| @tootallnate/once |
CVE-2026-3449 |
LOW |
2.0.0 |
3.0.1 |
https://access.redhat.com/security/cve/CVE-2026-3449
https://github.com/TooTallNate/once
https://github.com/TooTallNate/once/commit/b9f43cc5259bee2952d91ad3cdbd201a82df448a
https://github.com/TooTallNate/once/issues/8
https://nvd.nist.gov/vuln/detail/CVE-2026-3449
https://security.snyk.io/vuln/SNYK-JS-TOOTALLNATEONCE-15250612
https://www.cve.org/CVERecord?id=CVE-2026-3449
|
| ajv |
CVE-2025-69873 |
MEDIUM |
6.12.6 |
8.18.0, 6.14.0 |
https://access.redhat.com/security/cve/CVE-2025-69873
https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md
https://github.com/advisories/GHSA-2g4f-4pwh-qvx6
https://github.com/ajv-validator/ajv
https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5
https://github.com/ajv-validator/ajv/pull/2586
https://github.com/ajv-validator/ajv/pull/2588
https://github.com/ajv-validator/ajv/pull/2590
https://github.com/ajv-validator/ajv/releases/tag/v6.14.0
https://github.com/ajv-validator/ajv/releases/tag/v8.18.0
https://github.com/github/advisory-database/pull/6991
https://nvd.nist.gov/vuln/detail/CVE-2025-69873
https://www.cve.org/CVERecord?id=CVE-2025-69873
|
| brace-expansion |
CVE-2026-33750 |
MEDIUM |
1.1.11 |
5.0.5, 3.0.2, 2.0.3, 1.1.13 |
https://access.redhat.com/security/cve/CVE-2026-33750
https://github.com/juliangruber/brace-expansion
https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L107-L113
https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L184
https://github.com/juliangruber/brace-expansion/commit/311ac0d54994158c0a384e286a7d6cbb17ee8ed5
https://github.com/juliangruber/brace-expansion/commit/7fd684f89fdde3549563d0a6522226a9189472a2
https://github.com/juliangruber/brace-expansion/commit/b9cacd9e55e7a1fa588fe4b7bb1159d52f1d902a
https://github.com/juliangruber/brace-expansion/issues/98
https://github.com/juliangruber/brace-expansion/pull/95
https://github.com/juliangruber/brace-expansion/pull/96
https://github.com/juliangruber/brace-expansion/pull/97
https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-f886-m6hf-6m8v
https://nvd.nist.gov/vuln/detail/CVE-2026-33750
https://www.cve.org/CVERecord?id=CVE-2026-33750
|
| brace-expansion |
CVE-2026-33750 |
MEDIUM |
1.1.11 |
5.0.5, 3.0.2, 2.0.3, 1.1.13 |
https://access.redhat.com/security/cve/CVE-2026-33750
https://github.com/juliangruber/brace-expansion
https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L107-L113
https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L184
https://github.com/juliangruber/brace-expansion/commit/311ac0d54994158c0a384e286a7d6cbb17ee8ed5
https://github.com/juliangruber/brace-expansion/commit/7fd684f89fdde3549563d0a6522226a9189472a2
https://github.com/juliangruber/brace-expansion/commit/b9cacd9e55e7a1fa588fe4b7bb1159d52f1d902a
https://github.com/juliangruber/brace-expansion/issues/98
https://github.com/juliangruber/brace-expansion/pull/95
https://github.com/juliangruber/brace-expansion/pull/96
https://github.com/juliangruber/brace-expansion/pull/97
https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-f886-m6hf-6m8v
https://nvd.nist.gov/vuln/detail/CVE-2026-33750
https://www.cve.org/CVERecord?id=CVE-2026-33750
|
| brace-expansion |
CVE-2025-5889 |
LOW |
1.1.11 |
2.0.2, 1.1.12, 3.0.1, 4.0.1 |
https://access.redhat.com/security/cve/CVE-2025-5889
https://gist.github.com/mmmsssttt404/37a40ce7d6e5ca604858fe30814d9466
https://github.com/juliangruber/brace-expansion
https://github.com/juliangruber/brace-expansion/commit/0b6a9781e18e9d2769bb2931f4856d1360243ed2
https://github.com/juliangruber/brace-expansion/commit/15f9b3c75ebf5988198241fecaebdc45eff28a9f
https://github.com/juliangruber/brace-expansion/commit/36603d5f3599a37af9e85eda30acd7d28599c36e
https://github.com/juliangruber/brace-expansion/commit/c3c73c8b088defc70851843be88ccc3af08e7217
