Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-13995
  • npm/@dsp-next-gen-ui/needs-review
Malicious code in @dsp-next-gen-ui/needs-review (npm) 5 days ago
  • No fix available
MAL-2026-11609
  • npm/@onereach/or-browser-next
Malicious code in @onereach/or-browser-next (npm) 04 Aug
  • No fix available
MAL-2026-11965
  • npm/conv-context-next
Malicious code in conv-context-next (npm) 04 Aug
  • No fix available
MAL-2026-11611
  • npm/@onereach/or-file-uploader-next
Malicious code in @onereach/or-file-uploader-next (npm) 04 Aug
  • No fix available
MAL-2026-11069
  • npm/clerk-next-fix-auth-protection
Malicious code in clerk-next-fix-auth-protection (npm) 24 Jul
  • No fix available
GHSA-8fpg-xm3f-6cx3
  • npm/next-auth
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error) 23 Jul
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-xmf8-cvqr-rfgj
  • npm/@auth/core
  • npm/next-auth
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers 23 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-7rqj-j65f-68wh
  • npm/@auth/core
  • npm/next-auth
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass 23 Jul
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-x445-f3h2-j279
  • npm/@auth/core
  • npm/next-auth
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them 23 Jul
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-89xv-2m56-2m9x
  • npm/next
Next.js: Server-Side Request Forgery in Server Actions on custom servers 22 Jul
  • Fix available
  • Severity - 8.3 (High)
GHSA-68g3-v927-f742
  • npm/next
Next.js: Cache confusion of response bodies for requests with bodies 22 Jul
  • Fix available
  • Severity - 6.0 (Medium)
GHSA-4633-3j49-mh5q
  • npm/next
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences 22 Jul
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-4c39-4ccg-62r3
  • npm/next
Next.js: Unbounded Server Action payload in Edge runtime 22 Jul
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-p9j2-gv94-2wf4
  • npm/next
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname 22 Jul
  • Fix available
  • Severity - 8.3 (High)
GHSA-q8wf-6r8g-63ch
  • npm/next
Next.js: Denial of Service in the Image Optimization API using SVGs 22 Jul
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-955p-x3mx-jcvp
  • npm/next
Next.js: Unauthenticated disclosure of internal Server Function endpoints 22 Jul
  • Fix available
  • Severity - 6.3 (Medium)