[go: up one dir, main page]

Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-11518
  • npm/exnesss
Malicious code in exnesss (npm) 3 hours ago
  • No fix available
MAL-2026-11517
  • npm/internallib_v688
Malicious code in internallib_v688 (npm) 9 hours ago
  • No fix available
MAL-2026-11515
  • npm/@zzzgenesis00/bip39-generator
Malicious code in @zzzgenesis00/bip39-generator (npm) 10 hours ago
  • No fix available
MAL-2026-11512
  • npm/internallib_v524
Malicious code in internallib_v524 (npm) 16 hours ago
  • No fix available
GHSA-v8fg-2rw7-q452
  • npm/sequelize
Sequelize: SQL Injection (Oracle DB) 16 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-8j4g-w8fx-2239
  • npm/hono
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers 16 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-mwp4-54f8-5fhr
  • npm/ip-address
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass 16 hours ago
  • Fix available
  • Severity - 7.7 (High)
GHSA-4xrf-jv44-h6hh
  • npm/ip-address
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks 16 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-22jq-vg5j-6vgg
  • npm/ip-address
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks 17 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-m8rv-5g2x-5cg5
  • npm/undici
undici vulnerable to CRLF Injection via blob-like body 'type' property 17 hours ago
  • Fix available
  • Severity - 4.2 (Medium)
GHSA-jr45-8vmc-qm54
  • npm/undici
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives 17 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-v3r7-h72x-cjcm
  • npm/undici
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields 17 hours ago
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-8xcm-r25x-g524
  • npm/undici
undici vulnerable to downstream response desynchronization via retry interceptor 17 hours ago
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-4cwx-7wf7-3272
  • npm/undici
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives 17 hours ago
  • Fix available
  • Severity - 7.4 (High)
GHSA-7p8r-x3mc-p8w7
  • npm/fast-uri
fast-uri vulnerable to host confusion via backslash authority introducer 17 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-2m8v-j782-fhvr
  • npm/socket.io-parser
Socket.IO: Zero-attachment Memory Exhaustion 17 hours ago
  • Fix available
  • Severity - 7.5 (High)