https://github.com/juliangruber/brace-expansion/pull/65/commits/a5b98a4f30d7813266b221435e1eaaf25a1b0ac5
https://github.com/juliangruber/brace-expansion/releases/tag/v4.0.1
https://nvd.nist.gov/vuln/detail/CVE-2025-5889
https://vuldb.com/?ctiid.311660
https://vuldb.com/?id.311660
https://vuldb.com/?submit.585717
https://www.cve.org/CVERecord?id=CVE-2025-5889
|
| brace-expansion |
CVE-2025-5889 |
LOW |
1.1.11 |
2.0.2, 1.1.12, 3.0.1, 4.0.1 |
https://access.redhat.com/security/cve/CVE-2025-5889
https://gist.github.com/mmmsssttt404/37a40ce7d6e5ca604858fe30814d9466
https://github.com/juliangruber/brace-expansion
https://github.com/juliangruber/brace-expansion/commit/0b6a9781e18e9d2769bb2931f4856d1360243ed2
https://github.com/juliangruber/brace-expansion/commit/15f9b3c75ebf5988198241fecaebdc45eff28a9f
https://github.com/juliangruber/brace-expansion/commit/36603d5f3599a37af9e85eda30acd7d28599c36e
https://github.com/juliangruber/brace-expansion/commit/c3c73c8b088defc70851843be88ccc3af08e7217
https://github.com/juliangruber/brace-expansion/pull/65/commits/a5b98a4f30d7813266b221435e1eaaf25a1b0ac5
https://github.com/juliangruber/brace-expansion/releases/tag/v4.0.1
https://nvd.nist.gov/vuln/detail/CVE-2025-5889
https://vuldb.com/?ctiid.311660
https://vuldb.com/?id.311660
https://vuldb.com/?submit.585717
https://www.cve.org/CVERecord?id=CVE-2025-5889
|
| brace-expansion |
CVE-2026-33750 |
MEDIUM |
2.0.1 |
5.0.5, 3.0.2, 2.0.3, 1.1.13 |
https://access.redhat.com/security/cve/CVE-2026-33750
https://github.com/juliangruber/brace-expansion
https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L107-L113
https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L184
https://github.com/juliangruber/brace-expansion/commit/311ac0d54994158c0a384e286a7d6cbb17ee8ed5
https://github.com/juliangruber/brace-expansion/commit/7fd684f89fdde3549563d0a6522226a9189472a2
https://github.com/juliangruber/brace-expansion/commit/b9cacd9e55e7a1fa588fe4b7bb1159d52f1d902a
https://github.com/juliangruber/brace-expansion/issues/98
https://github.com/juliangruber/brace-expansion/pull/95
https://github.com/juliangruber/brace-expansion/pull/96
https://github.com/juliangruber/brace-expansion/pull/97
https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-f886-m6hf-6m8v
https://nvd.nist.gov/vuln/detail/CVE-2026-33750
https://www.cve.org/CVERecord?id=CVE-2026-33750
|
| brace-expansion |
CVE-2025-5889 |
LOW |
2.0.1 |
2.0.2, 1.1.12, 3.0.1, 4.0.1 |
https://access.redhat.com/security/cve/CVE-2025-5889
https://gist.github.com/mmmsssttt404/37a40ce7d6e5ca604858fe30814d9466
https://github.com/juliangruber/brace-expansion
https://github.com/juliangruber/brace-expansion/commit/0b6a9781e18e9d2769bb2931f4856d1360243ed2
https://github.com/juliangruber/brace-expansion/commit/15f9b3c75ebf5988198241fecaebdc45eff28a9f
https://github.com/juliangruber/brace-expansion/commit/36603d5f3599a37af9e85eda30acd7d28599c36e
https://github.com/juliangruber/brace-expansion/commit/c3c73c8b088defc70851843be88ccc3af08e7217
https://github.com/juliangruber/brace-expansion/pull/65/commits/a5b98a4f30d7813266b221435e1eaaf25a1b0ac5
https://github.com/juliangruber/brace-expansion/releases/tag/v4.0.1
https://nvd.nist.gov/vuln/detail/CVE-2025-5889
https://vuldb.com/?ctiid.311660
https://vuldb.com/?id.311660
https://vuldb.com/?submit.585717
https://www.cve.org/CVERecord?id=CVE-2025-5889
|
| diff |
CVE-2026-24001 |
LOW |
5.1.0 |
8.0.3, 5.2.2, 4.0.4, 3.5.1 |
https://access.redhat.com/security/cve/CVE-2026-24001
https://github.com/kpdecker/jsdiff
https://github.com/kpdecker/jsdiff/commit/15a1585230748c8ae6f8274c202e0c87309142f5
https://github.com/kpdecker/jsdiff/issues/653
https://github.com/kpdecker/jsdiff/pull/649
https://github.com/kpdecker/jsdiff/security/advisories/GHSA-73rr-hh4g-fpgx
https://nvd.nist.gov/vuln/detail/CVE-2026-24001
