Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-f49m-vf83-692w
  • npm/i18next-http-middleware
i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names 25 Jun
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-48714
  • github.com/i18next/i18next-http-middleware
i18next-http-middleware missingKeyHandler does not reject keys whose segments contain prototype-polluting names 15 Jun
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-42353
  • github.com/i18next/i18next-http-middleware
Path traversal / SSRF in i18next-http-middleware via user-controlled language and namespace parameters 08 May
  • Fix available
  • Severity - 8.2 (High)
CVE-2026-41683
  • github.com/i18next/i18next-http-middleware
HTTP response splitting and DoS in i18next-http-middleware via unsanitised Content-Language header 08 May
  • Fix available
  • Severity - 8.6 (High)
CVE-2026-41690
  • github.com/i18next/i18next-http-middleware
Prototype pollution and path traversal in i18next-http-middleware via user-controlled language and namespace parameters 08 May
  • Fix available
  • Severity - 8.6 (High)
GHSA-jfgf-83c5-2c4m
  • npm/i18next-http-middleware
i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace parameters 29 Apr
  • Fix available
  • Severity - 8.2 (High)
GHSA-c3h8-g69v-pjrg
  • npm/i18next-http-middleware
i18next-http-middleware: HTTP response splitting and DoS via unsanitised Content-Language header 22 Apr
  • Fix available
  • Severity - 8.6 (High)
GHSA-5fgg-jcpf-8jjw
  • npm/i18next-http-middleware
i18next-http-middleware: Prototype pollution and path traversal via user-controlled language and namespace parameters 22 Apr
  • Fix available
  • Severity - 8.6 (High)