64 amd64 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Previously, DecodeElement would reset the depth counter causing it to never f... |
| GO-2026-6090 | High | stdlib@go1.26.5 | arm64 amd64 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Handshake messages, such as KeyUpdate, are always considered as state-advanci... |
| GO-2026-5972 | High | stdlib@go1.26.5 | arm64 amd64 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsi... |
| GO-2026-5970 | High | golang.org/x/text@v0.38.0 | arm64 amd64 | 0.39.0 | A norm.Iter can enter an infinite loop when handling input containing invalid... |
| CVE-2026-46600 | High | stdlib@go1.26.5 | arm64 amd64 | 1.26.6, 1.27.0-rc.3 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter va... |
| GO-2026-5942 | High | stdlib@go1.26.5 | arm64 amd64 | 1.26.6, 1.27.0-rc.3 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter va... |
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| GO-2026-6218 | Medium | stdlib@go1.26.5 | arm64 amd64 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Previously, resolving relative paths containing parent directory ('..... |
| GO-2026-6091 | Medium | stdlib@go1.26.5 | arm64 amd64 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Previously, pathological inputs could close an unescaped '/' early,... |
| GHSA-mwwc-3jv2-62j3 | Medium | github.com/AdguardTeam/AdGuardHome@v0.107.78+dirty | arm64 amd64 | 0.108.0-b.16 | AdGuardHome vulnerable to Cross-Site Request Forgery |
| GO-2026-5932 | Unknown | golang.org/x/crypto@v0.53.0 | arm64 amd64 | Unpatched | The golang.org/x/crypto/openpgp package is unsafe by design, has numerous kno... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2012-4682 | Medium | bitcoin-core@31.1-r0 | arm64 amd64 | Unpatched | Unspecified vulnerability in bitcoind and Bitcoin-Qt allows attackers to caus... |
| CVE-2012-4683 | Medium | bitcoin-core@31.1-r0 | arm64 amd64 | Unpatched | Unspecified vulnerability in bitcoind and Bitcoin-Qt allows attackers to caus... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-40200 | High | musl@1.2.6-r2 | arm64 amd64 | Unpatched | An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory... |
| CVE-2026-6042 | Medium | musl@1.2.6-r2 | arm64 amd64 | Unpatched | A security flaw has been discovered in musl libc up to 1.2.6. Affected is the... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-47304 | Critical | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| CVE-2026-47304 | Critical | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| CVE-2026-47302 | High | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| CVE-2026-47302 | High | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| CVE-2026-50648 | High | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| CVE-2026-50648 | High | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| CVE-2026-50525 | High | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| CVE-2026-50525 | High | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| GHSA-23rf-6693-g89p | Unknown | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| GHSA-8q5v-6pqq-x66h | Unknown | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| GHSA-cvvh-rhrc-wg4q | Unknown | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| GHSA-g8r8-53c2-pm3f | Unknown | dotnet-8@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| GHSA-23rf-6693-g89p | Unknown | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| GHSA-8q5v-6pqq-x66h | Unknown | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| GHSA-cvvh-rhrc-wg4q | Unknown | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 | |
| GHSA-g8r8-53c2-pm3f | Unknown | dotnet-8-runtime@8.0.127-r0 | arm64 amd64 | 8.0.129-r1 |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-cq8v-f236-94qc | Low | rand@0.8.5 | arm64 amd64 | 0.8.6 | Rand is unsound with a custom logger using rand::rng() |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2025-15367 | Medium | python-3.14@3.14.7-r1 | arm64 amd64 | Unpatched | The poplib module, when passed a user-controlled command, can have additional... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-qpgv-g792-wh6x | High | parse_duration@2.1.1 | arm64 amd64 | Unpatched | Uncontrolled Resource Consumption in parse_duration |
| GHSA-2gh3-rmm4-6rq5 | Medium | protobuf@2.28.0 | arm64 amd64 | 3.7.2 | Crash due to uncontrolled recursion in protobuf crate |
| GHSA-cq8v-f236-94qc | Low | rand@0.8.5 | arm64 amd64 | 0.8.6 | Rand is unsound with a custom logger using rand::rng() |
| GHSA-cq8v-f236-94qc | Low | rand@0.9.2 | arm64 amd64 | 0.9.3 | Rand is unsound with a custom logger using rand::rng() |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-vgwf-h737-ff37 | Critical | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: Invoking client can cause server deadlock on unexpected ... |
| GHSA-f5wc-c3c7-36mc | Critical | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto doesn't drop invoking agent constraints when forward... |
| GHSA-5cgq-3rg8-m6cv | Critical | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status |
| GHSA-x527-x647-q7gg | Critical | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enfo... |
| GHSA-rm3j-f69w-wqmq | Critical | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto vulnerable to infinite loop on large channel writes |
| GHSA-89gr-r52h-f8rx | Critical | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: FIDO/U2F security key physical presence check can be byp... |
| GHSA-jppx-rxg9-jmrx | Critical | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto doesn't enforce invoking key constraints |
| GO-2025-4116 | High | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.43.0 | SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will ... |
| GHSA-q4h4-gmj2-qvw2 | High | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic |
| GHSA-w879-237q-wc7r | High | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS |
| GHSA-j5w8-q4qc-rx2x | Medium | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.45.0 | golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption |
| GHSA-f6x5-jh6r-wrfv | Medium | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.45.0 | golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due... |
| GHSA-78mq-xcr3-xm33 | Medium | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKe... |
| GHSA-9m57-25v3-79x9 | Medium | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: Invoking pathological inputs can lead to client panic |
| GHSA-45gg-vh54-h5m9 | Medium | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions |
| GHSA-qpw4-5x99-6vjp | Medium | golang.org/x/crypto@v0.35.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to... |
| GHSA-xmrv-pmrh-hhx2 | Medium | github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.6.4 | arm64 amd64 | 1.7.8 | Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder |
| GHSA-xmrv-pmrh-hhx2 | Medium | github.com/aws/aws-sdk-go-v2/service/s3@v1.59.0 | arm64 amd64 | 1.97.3 | Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder |
| GO-2026-5932 | Unknown | golang.org/x/crypto@v0.35.0 | arm64 amd64 | Unpatched | The golang.org/x/crypto/openpgp package is unsafe by design, has numerous kno... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-67hx-6x53-jw92 | Critical | babel-traverse@6.26.0 | arm64 amd64 | Unpatched | Babel vulnerable to arbitrary code execution when compiling specifically craf... |
| GHSA-23hp-3jrh-7fpw | Critical | tar@7.5.16 | arm64 amd64 | 7.5.19 | node-tar: Decompression/parse DoS via unlimited input |
| GHSA-p6mc-m468-83gw | High | lodash.pick@4.4.0 | arm64 amd64 | Unpatched | Prototype Pollution in lodash |
| GHSA-pfq8-rq6v-vf5m | High | html-minifier@4.0.0 | arm64 amd64 | Unpatched | kangax html-minifier REDoS vulnerability |
| GHSA-vghf-hv5q-vc2g | High | validator@7.2.0 | arm64 amd64 | 13.15.22 | Validator is Vulnerable to Incomplete Filtering of One or More Instances of S... |
| GHSA-8cf7-32gw-wr33 | High | jsonwebtoken@8.5.1 | arm64 amd64 | 9.0.0 | jsonwebtoken unrestricted key type could lead to legacy keys usage |
| GHSA-5p2g-fcmc-qvqq | High | image-size@1.2.1 | arm64 amd64 | Unpatched | image-size: JXL and HEIF parsers allow denial of service through infinite loops |
| GHSA-w3rx-r6r6-pgpr | High | image-size@1.2.1 | arm64 amd64 | Unpatched | image-size: ICNS parser allows denial of service through an infinite loop |
| GHSA-8x88-c5mf-7j5w | High | tar@7.5.16 | arm64 amd64 | 7.5.18 | node-tar: Negative tar entry size causes infinite loop in archive replace |
| GHSA-jmr9-qjv8-65gv | High | extract-zip@2.0.1 | arm64 amd64 | Unpatched | extract-zip unvalidated symlink path traversal |
| GHSA-rgw5-rvv9-x895 | High | brace-expansion@1.1.15 | arm64 amd64 | 1.1.18 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-202... |
| GHSA-rgw5-rvv9-x895 | High | brace-expansion@2.1.1 | arm64 amd64 | 2.1.4 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-202... |
| GHSA-rgw5-rvv9-x895 | High | brace-expansion@5.0.6 | arm64 amd64 | 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-202... |
| GHSA-4c8g-83qw-93j6 | High | fast-uri@3.1.2 | arm64 amd64 | 3.1.3 | fast-uri vulnerable to host confusion via failed IDN canonicalization |
| GHSA-mh99-v99m-4gvg | High | brace-expansion@1.1.15 | arm64 amd64 | 1.1.17 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory ... |
| GHSA-mh99-v99m-4gvg | High | brace-expansion@2.1.1 | arm64 amd64 | 2.1.3 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory ... |
| GHSA-mh99-v99m-4gvg | High | brace-expansion@5.0.6 | arm64 amd64 | 5.0.8 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory ... |
| GHSA-3jxr-9vmj-r5cp | High | brace-expansion@1.1.15 | arm64 amd64 | 1.1.16 | brace-expansion: DoS via exponential-time expansion of consecutive non-expand... |
| GHSA-3jxr-9vmj-r5cp | High | brace-expansion@2.1.1 | arm64 amd64 | 2.1.2 | brace-expansion: DoS via exponential-time expansion of consecutive non-expand... |
| GHSA-3jxr-9vmj-r5cp | High | brace-expansion@5.0.6 | arm64 amd64 | 5.0.7 | brace-expansion: DoS via exponential-time expansion of consecutive non-expand... |
| GHSA-4cwx-7wf7-3272 | High | undici@7.28.0 | arm64 amd64 | 7.29.0 | undici vulnerable to cross-user information disclosure and parse-time crash v... |
| GHSA-28wg-ghj8-5hjv | High | nanoid@3.3.15 | arm64 amd64 | 3.3.16 | nanoid: non-secure generators can loop indefinitely with negative size |
| GHSA-2v37-7h3g-55p8 | High | nanoid@3.3.15 | arm64 amd64 | 3.3.18 | nanoid: custom generators can loop indefinitely when size is zero |
| GHSA-mwp4-54f8-5fhr | High | ip-address@10.2.0 | arm64 amd64 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers d... |
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| GHSA-v2hh-gcrm-f6hx | High | fast-uri@3.1.2 | arm64 amd64 | 3.1.4 | fast-uri vulnerable to host confusion via literal backslash authority delimiter |
| GHSA-7p8r-x3mc-p8w7 | High | fast-uri@3.1.2 | arm64 amd64 | 3.1.5 | fast-uri vulnerable to host confusion via backslash authority introducer |
| GHSA-5p4m-2wfm-xmqj | High | js-yaml@4.3.0 | arm64 amd64 | 4.3.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2... |
| GHSA-p6gq-j5cr-w38f | High | nodemailer@8.0.11 | arm64 amd64 | 9.0.1 | Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAcc... |
| GHSA-r28c-9q8g-f849 | High | postcss@8.5.16 | arm64 amd64 | 8.5.18 | PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL... |
| GHSA-qgmg-gppg-76g5 | Medium | validator@7.2.0 | arm64 amd64 | 13.7.0 | Inefficient Regular Expression Complexity in validator.js |
| GHSA-hjrf-2m68-5959 | Medium | jsonwebtoken@8.5.1 | arm64 amd64 | 9.0.0 | jsonwebtoken's insecure implementation of key retrieval function could l... |
| GHSA-qwph-4952-7xr6 | Medium | jsonwebtoken@8.5.1 | arm64 amd64 | 9.0.0 | jsonwebtoken vulnerable to signature validation bypass due to insecure defaul... |
| GHSA-w8wr-v893-vjvp | Medium | tar@7.5.16 | arm64 amd64 | 7.5.18 | node-tar: Process crash via PAX numeric path type confusion |
| GHSA-w5hq-g745-h8pq | Medium | uuid@9.0.1 | arm64 amd64 | 11.1.1 | uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided |
| GHSA-fxqj-rqcc-2cmp | Medium | postcss@8.5.16 | arm64 amd64 | 8.5.23 | PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMa... |