https://www.cve.org/CVERecord?id=CVE-2026-24001
|
| flatted |
CVE-2026-32141 |
HIGH |
3.2.6 |
3.4.0 |
https://access.redhat.com/security/cve/CVE-2026-32141
https://github.com/WebReflection/flatted
https://github.com/WebReflection/flatted/commit/7eb65d857e1a40de11c47461cdbc8541449f0606
https://github.com/WebReflection/flatted/pull/88
https://github.com/WebReflection/flatted/security/advisories/GHSA-25h7-pfq9-p65f
https://nvd.nist.gov/vuln/detail/CVE-2026-32141
https://www.cve.org/CVERecord?id=CVE-2026-32141
|
| flatted |
CVE-2026-33228 |
HIGH |
3.2.6 |
3.4.2 |
https://access.redhat.com/security/cve/CVE-2026-33228
https://github.com/WebReflection/flatted
https://github.com/WebReflection/flatted/commit/885ddcc33cf9657caf38c57c7be45ae1c5272802
https://github.com/WebReflection/flatted/releases/tag/v3.4.2
https://github.com/WebReflection/flatted/security/advisories/GHSA-rf6f-7fwh-wjgh
https://nvd.nist.gov/vuln/detail/CVE-2026-33228
https://www.cve.org/CVERecord?id=CVE-2026-33228
|
| handlebars |
CVE-2026-33937 |
CRITICAL |
4.7.8 |
4.7.9 |
https://access.redhat.com/security/cve/CVE-2026-33937
https://github.com/handlebars-lang/handlebars.js
https://github.com/handlebars-lang/handlebars.js/commit/68d8df5a88e0a26fe9e6084c5c6aaebe67b07da2
https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.9
https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-2w6w-674q-4c4q
https://nvd.nist.gov/vuln/detail/CVE-2026-33937
https://www.cve.org/CVERecord?id=CVE-2026-33937
|
| handlebars |
CVE-2026-33938 |
HIGH |
4.7.8 |
4.7.9 |
https://access.redhat.com/security/cve/CVE-2026-33938
https://github.com/handlebars-lang/handlebars.js
https://github.com/handlebars-lang/handlebars.js/commit/68d8df5a88e0a26fe9e6084c5c6aaebe67b07da2
https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.9
https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-3mfm-83xf-c92r
https://nvd.nist.gov/vuln/detail/CVE-2026-33938
https://www.cve.org/CVERecord?id=CVE-2026-33938
|
| handlebars |
CVE-2026-33939 |
HIGH |
4.7.8 |
4.7.9 |
https://access.redhat.com/security/cve/CVE-2026-33939
https://github.com/handlebars-lang/handlebars.js
https://github.com/handlebars-lang/handlebars.js/commit/68d8df5a88e0a26fe9e6084c5c6aaebe67b07da2
https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.9
https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-9cx6-37pm-9jff
https://nvd.nist.gov/vuln/detail/CVE-2026-33939
https://www.cve.org/CVERecord?id=CVE-2026-33939
|
| handlebars |
CVE-2026-33940 |
HIGH |
4.7.8 |
4.7.9 |
https://access.redhat.com/security/cve/CVE-2026-33940
https://github.com/handlebars-lang/handlebars.js
https://github.com/handlebars-lang/handlebars.js/commit/68d8df5a88e0a26fe9e6084c5c6aaebe67b07da2
https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.9
https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-xhpv-hc6g-r9c6
https://nvd.nist.gov/vuln/detail/CVE-2026-33940
https://www.cve.org/CVERecord?id=CVE-2026-33940
|
| handlebars |
CVE-2026-33941 |
HIGH |
4.7.8 |
4.7.9 |
https://access.redhat.com/security/cve/CVE-2026-33941
https://github.com/handlebars-lang/handlebars.js
https://github.com/handlebars-lang/handlebars.js/commit/68d8df5a88e0a26fe9e6084c5c6aaebe67b07da2
https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.9
https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-xjpj-3mr7-gcpf
https://nvd.nist.gov/vuln/detail/CVE-2026-33941
https://www.cve.org/CVERecord?id=CVE-2026-33941
|
| handlebars |
CVE-2026-33916 |
MEDIUM |
4.7.8 |
4.7.9 |
https://access.redhat.com/security/cve/CVE-2026-33916
https://github.com/handlebars-lang/handlebars.js
https://github.com/handlebars-lang/handlebars.js/commit/68d8df5a88e0a26fe9e6084c5c6aaebe67b07da2
https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.9
https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-2qvq-rjwj-gvw9
