Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2247785
AlmaLinux
5993
Alpaquita
16181
Alpine
4656
Android
3707
Azure Linux
17973
BellSoft Hardened Containers
771
Bitnami
9525
Chainguard
1051223
CleanStart
5486
CRAN
14
crates.io
2768
Debian
69491
Echo
7849
GHC
3
GIT
109526
GitHub Actions
55
Go
9336
Hackage
33
Hex
367
Julia
1713
Linux
30182
Mageia
6239
Maven
7055
MinimOS
149275
npm
229295
NuGet
1872
opam
29
openEuler
8900
openSUSE
14658
OSS-Fuzz
4020
Packagist
7103
Pub
11
PyPI
25503
Red Hat
23557
Rocky Linux
4362
Root
19696
RubyGems
5369
SUSE
23494
SwiftURL
61
TuxCare
10047
Ubuntu
66140
VSCode
21
Wolfi
294226
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-f49m-vf83-692w
npm/i18next-http-middleware
i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names
25 Jun
Fix available
Severity - 9.1 (Critical)
CVE-2026-48714
github.com/i18next/i18next-http-middleware
i18next-http-middleware missingKeyHandler does not reject keys whose segments contain prototype-polluting names
15 Jun
Fix available
Severity - 9.1 (Critical)
CVE-2026-42353
github.com/i18next/i18next-http-middleware
Path traversal / SSRF in i18next-http-middleware via user-controlled language and namespace parameters
08 May
Fix available
Severity - 8.2 (High)
CVE-2026-41683
github.com/i18next/i18next-http-middleware
HTTP response splitting and DoS in i18next-http-middleware via unsanitised Content-Language header
08 May
Fix available
Severity - 8.6 (High)
CVE-2026-41690
github.com/i18next/i18next-http-middleware
Prototype pollution and path traversal in i18next-http-middleware via user-controlled language and namespace parameters
08 May
Fix available
Severity - 8.6 (High)
GHSA-jfgf-83c5-2c4m
npm/i18next-http-middleware
i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace parameters
29 Apr
Fix available
Severity - 8.2 (High)
GHSA-c3h8-g69v-pjrg
npm/i18next-http-middleware
i18next-http-middleware: HTTP response splitting and DoS via unsanitised Content-Language header
22 Apr
Fix available
Severity - 8.6 (High)
GHSA-5fgg-jcpf-8jjw
npm/i18next-http-middleware
i18next-http-middleware: Prototype pollution and path traversal via user-controlled language and namespace parameters
22 Apr
Fix available
Severity - 8.6 (High)
Vulnerability Database - OSV