| GHSA-9965-vmph-33xx | Medium | validator@7.2.0 | arm64 amd64 | 13.15.20 | validator.js has a URL validation bypass vulnerability in its isURL function |
| GHSA-4xrf-jv44-h6hh | Medium | ip-address@10.2.0 | arm64 amd64 | 10.2.2 | ip-address: a CIDR suffix on the parsed address suppresses special-use classi... |
| GHSA-22jq-vg5j-6vgg | Medium | ip-address@10.2.0 | arm64 amd64 | 10.2.1 | ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass ... |
| GHSA-gvwx-54wh-qm9j | Medium | tar@7.5.16 | arm64 amd64 | 7.5.17 | node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records |
| GHSA-jr45-8vmc-qm54 | Medium | undici@7.28.0 | arm64 amd64 | 7.29.0 | undici vulnerable to cross-user information disclosure via whitespace around ... |
| GHSA-8xcm-r25x-g524 | Medium | undici@6.27.0 | arm64 amd64 | 6.28.0 | undici vulnerable to downstream response desynchronization via retry interceptor |
| GHSA-8xcm-r25x-g524 | Medium | undici@7.28.0 | arm64 amd64 | 7.29.0 | undici vulnerable to downstream response desynchronization via retry interceptor |
| GHSA-v3r7-h72x-cjcm | Medium | undici@6.27.0 | arm64 amd64 | 6.28.0 | undici vulnerable to cookie attribute injection via unsanitized domain and un... |
| GHSA-v3r7-h72x-cjcm | Medium | undici@7.28.0 | arm64 amd64 | 7.29.0 | undici vulnerable to cookie attribute injection via unsanitized domain and un... |
| GHSA-j4r3-hg7j-8chg | Medium | re2@1.25.0 | arm64 amd64 | 1.26.1 | node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending ... |
| GHSA-6hxr-mr5r-9836 | Medium | re2@1.25.0 | arm64 amd64 | 1.25.2 | re2: Global `String.prototype.match` with an empty-matchable pattern never ad... |
| GHSA-m8rv-5g2x-5cg5 | Medium | undici@6.27.0 | arm64 amd64 | 6.28.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property |
| GHSA-m8rv-5g2x-5cg5 | Medium | undici@7.28.0 | arm64 amd64 | 7.29.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property |
| GHSA-ff84-5f28-78qj | Medium | re2@1.25.0 | arm64 amd64 | 1.25.2 | re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced... |
| GHSA-8hcv-x26h-mcgp | Medium | re2@1.25.0 | arm64 amd64 | 1.25.1 | node-re2: String.prototype.replace(re2, template) aborts the Node process (un... |
| GHSA-55q2-fjhq-7xh7 | Medium | dompurify@3.4.11 | arm64 amd64 | 3.4.13 | DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causin... |
| GHSA-984p-xq9m-4rjw | Medium | express-brute@1.0.1 | arm64 amd64 | Unpatched | Rate Limiting Bypass in express-brute |
| GHSA-r292-9mhp-454m | Medium | tar@7.5.16 | arm64 amd64 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable sta... |
| GHSA-v422-hmwv-36x6 | Low | body-parser@1.20.5 | arm64 amd64 | 1.20.6 | body-parser vulnerable to denial of service when invalid limit value silently... |
| GHSA-c2j3-45gr-mqc4 | Low | dompurify@3.4.11 | arm64 amd64 | 3.4.12 | DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for all... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | openssl@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| GHSA-g7hc-96xr-gvvx | Medium | MimeKit@4.14.0 | arm64 amd64 | 4.15.1 | MimeKit has CRLF Injection in Quoted Local-Part that Enables SMTP Command Inj... |
| GHSA-9j88-vvj5-vhgr | Medium | MailKit@4.14.0 | arm64 amd64 | 4.16.0 | MailKit has STARTTLS Response Injection via unflushed stream buffer that enab... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-p77j-4mvh-x3m3 | Critical | google.golang.org/grpc@v1.59.0 | arm64 amd64 | 1.79.3 | gRPC-Go has an authorization bypass via missing leading slash in :path |
| GHSA-xgrm-4fwx-7qm8 | Critical | github.com/jackc/pgx/v5@v5.7.4 | arm64 amd64 | 5.9.0 | pgx contains memory-safety vulnerability |
| GHSA-vgwf-h737-ff37 | Critical | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: Invoking client can cause server deadlock on unexpected ... |
| GHSA-f5wc-c3c7-36mc | Critical | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto doesn't drop invoking agent constraints when forward... |
| GHSA-9jj7-4m8r-rfcm | Critical | github.com/jackc/pgx/v5@v5.7.4 | arm64 amd64 | 5.9.0 | Memory-safety vulnerability in github.com/jackc/pgx/v5. |
| GHSA-5cgq-3rg8-m6cv | Critical | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status |
| GHSA-x527-x647-q7gg | Critical | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enfo... |
| GHSA-rm3j-f69w-wqmq | Critical | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto vulnerable to infinite loop on large channel writes |
| GHSA-89gr-r52h-f8rx | Critical | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: FIDO/U2F security key physical presence check can be byp... |
| GHSA-jppx-rxg9-jmrx | Critical | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto doesn't enforce invoking key constraints |
| GHSA-x744-4wpc-v9h2 | High | github.com/docker/docker@v28.1.1+incompatible | arm64 amd64 | 29.3.1 | Moby has AuthZ plugin bypass when provided oversized request bodies |
| GHSA-9493-h29p-rfm2 | High | github.com/opencontainers/runc@v1.1.14 | arm64 amd64 | 1.2.8 | runc container escape via "masked path" abuse due to mount race con... |
| GO-2026-4918 | High | golang.org/x/net@v0.39.0 | arm64 amd64 | 0.53.0 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop... |
| GHSA-4f99-4q7p-p3gh | High | github.com/sirupsen/logrus@v1.9.2 | arm64 amd64 | 1.9.3 | Logrus is vulnerable to DoS when using Entry.Writer() |
| GO-2026-5026 | High | golang.org/x/net@v0.39.0 | arm64 amd64 | 0.55.0 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded label... |
| GHSA-jqcq-xjh3-6g23 | High | github.com/jackc/pgproto3/v2@v2.3.3 | arm64 amd64 | Unpatched | Denial of service in github.com/jackc/pgproto3/v2 |
| GO-2025-4116 | High | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.43.0 | SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will ... |
| GHSA-qw9x-cqr3-wc7r | High | github.com/opencontainers/runc@v1.1.14 | arm64 amd64 | 1.2.8 | runc container escape with malicious config due to /dev/console mount and rel... |
| GHSA-cgrx-mc8f-2prm | High | github.com/opencontainers/runc@v1.1.14 | arm64 amd64 | 1.2.8 | runc container escape and denial of service due to arbitrary write gadgets an... |