https://nvd.nist.gov/vuln/detail/CVE-2021-23369
https://nvd.nist.gov/vuln/detail/CVE-2021-23383
https://nvd.nist.gov/vuln/detail/CVE-2026-33916
https://www.cve.org/CVERecord?id=CVE-2026-33916
|
| handlebars |
GHSA-7rx3-28cr-v5wh |
MEDIUM |
4.7.8 |
4.7.9 |
https://github.com/advisories/GHSA-765h-qjxv-5f44
https://github.com/handlebars-lang/handlebars.js
https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.9
https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-7rx3-28cr-v5wh
|
| handlebars |
GHSA-442j-39wm-28r2 |
LOW |
4.7.8 |
4.7.9 |
https://github.com/handlebars-lang/handlebars.js
https://github.com/handlebars-lang/handlebars.js/commit/68d8df5a88e0a26fe9e6084c5c6aaebe67b07da2
https://github.com/handlebars-lang/handlebars.js/releases/tag/v4.7.9
https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-442j-39wm-28r2
|
| ip |
CVE-2024-29415 |
HIGH |
2.0.0 |
no fix available |
https://access.redhat.com/security/cve/CVE-2024-29415
https://cosmosofcyberspace.github.io/npm_ip_cve/npm_ip_cve.html
https://github.com/indutny/node-ip
https://github.com/indutny/node-ip/issues/150
https://github.com/indutny/node-ip/pull/143
https://github.com/indutny/node-ip/pull/144
https://nvd.nist.gov/vuln/detail/CVE-2024-29415
https://security.netapp.com/advisory/ntap-20250117-0010
https://security.netapp.com/advisory/ntap-20250117-0010/
https://www.cve.org/CVERecord?id=CVE-2024-29415
|
| ip |
CVE-2023-42282 |
LOW |
2.0.0 |
2.0.1, 1.1.9 |
https://access.redhat.com/security/cve/CVE-2023-42282
https://cosmosofcyberspace.github.io/npm_ip_cve/npm_ip_cve.html
https://github.com/JoshGlazebrook/socks/issues/93#issue-2128357447
https://github.com/github/advisory-database/pull/3504#issuecomment-1937179999
https://github.com/indutny/node-ip
https://github.com/indutny/node-ip/commit/32f468f1245574785ec080705737a579be1223aa
https://github.com/indutny/node-ip/commit/6a3ada9b471b09d5f0f5be264911ab564bf67894
https://github.com/indutny/node-ip/pull/138
https://huntr.com/bounties/bfc3b23f-ddc0-4ee7-afab-223b07115ed3/
https://nvd.nist.gov/vuln/detail/CVE-2023-42282
https://security.netapp.com/advisory/ntap-20240315-0008/
https://ubuntu.com/security/notices/USN-6643-1
https://www.bleepingcomputer.com/news/security/dev-rejects-cve-severity-makes-his-github-repo-read-only/
https://www.cve.org/CVERecord?id=CVE-2023-42282
|
| jose |
CVE-2024-28176 |
MEDIUM |
4.14.4 |
4.15.5, 2.0.7 |
https://access.redhat.com/errata/RHSA-2024:9181
https://access.redhat.com/security/cve/CVE-2024-28176
https://bugzilla.redhat.com/2268820
https://bugzilla.redhat.com/2270538
https://bugzilla.redhat.com/show_bug.cgi?id=2268820
https://bugzilla.redhat.com/show_bug.cgi?id=2270538
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-50967
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28176
https://errata.almalinux.org/9/ALSA-2024-9181.html
https://errata.rockylinux.org/RLSA-2024:9181
https://github.com/panva/jose
https://github.com/panva/jose/commit/02a65794f7873cdaf12e81e80ad076fcdc4a9314
https://github.com/panva/jose/commit/1b91d88d2f8233f3477a5f4579aa5f8057b2ee8b
https://github.com/panva/jose/security/advisories/GHSA-hhhv-q57g-882q
https://linux.oracle.com/cve/CVE-2024-28176.html
https://linux.oracle.com/errata/ELSA-2024-9181.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I6MMWFBOXJA6ZCXNVPDFJ4XMK5PVG5RG
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I6MMWFBOXJA6ZCXNVPDFJ4XMK5PVG5RG/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KXKGNCRU7OTM5AHC7YIYBNOWI742PRMY
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KXKGNCRU7OTM5AHC7YIYBNOWI742PRMY/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UG5FSEYJ3GP27FZXC5YAAMMEC5XWKJHG
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UG5FSEYJ3GP27FZXC5YAAMMEC5XWKJHG/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UJO2U5ACZVACNQXJ5EBRFLFW6DP5BROY
