Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-rcw4-f5rp-g42v
  • npm/adm-zip
adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0 1 hour ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-j5f4-cc29-5x44
  • npm/adm-zip
adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation 1 hour ago
  • Fix available
  • Severity - 7.1 (High)
GHSA-8vvx-rff5-p5rq
  • npm/nodemailer
Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS 1 hour ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-pmjh-fq2x-6v4x
  • npm/undici
undici vulnerable to Denial of Service via orphaned RetryHandler response body 1 hour ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-r53p-7pc4-xj5r
  • npm/undici
undici vulnerable to downstream response splitting via retry interceptor 1 hour ago
  • Fix available
  • Severity - 3.7 (Low)
GHSA-rfgv-xxqx-mfg5
  • npm/undici
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol 1 hour ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-3xpg-4rpp-hhhm
  • npm/undici
undici vulnerable to Denial of Service via unbounded decompression of compressed responses 1 hour ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-2jfj-6hjv-fm6j
  • npm/undici
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches 1 hour ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2gqq-gqf2-x968
  • npm/undici
undici vulnerable to response truncation via oversized chunked responses in the dump interceptor 1 hour ago
  • Fix available
  • Severity - 3.7 (Low)
GHSA-w293-vg96-wgc3
  • npm/undici
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool 2 hours ago
  • Fix available
  • Severity - 7.4 (High)
GHSA-8436-99hf-9mmv
  • npm/undici
undici vulnerable to caching and replay of unsafe HTTP method responses 2 hours ago
  • Fix available
  • Severity - 3.7 (Low)
GHSA-vp8m-p9jh-q5pm
  • npm/undici
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors 2 hours ago
  • Fix available
  • Severity - 7.4 (High)
GHSA-rx4f-c7p8-82vq
  • npm/undici
undici vulnerable to Denial of Service via WebSocketStream unclean close 2 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-6h2x-m376-mqjq
  • npm/joi
joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()` 2 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-vv43-5jgx-7qv8
  • npm/electron
Electron: Local race condition in Squirrel.Mac update installation on macOS 2 hours ago
  • Fix available
  • Severity - 6.7 (Medium)
GHSA-hq2x-r82h-9wj4
  • npm/electron
Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab 2 hours ago
  • Fix available
  • Severity - 8.2 (High)