| GHSA-q4h4-gmj2-qvw2 | High | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic |
| GHSA-w879-237q-wc7r | High | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS |
| GHSA-p436-gjf2-799p | High | github.com/docker/cli@v28.1.1+incompatible | arm64 amd64 | 29.2.0 | Docker CLI Plugins: Uncontrolled Search Path Element Leads to Local Privilege... |
| GO-2026-5970 | High | golang.org/x/text@v0.24.0 | arm64 amd64 | 0.39.0 | A norm.Iter can enter an infinite loop when handling input containing invalid... |
| GO-2026-5942 | High | golang.org/x/net@v0.39.0 | arm64 amd64 | 0.56.0 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter va... |
| GHSA-hfvc-g4fc-pqhx | High | go.opentelemetry.io/otel/sdk@v1.35.0 | arm64 amd64 | 1.43.0 | opentelemetry-go: BSD kenv command not using absolute path enables PATH hijac... |
| GHSA-x86f-5xw2-fm2r | High | github.com/docker/docker@v28.1.1+incompatible | arm64 amd64 | Unpatched | Docker: `PUT /containers/{id}/archive` executes container binary on the host |
| GHSA-9h8m-3fm2-qjrq | High | go.opentelemetry.io/otel/sdk@v1.35.0 | arm64 amd64 | 1.40.0 | OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking |
| GHSA-rg2x-37c3-w2rh | High | github.com/docker/docker@v28.1.1+incompatible | arm64 amd64 | Unpatched | Docker: Race condition in docker cp allows bind mount redirection to host path |
| GHSA-hrxh-6v49-42gf | High | google.golang.org/grpc@v1.59.0 | arm64 amd64 | 1.82.1 | gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities |
| GHSA-j5w8-q4qc-rx2x | Medium | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.45.0 | golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption |
| GHSA-f6x5-jh6r-wrfv | Medium | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.45.0 | golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due... |
| GHSA-78mq-xcr3-xm33 | Medium | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKe... |
| GO-2026-4440 | Medium | golang.org/x/net@v0.39.0 | arm64 amd64 | 0.45.0 | The html.Parse function in golang.org/x/net/html has quadratic parsing comple... |
| GO-2026-4441 | Medium | golang.org/x/net@v0.39.0 | arm64 amd64 | 0.45.0 | The html.Parse function in golang.org/x/net/html has an infinite parsing loop... |
| GHSA-pxq6-2prw-chj9 | Medium | github.com/docker/docker@v28.1.1+incompatible | arm64 amd64 | Unpatched | Moby has an Off-by-one error in its plugin privilege validation |
| GHSA-9m57-25v3-79x9 | Medium | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: Invoking pathological inputs can lead to client panic |
| GHSA-45gg-vh54-h5m9 | Medium | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions |
| GHSA-5cv4-jp36-h3mw | Medium | golang.org/x/net@v0.39.0 | arm64 amd64 | 0.55.0 | Go Net HTML parser is vulnerable to denial of service |
| GHSA-2464-8j7c-4cjm | Medium | github.com/go-viper/mapstructure/v2@v2.3.0 | arm64 amd64 | 2.4.0 | go-viper's mapstructure May Leak Sensitive Information in Logs When Proc... |
| GHSA-qpw4-5x99-6vjp | Medium | golang.org/x/crypto@v0.37.0 | arm64 amd64 | 0.52.0 | golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to... |
| GO-2026-5025 | Medium | golang.org/x/net@v0.39.0 | arm64 amd64 | 0.55.0 | Parsing arbitrary HTML which is then rendered using Render can result in an u... |
| GO-2026-5030 | Medium | golang.org/x/net@v0.39.0 | arm64 amd64 | 0.55.0 | Parsing arbitrary HTML which is then rendered using Render can result in an u... |
| GO-2026-5027 | Medium | golang.org/x/net@v0.39.0 | arm64 amd64 | 0.55.0 | Parsing arbitrary HTML which is then rendered using Render can result in an u... |
| GO-2026-5029 | Medium | golang.org/x/net@v0.39.0 | arm64 amd64 | 0.55.0 | Parsing arbitrary HTML which is then rendered using Render can result in an u... |
| GO-2026-5736 | Medium | go.etcd.io/etcd/server/v3@v3.5.12 | arm64 amd64 | 3.4.44, 3.5.30, 3.6.11 | Etcd RBAC bypass via PrevKv/lease in nested transactions in go.etcd.io/etcd/v... |
| GHSA-xjvp-4fhw-gc47 | Medium | github.com/opencontainers/runc@v1.1.14 | arm64 amd64 | 1.3.6 | runc: Malicious image with /dev symlink can trigger limited host filesystem i... |
| GHSA-vp62-88p7-qqf5 | Medium | github.com/docker/docker@v28.1.1+incompatible | arm64 amd64 | Unpatched | Docker: Race condition in docker cp allows creation of arbitrary empty files ... |
| GHSA-j88v-2chj-qfwx | Low | github.com/jackc/pgx/v4@v4.18.3 | arm64 amd64 | Unpatched | pgx: SQL Injection via placeholder confusion with dollar quoted string literals |
| GHSA-j88v-2chj-qfwx | Low | github.com/jackc/pgx/v5@v5.7.4 | arm64 amd64 | 5.9.2 | pgx: SQL Injection via placeholder confusion with dollar quoted string literals |
| GO-2026-5024 | Low | golang.org/x/sys@v0.32.0 | arm64 amd64 | 0.44.0 | NewNTUnicodeString does not check for string length overflow. When provided w... |
| GO-2026-5841 | Unknown | github.com/klauspost/compress@v1.17.9 | arm64 amd64 | 1.18.7 | Providing a specially crafted dictionary to s2.NewDict and using it to encode... |
| GO-2026-5932 | Unknown | golang.org/x/crypto@v0.37.0 | arm64 amd64 | Unpatched | The golang.org/x/crypto/openpgp package is unsafe by design, has numerous kno... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | openssl@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GO-2026-5841 | Unknown | github.com/klauspost/compress@v1.18.6 | arm64 amd64 | 1.18.7 | Providing a specially crafted dictionary to s2.NewDict and using it to encode... |
| GO-2026-5932 | Unknown | golang.org/x/crypto@v0.53.0 | arm64 amd64 | Unpatched | The golang.org/x/crypto/openpgp package is unsafe by design, has numerous kno... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-2w6w-674q-4c4q | Critical | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has JavaScript Injection via AST Type Confusion |
| GHSA-23hp-3jrh-7fpw | Critical | tar@6.2.1 | arm64 amd64 | 7.5.19 | node-tar: Decompression/parse DoS via unlimited input |
| GHSA-23hp-3jrh-7fpw | Critical | tar@7.5.13 | arm64 amd64 | 7.5.19 | node-tar: Decompression/parse DoS via unlimited input |
| GHSA-r5fr-rjxr-66jc | High | lodash-es@4.17.23 | arm64 amd64 | 4.18.0 | lodash vulnerable to Code Injection via `_.template` imports key names |