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UJO2U5ACZVACNQXJ5EBRFLFW6DP5BROY/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XJDO5VSIAOGT2WP63AXAAWNRSVJCNCRH
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XJDO5VSIAOGT2WP63AXAAWNRSVJCNCRH/
https://nvd.nist.gov/vuln/detail/CVE-2024-28176
https://www.cve.org/CVERecord?id=CVE-2024-28176
|
| lodash |
CVE-2025-13465 |
MEDIUM |
4.17.21 |
4.17.23 |
https://access.redhat.com/errata/RHSA-2026:2452
https://access.redhat.com/security/cve/CVE-2025-13465
https://bugzilla.redhat.com/2431740
https://errata.almalinux.org/9/ALSA-2026-2452.html
https://github.com/lodash/lodash
https://github.com/lodash/lodash/commit/edadd452146f7e4bad4ea684e955708931d84d81
https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg
https://linux.oracle.com/cve/CVE-2025-13465.html
https://linux.oracle.com/errata/ELSA-2026-2452.html
https://nvd.nist.gov/vuln/detail/CVE-2025-13465
https://www.cve.org/CVERecord?id=CVE-2025-13465
|
| minimatch |
CVE-2026-26996 |
HIGH |
3.1.2 |
10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3 |
https://access.redhat.com/security/cve/CVE-2026-26996
https://github.com/isaacs/minimatch
https://github.com/isaacs/minimatch/commit/2e111f3a79abc00fa73110195de2c0f2351904f5
https://github.com/isaacs/minimatch/security/advisories/GHSA-3ppc-4f35-3m26
https://nvd.nist.gov/vuln/detail/CVE-2026-26996
https://www.cve.org/CVERecord?id=CVE-2026-26996
|
| minimatch |
CVE-2026-26996 |
HIGH |
3.1.2 |
10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3 |
https://access.redhat.com/security/cve/CVE-2026-26996
https://github.com/isaacs/minimatch
https://github.com/isaacs/minimatch/commit/2e111f3a79abc00fa73110195de2c0f2351904f5
https://github.com/isaacs/minimatch/security/advisories/GHSA-3ppc-4f35-3m26
https://nvd.nist.gov/vuln/detail/CVE-2026-26996
https://www.cve.org/CVERecord?id=CVE-2026-26996
|
| minimatch |
CVE-2026-27903 |
HIGH |
3.1.2 |
10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3 |
https://access.redhat.com/security/cve/CVE-2026-27903
https://github.com/isaacs/minimatch
https://github.com/isaacs/minimatch/commit/0bf499aa45f5059b56809cc3b75ff3eafeb8d748
https://github.com/isaacs/minimatch/security/advisories/GHSA-7r86-cg39-jmmj
https://nvd.nist.gov/vuln/detail/CVE-2026-27903
https://www.cve.org/CVERecord?id=CVE-2026-27903
|
| minimatch |
CVE-2026-27903 |
HIGH |
3.1.2 |
10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3 |
https://access.redhat.com/security/cve/CVE-2026-27903
https://github.com/isaacs/minimatch
https://github.com/isaacs/minimatch/commit/0bf499aa45f5059b56809cc3b75ff3eafeb8d748
https://github.com/isaacs/minimatch/security/advisories/GHSA-7r86-cg39-jmmj
https://nvd.nist.gov/vuln/detail/CVE-2026-27903
https://www.cve.org/CVERecord?id=CVE-2026-27903
|
| minimatch |
CVE-2026-27904 |
HIGH |
3.1.2 |
10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4 |
https://access.redhat.com/security/cve/CVE-2026-27904
https://github.com/isaacs/minimatch
https://github.com/isaacs/minimatch/commit/11d0df6165d15a955462316b26d52e5efae06fce
https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74
https://nvd.nist.gov/vuln/detail/CVE-2026-27904
https://www.cve.org/CVERecord?id=CVE-2026-27904
|
| minimatch |
CVE-2026-27904 |
HIGH |
3.1.2 |
10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4 |
https://access.redhat.com/security/cve/CVE-2026-27904
https://github.com/isaacs/minimatch
https://github.com/isaacs/minimatch/commit/11d0df6165d15a955462316b26d52e5efae06fce
https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74
https://nvd.nist.gov/vuln/detail/CVE-2026-27904
https://www.cve.org/CVERecord?id=CVE-2026-27904
|
| minimatch |
CVE-2026-26996 |
HIGH |
5.1.0 |
10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3 |
https://access.redhat.com/security/cve/CVE-2026-26996
https://github.com/isaacs/minimatch
https://github.com/isaacs/minimatch/commit/2e111f3a79abc00fa73110195de2c0f2351904f5
https://github.com/isaacs/minimatch/security/advisories/GHSA-3ppc-4f35-3m26
https://nvd.nist.gov/vuln/detail/CVE-2026-26996
https://www.cve.org/CVERecord?id=CVE-2026-26996
|
| minimatch |
CVE-2026-27903 |
HIGH |
5.1.0 |
10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3 |
https://access.redhat.com/security/cve/CVE-2026-27903
https://github.com/isaacs/minimatch
https://github.com/isaacs/minimatch/commit/0bf499aa45f5059b56809cc3b75ff3eafeb8d748
https://github.com/isaacs/minimatch/security/advisories/GHSA-7r86-cg39-jmmj
https://nvd.nist.gov/vuln/detail/CVE-2026-27903
https://www.cve.org/CVERecord?id=CVE-2026-27903
|
| minimatch |
CVE-2026-27904 |
HIGH |
5.1.0 |
10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4 |
https://access.redhat.com/security/cve/CVE-2026-27904
https://github.com/isaacs/minimatch
https://github.com/isaacs/minimatch/commit/11d0df6165d15a955462316b26d52e5efae06fce
https://github.com/isaacs/minimatch/security/advisories/GHSA-23c5-xmqv-rm74
https://nvd.nist.gov/vuln/detail/CVE-2026-27904
https://www.cve.org/CVERecord?id=CVE-2026-27904
|
| node-forge |
CVE-2025-12816 |
HIGH |
1.3.1 |
1.3.2 |
https://access.redhat.com/security/cve/CVE-2025-12816
https://github.com/digitalbazaar/forge
https://github.com/digitalbazaar/forge/blob/2bb97afb5058285ef09bcf1d04d6bd6b87cffd58/lib/asn1.js#L1153
https://github.com/digitalbazaar/forge/blob/2bb97afb5058285ef09bcf1d04d6bd6b87cffd58/lib/ed25519.js#L81
https://github.com/digitalbazaar/forge/blob/2bb97afb5058285ef09bcf1d04d6bd6b87cffd58/lib/pbe.js#L363
https://github.com/digitalbazaar/forge/blob/2bb97afb5058285ef09bcf1d04d6bd6b87cffd58/lib/pkcs12.js#L328
https://github.com/digitalbazaar/forge/blob/2bb97afb5058285ef09bcf1d04d6bd6b87cffd58/lib/pkcs7.js#L90
https://github.com/digitalbazaar/forge/blob/2bb97afb5058285ef09bcf1d04d6bd6b87cffd58/lib/rsa.js#L1167
https://github.com/digitalbazaar/forge/blob/2bb97afb5058285ef09bcf1d04d6bd6b87cffd58/lib/x509.js#L667
https://github.com/digitalbazaar/forge/pull/1124
https://github.com/digitalbazaar/forge/security/advisories/GHSA-5gfm-wpxj-wjgq
https://kb.cert.org/vuls/id/521113
https://nvd.nist.gov/vuln/detail/CVE-2025-12816
https://www.cve.org/CVERecord?id=CVE-2025-12816
https://www.kb.cert.org/vuls/id/521113
https://www.npmjs.com/package/node-forge
|
| node-forge |
CVE-2025-66031 |
HIGH |
1.3.1 |
1.3.2 |
https://access.redhat.com/security/cve/CVE-2025-66031
https://github.com/digitalbazaar/forge
https://github.com/digitalbazaar/forge/commit/260425c6167a38aae038697132483b5517b26451
https://github.com/digitalbazaar/forge/security/advisories/GHSA-554w-wpv2-vw27
https://nvd.nist.gov/vuln/detail/CVE-2025-66031
https://www.cve.org/CVERecord?id=CVE-2025-66031
|
| node-forge |
CVE-2026-33891 |
HIGH |
1.3.1 |
1.4.0 |
https://access.redhat.com/security/cve/CVE-2026-33891
https://github.com/digitalbazaar/forge
https://github.com/digitalbazaar/forge/commit/9bb8d67b99d17e4ebb5fd7596cd699e11f25d023
https://github.com/digitalbazaar/forge/security/advisories/GHSA-5m6q-g25r-mvwx
https://nvd.nist.gov/vuln/detail/CVE-2026-33891
https://www.cve.org/CVERecord?id=CVE-2026-33891
|
| node-forge |
CVE-2026-33894 |
HIGH |
1.3.1 |
1.4.0 |
https://access.redhat.com/security/cve/CVE-2026-33894
https://datatracker.ietf.org/doc/html/rfc2313#section-8
https://github.com/digitalbazaar/forge
https://github.com/digitalbazaar/forge/security/advisories/GHSA-cfm4-qjh2-4765
https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwp
https://mailarchive.ietf.org/arch/msg/openpgp/5rnE9ZRN1AokBVj3VqblGlP63QE
https://nvd.nist.gov/vuln/detail/CVE-2026-33894
https://www.cve.org/CVERecord?id=CVE-2026-33894
https://www.rfc-editor.org/rfc/rfc8017.html
|
| node-forge |