| GHSA-35jp-ww65-95wh | High | axios@1.15.0 | arm64 amd64 | 1.16.0 | axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in ... |
| GHSA-6gpp-xcg3-4w24 | High | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Middleware / Proxy bypass in App Router applications using Turbopack... |
| GHSA-pjwm-pj3p-43mv | High | axios@1.15.0 | arm64 amd64 | 1.16.0 | axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses,... |
| GHSA-qpx9-hpmf-5gmw | High | underscore@1.13.7 | arm64 amd64 | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for ... |
| GHSA-p9j2-gv94-2wf4 | High | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Server-Side Request Forgery in rewrites via attacker-controlled dest... |
| GHSA-pf86-5x62-jrwf | High | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, a... |
| GHSA-vxpw-j846-p89q | High | undici@6.25.0 | arm64 amd64 | 6.27.0 | undici WebSocket client vulnerable to denial of service via fragment count by... |
| GHSA-vxpw-j846-p89q | High | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici WebSocket client vulnerable to denial of service via fragment count by... |
| GHSA-3mfm-83xf-c92r | High | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @p... |
| GHSA-xhpv-hc6g-r9c6 | High | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has JavaScript Injection via AST Type Confusion when passing an... |
| GHSA-q8qp-cvcw-x6jj | High | axios@1.15.0 | arm64 amd64 | 1.15.2 | Axios has prototype pollution read-side gadgets in HTTP adapter that allow cr... |
| GHSA-p92q-9vqr-4j8v | High | axios@1.15.0 | arm64 amd64 | 1.16.0 | Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HT... |
| GHSA-j5f8-grm9-p9fc | High | axios@1.15.0 | arm64 amd64 | 1.16.0 | Axios: Proxy-Authorization header leaks to redirect target when proxy is re-e... |
| GHSA-pmwg-cvhr-8vh7 | High | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via R... |
| GHSA-m99w-x7hq-7vfj | High | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Denial of Service in App Router using Server Actions |
| GHSA-hfxv-24rg-xrqf | High | axios@1.15.0 | arm64 amd64 | 1.16.0 | Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection |
| GHSA-777c-7fjr-54vf | High | axios@1.15.0 | arm64 amd64 | 1.16.0 | Allocation of Resources Without Limits or Throttling in Axios |
| GHSA-9cx6-37pm-9jff | High | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has Denial of Service via Malformed Decorator Syntax in Templat... |
| GHSA-6g55-p6wh-862q | High | postcss@8.4.31 | arm64 amd64 | 8.5.12 | PostCSS: Arbitrary file read and information disclosure via attacker-controll... |
| GHSA-34x7-hfp2-rc4v | High | tar@6.2.1 | arm64 amd64 | 7.5.7 | node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Tr... |
| GHSA-89xv-2m56-2m9x | High | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Server-Side Request Forgery in Server Actions on custom servers |
| GHSA-3ppc-4f35-3m26 | High | minimatch@9.0.5 | arm64 amd64 | 9.0.6 | minimatch has a ReDoS via repeated wildcards with non-matching literal in pat... |
| GHSA-hmw2-7cc7-3qxx | High | form-data@4.0.5 | arm64 amd64 | 4.0.6 | form-data: CRLF injection in form-data via unescaped multipart field names an... |
| GHSA-q3j6-qgpj-74h6 | High | fast-uri@3.1.0 | arm64 amd64 | 3.1.1 | fast-uri vulnerable to path traversal via percent-encoded dot segments |
| GHSA-7r86-cg39-jmmj | High | minimatch@9.0.5 | arm64 amd64 | 9.0.7 | minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-a... |
| GHSA-3g43-6gmg-66jw | High | axios@1.15.0 | arm64 amd64 | 1.15.2 | axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pol... |
| GHSA-v39h-62p7-jpjc | High | fast-uri@3.1.0 | arm64 amd64 | 3.1.2 | fast-uri vulnerable to host confusion via percent-encoded authority delimiters |
| GHSA-23c5-xmqv-rm74 | High | minimatch@9.0.5 | arm64 amd64 | 9.0.7 | minimatch ReDoS: nested *() extglobs generate catastrophically backtracking r... |
| GHSA-rcmh-qjqh-p98v | High | nodemailer@6.10.0 | arm64 amd64 | 7.0.11 | Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls |
| GHSA-rcmh-qjqh-p98v | High | nodemailer@6.9.16 | arm64 amd64 | 7.0.11 | Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls |
| GHSA-vmh5-mc38-953g | High | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici vulnerable to TLS certificate validation bypass via dropped requestTls... |
| GHSA-8x88-c5mf-7j5w | High | tar@6.2.1 | arm64 amd64 | 7.5.18 | node-tar: Negative tar entry size causes infinite loop in archive replace |
| GHSA-8x88-c5mf-7j5w | High | tar@7.5.13 | arm64 amd64 | 7.5.18 | node-tar: Negative tar entry size causes infinite loop in archive replace |
| GHSA-qffp-2rhf-9h96 | High | tar@6.2.1 | arm64 amd64 | 7.5.10 | tar has Hardlink Path Traversal via Drive-Relative Linkpath |
| GHSA-38rv-x7px-6hhq | High | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici WebSocket client vulnerable to denial of service via cumulative fragme... |
| GHSA-52cp-r559-cp3m | High | js-yaml@4.1.1 | arm64 amd64 | 4.3.0 | js-yaml: YAML merge-key chains can force quadratic CPU consumption |
| GHSA-rgw5-rvv9-x895 | High | brace-expansion@1.1.12 | arm64 amd64 | 1.1.18 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-202... |
| GHSA-rgw5-rvv9-x895 | High | brace-expansion@2.0.2 | arm64 amd64 | 2.1.4 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-202... |
| GHSA-rgw5-rvv9-x895 | High | brace-expansion@5.0.4 | arm64 amd64 | 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-202... |
| GHSA-6chq-wfr3-2hj9 | High | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: Header Injection via Prototype Pollution |
| GHSA-4c8g-83qw-93j6 | High | fast-uri@3.1.0 | arm64 amd64 | 3.1.3 | fast-uri vulnerable to host confusion via failed IDN canonicalization |
| GHSA-22p9-wv53-3rq4 | High | linkify-it@5.0.0 | arm64 amd64 | 5.0.1 | LinkifyIt#match scan loop has quadratic algorithmic complexity |
| GHSA-8qq5-rm4j-mr97 | High | tar@6.2.1 | arm64 amd64 | 7.5.3 | node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via ... |
| GHSA-hm92-r4w5-c3mj | High | undici@8.1.0 | arm64 amd64 | 8.2.0 | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse |
| GHSA-v245-v573-v5vm | High | linkify-it@5.0.0 | arm64 amd64 | 5.0.2 | linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on... |
| GHSA-mh99-v99m-4gvg | High | brace-expansion@1.1.12 | arm64 amd64 | 1.1.17 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory ... |
| GHSA-mh99-v99m-4gvg | High | brace-expansion@2.0.2 | arm64 amd64 | 2.1.3 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory ... |
| GHSA-mh99-v99m-4gvg | High | brace-expansion@5.0.4 | arm64 amd64 | 5.0.8 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory ... |
| GHSA-3jxr-9vmj-r5cp | High | brace-expansion@1.1.12 | arm64 amd64 | 1.1.16 | brace-expansion: DoS via exponential-time expansion of consecutive non-expand... |
| GHSA-3jxr-9vmj-r5cp | High | brace-expansion@2.0.2 | arm64 amd64 | 2.1.2 | brace-expansion: DoS via exponential-time expansion of consecutive non-expand... |
| GHSA-3jxr-9vmj-r5cp | High | brace-expansion@5.0.4 | arm64 amd64 | 5.0.7 | brace-expansion: DoS via exponential-time expansion of consecutive non-expand... |
| GHSA-4cwx-7wf7-3272 | High | undici@8.1.0 | arm64 amd64 | 8.9.0 | undici vulnerable to cross-user information disclosure and parse-time crash v... |
| GHSA-28wg-ghj8-5hjv | High | nanoid@3.3.12 | arm64 amd64 | 3.3.16 | nanoid: non-secure generators can loop indefinitely with negative size |
| GHSA-2v37-7h3g-55p8 | High | nanoid@3.3.12 | arm64 amd64 | 3.3.18 | nanoid: custom generators can loop indefinitely when size is zero |
| GHSA-28wg-ghj8-5hjv | High | nanoid@5.1.11 | arm64 amd64 | 5.1.16 | nanoid: non-secure generators can loop indefinitely with negative size |
| GHSA-xjpj-3mr7-gcpf | High | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names... |
| GHSA-mwp4-54f8-5fhr | High | ip-address@10.1.0 | arm64 amd64 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers d... |
| GHSA-mwp4-54f8-5fhr | High | ip-address@10.2.0 | arm64 amd64 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers d... |
| GHSA-mwp4-54f8-5fhr | High | ip-address@9.0.5 | arm64 amd64 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers d... |
| GHSA-83g3-92jg-28cx | High | tar@6.2.1 | arm64 amd64 | 7.5.8 | Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in... |
| GHSA-72gw-mp4g-v24j | High | multer@2.1.1 | arm64 amd64 | 2.2.0 | Multer vulnerable to Denial of Service via deeply nested field names |
| GHSA-9ppj-qmqm-q256 | High | tar@6.2.1 | arm64 amd64 | 7.5.11 | node-tar Symlink Path Traversal via Drive-Relative Linkpath |
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| GHSA-v2hh-gcrm-f6hx | High | fast-uri@3.1.0 | arm64 amd64 | 3.1.4 | fast-uri vulnerable to host confusion via literal backslash authority delimiter |
| GHSA-2p49-hgcm-8545 | High | svgo@3.3.3 | arm64 amd64 | 3.3.4 | SVGO removeScripts plugin leaves some executable scripts intact |
| GHSA-r6q2-hw4h-h46w | High | tar@6.2.1 | arm64 amd64 | 7.5.4 | Race Condition in node-tar Path Reservations via Unicode Ligature Collisions ... |
| GHSA-7p8r-x3mc-p8w7 | High | fast-uri@3.1.0 | arm64 amd64 | 3.1.5 | fast-uri vulnerable to host confusion via backslash authority introducer |
| GHSA-fv7c-fp4j-7gwp | High | @babel/plugin-transform-modules-systemjs@7.24.7 | arm64 amd64 | 7.29.4 | @babel/plugin-transform-modules-systemjs generates arbitrary code when compil... |
| GHSA-5p4m-2wfm-xmqj | High | js-yaml@4.1.1 | arm64 amd64 | 4.3.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2... |
| GHSA-p6gq-j5cr-w38f | High | nodemailer@6.10.0 | arm64 amd64 | 9.0.1 | Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAcc... |
| GHSA-p6gq-j5cr-w38f | High | nodemailer@6.9.16 | arm64 amd64 | 9.0.1 | Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAcc... |
| GHSA-p6gq-j5cr-w38f | High | nodemailer@7.0.12 | arm64 amd64 | 9.0.1 | Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAcc... |
| GHSA-p6gq-j5cr-w38f | High | nodemailer@8.0.5 | arm64 amd64 | 9.0.1 | Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAcc... |
| GHSA-r28c-9q8g-f849 | High | postcss@8.4.31 | arm64 amd64 | 8.5.18 | PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL... |
| GHSA-f88m-g3jw-g9cj | High | sharp@0.34.5 | arm64 amd64 | 0.35.0 | sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, C... |
| GHSA-62hf-57xw-28j9 | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: unbounded recursion in toFormData causes DoS via deeply nested request... |
| GHSA-q8wf-6r8g-63ch | Medium | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Denial of Service in the Image Optimization API using SVGs |
| GHSA-3w6x-2g7m-8v23 | Medium | axios@1.15.0 | arm64 amd64 | 1.15.2 | Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `p... |
| GHSA-4c39-4ccg-62r3 | Medium | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Unbounded Server Action payload in Edge runtime |
| GHSA-w9j2-pvgh-6h63 | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatu... |
| GHSA-955p-x3mx-jcvp | Medium | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Unauthenticated disclosure of internal Server Function endpoints |
| GHSA-mm7p-fcc7-pg87 | Medium | nodemailer@6.10.0 | arm64 amd64 | 7.0.7 | Nodemailer: Email to an unintended domain can occur due to Interpretation Con... |
| GHSA-mm7p-fcc7-pg87 | Medium | nodemailer@6.9.16 | arm64 amd64 | 7.0.7 | Nodemailer: Email to an unintended domain can occur due to Interpretation Con... |
| GHSA-f886-m6hf-6m8v | Medium | brace-expansion@1.1.12 | arm64 amd64 | 1.1.13 | brace-expansion: Zero-step sequence causes process hang and memory exhaustion |
| GHSA-f886-m6hf-6m8v | Medium | brace-expansion@2.0.2 | arm64 amd64 | 2.0.3 | brace-expansion: Zero-step sequence causes process hang and memory exhaustion |
| GHSA-f886-m6hf-6m8v | Medium | brace-expansion@5.0.4 | arm64 amd64 | 5.0.5 | brace-expansion: Zero-step sequence causes process hang and memory exhaustion |
| GHSA-378v-28hj-76wf | Medium | bn.js@4.12.2 | arm64 amd64 | 4.12.3 | bn.js affected by an infinite loop |
| GHSA-v2v4-37r5-5v8g | Medium | ip-address@10.1.0 | arm64 amd64 | 10.1.1 | ip-address has XSS in Address6 HTML-emitting methods |
| GHSA-v2v4-37r5-5v8g | Medium | ip-address@9.0.5 | arm64 amd64 | 10.1.1 | ip-address has XSS in Address6 HTML-emitting methods |