CVE-2026-33895 |
HIGH |
1.3.1 |
1.4.0 |
https://access.redhat.com/security/cve/CVE-2026-33895
https://datatracker.ietf.org/doc/html/rfc8032#section-8.4
https://github.com/digitalbazaar/forge
https://github.com/digitalbazaar/forge/commit/bdecf11571c9f1a487cc0fe72fe78ff6dfa96b85
https://github.com/digitalbazaar/forge/security/advisories/GHSA-q67f-28xg-22rw
https://nvd.nist.gov/vuln/detail/CVE-2022-35961
https://nvd.nist.gov/vuln/detail/CVE-2026-25793
https://nvd.nist.gov/vuln/detail/CVE-2026-33895
https://www.cve.org/CVERecord?id=CVE-2026-33895
|
| node-forge |
CVE-2026-33896 |
HIGH |
1.3.1 |
1.4.0 |
https://access.redhat.com/security/cve/CVE-2026-33896
https://github.com/digitalbazaar/forge
https://github.com/digitalbazaar/forge/commit/2e492832fb25227e6b647cbe1ac981c123171e90
https://github.com/digitalbazaar/forge/security/advisories/GHSA-2328-f5f3-gj25
https://nvd.nist.gov/vuln/detail/CVE-2026-33896
https://www.cve.org/CVERecord?id=CVE-2026-33896
|
| node-forge |
CVE-2025-66030 |
MEDIUM |
1.3.1 |
1.3.2 |
https://access.redhat.com/security/cve/CVE-2025-66030
https://github.com/digitalbazaar/forge
https://github.com/digitalbazaar/forge/commit/3e0c35ace169cfca529a3e547a7848dc7bf57fdb
https://github.com/digitalbazaar/forge/security/advisories/GHSA-65ch-62r8-g69g
https://nvd.nist.gov/vuln/detail/CVE-2025-66030
https://www.cve.org/CVERecord?id=CVE-2025-66030
|
| qs |
CVE-2025-15284 |
MEDIUM |
6.5.3 |
6.14.1 |
https://access.redhat.com/security/cve/CVE-2025-15284
https://github.com/ljharb/qs
https://github.com/ljharb/qs/commit/3086902ecf7f088d0d1803887643ac6c03d415b9
https://github.com/ljharb/qs/security/advisories/GHSA-6rw7-vpxm-498p
https://nvd.nist.gov/vuln/detail/CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
|
| semver |
CVE-2022-25883 |
HIGH |
7.3.7 |
7.5.2, 6.3.1, 5.7.2 |
https://access.redhat.com/errata/RHSA-2023:5363
https://access.redhat.com/security/cve/CVE-2022-25883
https://bugzilla.redhat.com/2216475
https://bugzilla.redhat.com/2230948
https://bugzilla.redhat.com/2230955
https://bugzilla.redhat.com/2230956
https://bugzilla.redhat.com/show_bug.cgi?id=2216475
https://bugzilla.redhat.com/show_bug.cgi?id=2230948
https://bugzilla.redhat.com/show_bug.cgi?id=2230955
https://bugzilla.redhat.com/show_bug.cgi?id=2230956
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25883
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32002
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32006
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32559
https://errata.almalinux.org/9/ALSA-2023-5363.html
https://errata.rockylinux.org/RLSA-2023:5363
https://github.com/advisories/GHSA-c2qf-rxjj-qqgw
https://github.com/npm/node-semver
https://github.com/npm/node-semver/blob/main/classes/range.js#L97-L104
https://github.com/npm/node-semver/blob/main/classes/range.js%23L97-L104
https://github.com/npm/node-semver/blob/main/internal/re.js#L138
https://github.com/npm/node-semver/blob/main/internal/re.js#L160
https://github.com/npm/node-semver/blob/main/internal/re.js%23L138
https://github.com/npm/node-semver/blob/main/internal/re.js%23L160
https://github.com/npm/node-semver/commit/2f8fd41487acf380194579ecb6f8b1bbfe116be0
https://github.com/npm/node-semver/commit/717534ee353682f3bcf33e60a8af4292626d4441
https://github.com/npm/node-semver/commit/928e56d21150da0413a3333a3148b20e741a920c
https://github.com/npm/node-semver/pull/564
https://github.com/npm/node-semver/pull/585
https://github.com/npm/node-semver/pull/593
https://linux.oracle.com/cve/CVE-2022-25883.html
https://linux.oracle.com/errata/ELSA-2023-5363.html
https://nvd.nist.gov/vuln/detail/CVE-2022-25883
https://security.netapp.com/advisory/ntap-20241025-0004
https://security.netapp.com/advisory/ntap-20241025-0004/
https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795
https://www.cve.org/CVERecord?id=CVE-2022-25883