| GHSA-9h5v-pfqq-x599 | Medium | ua-parser-js@2.0.9 | arm64 amd64 | 2.0.10 | UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withCl... |
| GHSA-48c2-rrv3-qjmp | Medium | yaml@1.10.2 | arm64 amd64 | 1.10.3 | yaml is vulnerable to Stack Overflow via deeply nested YAML collections |
| GHSA-vf2m-468p-8v99 | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: HTTP adapter streamed responses bypass maxContentLength |
| GHSA-w8wr-v893-vjvp | Medium | tar@6.2.1 | arm64 amd64 | 7.5.18 | node-tar: Process crash via PAX numeric path type confusion |
| GHSA-w8wr-v893-vjvp | Medium | tar@7.5.13 | arm64 amd64 | 7.5.18 | node-tar: Process crash via PAX numeric path type confusion |
| GHSA-w5hq-g745-h8pq | Medium | uuid@9.0.1 | arm64 amd64 | 11.1.1 | uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided |
| GHSA-pr7r-676h-xcf6 | Medium | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici vulnerable to cross-user information disclosure via shared cache white... |
| GHSA-h67p-54hq-rp68 | Medium | js-yaml@4.1.1 | arm64 amd64 | 4.2.0 | JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases |
| GHSA-q8mj-m7cp-5q26 | Medium | qs@6.14.1 | arm64 amd64 | 6.15.2 | qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on nul... |
| GHSA-4633-3j49-mh5q | Medium | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Cache confusion of response bodies for requests with bodies containi... |
| GHSA-68g3-v927-f742 | Medium | next@16.2.6 | arm64 amd64 | 16.2.11 | Next.js: Cache confusion of response bodies for requests with bodies |
| GHSA-f23m-r3pf-42rh | Medium | lodash-es@4.17.23 | arm64 amd64 | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` a... |
| GHSA-m7pr-hjqh-92cm | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: no_proxy bypass via IP alias allows SSRF |
| GHSA-fxqj-rqcc-2cmp | Medium | postcss@8.4.31 | arm64 amd64 | 8.5.23 | PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMa... |
| GHSA-jxxr-4gwj-5jf2 | Medium | brace-expansion@5.0.4 | arm64 amd64 | 5.0.6 | brace-expansion: Large numeric range defeats documented `max` DoS protection |
| GHSA-5c9x-8gcm-mpgx | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedire... |
| GHSA-4xrf-jv44-h6hh | Medium | ip-address@10.2.0 | arm64 amd64 | 10.2.2 | ip-address: a CIDR suffix on the parsed address suppresses special-use classi... |
| GHSA-445q-vr5w-6q77 | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type i... |
| GHSA-22jq-vg5j-6vgg | Medium | ip-address@10.2.0 | arm64 amd64 | 10.2.1 | ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass ... |
| GHSA-gvwx-54wh-qm9j | Medium | tar@6.2.1 | arm64 amd64 | 7.5.17 | node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records |
| GHSA-gvwx-54wh-qm9j | Medium | tar@7.5.13 | arm64 amd64 | 7.5.17 | node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records |
| GHSA-3p4h-7m6x-2hcm | Medium | multer@2.1.1 | arm64 amd64 | 2.2.0 | Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads |
| GHSA-898c-q2cr-xwhg | Medium | axios@1.15.0 | arm64 amd64 | 1.16.0 | axios has DoS & Header Injection via Prototype Pollution Read-Side Gadget... |
| GHSA-p88m-4jfj-68fv | Medium | undici@6.25.0 | arm64 amd64 | 6.27.0 | undici vulnerable to HTTP header injection via Set-Cookie percent-decoding |
| GHSA-p88m-4jfj-68fv | Medium | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici vulnerable to HTTP header injection via Set-Cookie percent-decoding |
| GHSA-2qvq-rjwj-gvw9 | Medium | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has Prototype Pollution Leading to XSS through Partial Template... |
| GHSA-jr45-8vmc-qm54 | Medium | undici@8.1.0 | arm64 amd64 | 8.9.0 | undici vulnerable to cross-user information disclosure via whitespace around ... |
| GHSA-2rp8-mm9q-fp49 | Medium | typeorm@0.3.29 | arm64 amd64 | 0.3.31 | TypeORM: migration:generate template-literal code injection |
| GHSA-xx6v-rp6x-q39c | Medium | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `wit... |
| GHSA-qx2v-qp2m-jg93 | Medium | postcss@8.4.31 | arm64 amd64 | 8.5.10 | PostCSS has XSS via Unescaped </style> in its CSS Stringify Output |
| GHSA-8xcm-r25x-g524 | Medium | undici@6.25.0 | arm64 amd64 | 6.28.0 | undici vulnerable to downstream response desynchronization via retry interceptor |
| GHSA-8xcm-r25x-g524 | Medium | undici@8.1.0 | arm64 amd64 | 8.9.0 | undici vulnerable to downstream response desynchronization via retry interceptor |
| GHSA-vmf3-w455-68vh | Medium | tar@6.2.1 | arm64 amd64 | 7.5.16 | node-tar applies PAX size override to intermediary GNU long-name/long-link he... |
| GHSA-vmf3-w455-68vh | Medium | tar@7.5.13 | arm64 amd64 | 7.5.16 | node-tar applies PAX size override to intermediary GNU long-name/long-link he... |
| GHSA-v3r7-h72x-cjcm | Medium | undici@6.25.0 | arm64 amd64 | 6.28.0 | undici vulnerable to cookie attribute injection via unsanitized domain and un... |
| GHSA-v3r7-h72x-cjcm | Medium | undici@8.1.0 | arm64 amd64 | 8.9.0 | undici vulnerable to cookie attribute injection via unsanitized domain and un... |
| GHSA-m8rv-5g2x-5cg5 | Medium | undici@6.25.0 | arm64 amd64 | 6.28.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property |
| GHSA-m8rv-5g2x-5cg5 | Medium | undici@8.1.0 | arm64 amd64 | 8.9.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property |
| GHSA-42h9-826w-cgv3 | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: Excessive recursion in formDataToJSON can cause denial of service |
| GHSA-7q8q-rj6j-mhjq | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: Nested axios option objects can consume polluted prototype values |
| GHSA-f4gw-2p7v-4548 | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios |
| GHSA-jqh4-m9w3-8hp9 | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength` |
| GHSA-mmx7-hfxf-jppx | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: Prototype pollution gadgets can alter axios request construction |
| GHSA-mwf2-3pr3-8698 | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: HTTP/2 streamed uploads bypass `maxBodyLength` |
| GHSA-pmv8-rq9r-6j72 | Medium | axios@1.15.0 | arm64 amd64 | 1.18.0 | Axios: Deep formToJSON Key Recursion Can Cause Denial of Service |
| GHSA-7rx3-28cr-v5wh | Medium | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupS... |
| GHSA-268h-hp4c-crq3 | Medium | nodemailer@6.10.0 | arm64 amd64 | 8.0.9 | Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitr... |
| GHSA-r7g4-qg5f-qqm2 | Medium | nodemailer@6.10.0 | arm64 amd64 | 8.0.8 | Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables... |
| GHSA-vvjj-xcjg-gr5g | Medium | nodemailer@6.10.0 | arm64 amd64 | 8.0.5 | Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Op... |
| GHSA-wqvq-jvpq-h66f | Medium | nodemailer@6.10.0 | arm64 amd64 | 8.0.9 | Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess duri... |
| GHSA-268h-hp4c-crq3 | Medium | nodemailer@6.9.16 | arm64 amd64 | 8.0.9 | Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitr... |
| GHSA-r7g4-qg5f-qqm2 | Medium | nodemailer@6.9.16 | arm64 amd64 | 8.0.8 | Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables... |
| GHSA-vvjj-xcjg-gr5g | Medium | nodemailer@6.9.16 | arm64 amd64 | 8.0.5 | Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Op... |
| GHSA-wqvq-jvpq-h66f | Medium | nodemailer@6.9.16 | arm64 amd64 | 8.0.9 | Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess duri... |
| GHSA-268h-hp4c-crq3 | Medium | nodemailer@7.0.12 | arm64 amd64 | 8.0.9 | Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitr... |
| GHSA-r7g4-qg5f-qqm2 | Medium | nodemailer@7.0.12 | arm64 amd64 | 8.0.8 | Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables... |
| GHSA-vvjj-xcjg-gr5g | Medium | nodemailer@7.0.12 | arm64 amd64 | 8.0.5 | Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Op... |
| GHSA-wqvq-jvpq-h66f | Medium | nodemailer@7.0.12 | arm64 amd64 | 8.0.9 | Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess duri... |
| GHSA-268h-hp4c-crq3 | Medium | nodemailer@8.0.5 | arm64 amd64 | 8.0.9 | Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitr... |
| GHSA-r7g4-qg5f-qqm2 | Medium | nodemailer@8.0.5 | arm64 amd64 | 8.0.8 | Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables... |
| GHSA-wqvq-jvpq-h66f | Medium | nodemailer@8.0.5 | arm64 amd64 | 8.0.9 | Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess duri... |
| GHSA-r292-9mhp-454m | Medium | tar@6.2.1 | arm64 amd64 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable sta... |
| GHSA-r292-9mhp-454m | Medium | tar@7.5.13 | arm64 amd64 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable sta... |
| GHSA-w7fw-mjwx-w883 | Low | qs@6.14.1 | arm64 amd64 | 6.14.2 | qs's arrayLimit bypass in comma parsing allows denial of service |
| GHSA-7gmj-h9xc-mcxc | Low | mailparser@3.7.2 | arm64 amd64 | 3.9.3 | mailparser vulnerable to Cross-site Scripting |
| GHSA-v422-hmwv-36x6 | Low | body-parser@2.2.2 | arm64 amd64 | 2.3.0 | body-parser vulnerable to denial of service when invalid limit value silently... |
| GHSA-g8m3-5g58-fq7m | Low | undici@6.25.0 | arm64 amd64 | 6.27.0 | undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive s... |
| GHSA-g8m3-5g58-fq7m | Low | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive s... |
| GHSA-35p6-xmwp-9g52 | Low | undici@6.25.0 | arm64 amd64 | 6.27.0 | undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse |
| GHSA-35p6-xmwp-9g52 | Low | undici@8.1.0 | arm64 amd64 | 8.5.0 | undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse |
| GHSA-xhjh-pmcv-23jw | Low | axios@1.15.0 | arm64 amd64 | 1.15.1 | Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams |
| GHSA-4x5r-pxfx-6jf8 | Low | @babel/core@7.29.0 | arm64 amd64 | 7.29.6 | @babel/core: Arbitrary File Read via sourceMappingURL Comment |
| GHSA-vpq2-c234-7xj6 | Low | @tootallnate/once@1.1.2 | arm64 amd64 | 2.0.1 | @tootallnate/once vulnerable to Incorrect Control Flow Scoping |
| GHSA-442j-39wm-28r2 | Low | handlebars@4.7.8 | arm64 amd64 | 4.7.9 | Handlebars.js has a Property Access Validation Bypass in container.lookup |
| GHSA-c7w3-x93f-qmm8 | Low | nodemailer@6.10.0 | arm64 amd64 | 8.0.4 | Nodemailer has SMTP command injection due to unsanitized `envelope.size` para... |
| GHSA-c7w3-x93f-qmm8 | Low | nodemailer@6.9.16 | arm64 amd64 | 8.0.4 | Nodemailer has SMTP command injection due to unsanitized `envelope.size` para... |
| GHSA-c7w3-x93f-qmm8 | Low | nodemailer@7.0.12 | arm64 amd64 | 8.0.4 | Nodemailer has SMTP command injection due to unsanitized `envelope.size` para... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| GHSA-8g4q-xg66-9fp4 | High | System.Text.Json@6.0.9 | arm64 amd64 | 6.0.10 | Microsoft Security Advisory CVE-2024-43485 | .NET Denial of Service Vulnerabi... |
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| GHSA-59j7-ghrg-fj52 | Medium | Microsoft.IdentityModel.JsonWebTokens@6.8.0 | arm64 amd64 | 6.34.0 | Microsoft ASP.NET Core project templates vulnerable to denial of service |
| GHSA-59j7-ghrg-fj52 | Medium | System.IdentityModel.Tokens.Jwt@6.8.0 | arm64 amd64 | 6.34.0 | Microsoft ASP.NET Core project templates vulnerable to denial of service |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2025-15367 | Medium | python-3.14@3.14.7-r1 | arm64 amd64 | Unpatched | The poplib module, when passed a user-controlled command, can have additional... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | openssl@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE ID | Severity | Package | Arch | Fixed Version | Description |
|---|---|---|---|---|---|
| CVE-2026-54876 | High | libcrypto3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| CVE-2026-54876 | High | libssl3@3.6.3-r4 | arm64 amd64 | Unpatched | Issue summary: A malicious TLS server can cause a memory leak in a TLS client... |
| GHSA-82j2-j2ch-gfr8 | High | rustls-webpki@0.101.7 | arm64 amd64 | 0.103.13 | rustls-webpki: Denial of service via panic on malformed CRL BIT STRING |
| GHSA-965h-392x-2mh5 | Low | rustls-webpki@0.101.7 | arm64 amd64 | 0.103.12 | webpki: Name constraints for URI names were incorrectly accepted |
| GHSA-xgp8-3hg3-c2mh | Low | rustls-webpki@0.101.7 | arm64 amd64 | 0.103.12 | webpki: Name constraints were accepted for certificates asserting a wildcard ... |