|
| tar |
CVE-2026-23745 |
HIGH |
6.1.11 |
7.5.3 |
https://access.redhat.com/security/cve/CVE-2026-23745
https://github.com/isaacs/node-tar
https://github.com/isaacs/node-tar/commit/340eb285b6d986e91969a1170d7fe9b0face405e
https://github.com/isaacs/node-tar/security/advisories/GHSA-8qq5-rm4j-mr97
https://nvd.nist.gov/vuln/detail/CVE-2026-23745
https://www.cve.org/CVERecord?id=CVE-2026-23745
|
| tar |
CVE-2026-23950 |
HIGH |
6.1.11 |
7.5.4 |
https://access.redhat.com/security/cve/CVE-2026-23950
https://github.com/isaacs/node-tar
https://github.com/isaacs/node-tar/commit/3b1abfae650056edfabcbe0a0df5954d390521e6
https://github.com/isaacs/node-tar/security/advisories/GHSA-r6q2-hw4h-h46w
https://nvd.nist.gov/vuln/detail/CVE-2026-23950
https://www.cve.org/CVERecord?id=CVE-2026-23950
|
| tar |
CVE-2026-24842 |
HIGH |
6.1.11 |
7.5.7 |
https://access.redhat.com/security/cve/CVE-2026-24842
https://github.com/isaacs/node-tar
https://github.com/isaacs/node-tar/commit/f4a7aa9bc3d717c987fdf1480ff7a64e87ffdb46
https://github.com/isaacs/node-tar/security/advisories/GHSA-34x7-hfp2-rc4v
https://nvd.nist.gov/vuln/detail/CVE-2026-24842
https://www.cve.org/CVERecord?id=CVE-2026-24842
|
| tar |
CVE-2026-26960 |
HIGH |
6.1.11 |
7.5.8 |
https://access.redhat.com/security/cve/CVE-2026-26960
https://github.com/isaacs/node-tar
https://github.com/isaacs/node-tar/commit/2cb1120bcefe28d7ecc719b41441ade59c52e384
https://github.com/isaacs/node-tar/commit/d18e4e1f846f4ddddc153b0f536a19c050e7499f
https://github.com/isaacs/node-tar/security/advisories/GHSA-83g3-92jg-28cx
https://nvd.nist.gov/vuln/detail/CVE-2026-26960
https://www.cve.org/CVERecord?id=CVE-2026-26960
|
| tar |
CVE-2026-29786 |
HIGH |
6.1.11 |
7.5.10 |
https://access.redhat.com/security/cve/CVE-2026-29786
https://github.com/isaacs/node-tar
https://github.com/isaacs/node-tar/commit/7bc755dd85e623c0279e08eb3784909e6d7e4b9f
https://github.com/isaacs/node-tar/security/advisories/GHSA-qffp-2rhf-9h96
https://nvd.nist.gov/vuln/detail/CVE-2026-29786
https://www.cve.org/CVERecord?id=CVE-2026-29786
|
| tar |
CVE-2026-31802 |
HIGH |
6.1.11 |
7.5.11 |
https://access.redhat.com/security/cve/CVE-2026-31802
https://github.com/isaacs/node-tar
https://github.com/isaacs/node-tar/commit/f48b5fa3b7985ddab96dc0f2125a4ffc9911b6ad
https://github.com/isaacs/node-tar/security/advisories/GHSA-9ppj-qmqm-q256
https://nvd.nist.gov/vuln/detail/CVE-2026-31802
https://www.cve.org/CVERecord?id=CVE-2026-31802
|
| tar |
CVE-2024-28863 |
MEDIUM |
6.1.11 |
6.2.1 |
https://access.redhat.com/errata/RHSA-2024:6147
https://access.redhat.com/security/cve/CVE-2024-28863
https://bugzilla.redhat.com/2293200
https://bugzilla.redhat.com/2296417
https://bugzilla.redhat.com/show_bug.cgi?id=2293200
https://bugzilla.redhat.com/show_bug.cgi?id=2296417
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22020
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28863
https://errata.almalinux.org/9/ALSA-2024-6147.html
https://errata.rockylinux.org/RLSA-2024:6147
https://github.com/isaacs/node-tar
https://github.com/isaacs/node-tar/commit/fe8cd57da5686f8695415414bda49206a545f7f7
https://github.com/isaacs/node-tar/commit/fe8cd57da5686f8695415414bda49206a545f7f7 (v6.2.1)
https://github.com/isaacs/node-tar/security/advisories/GHSA-f5x3-32g6-xq36
https://linux.oracle.com/cve/CVE-2024-28863.html
https://linux.oracle.com/errata/ELSA-2024-6148.html
https://nvd.nist.gov/vuln/detail/CVE-2024-28863
https://security.netapp.com/advisory/ntap-20240524-0005
https://security.netapp.com/advisory/ntap-20240524-0005/
https://www.cve.org/CVERecord?id=CVE-2024-28863
|
| underscore |
CVE-2026-27601 |
HIGH |
1.12.1 |
1.13.8 |
https://access.redhat.com/security/cve/CVE-2026-27601
https://github.com/jashkenas/underscore
https://github.com/jashkenas/underscore/commit/411e222eb0ca5d570cc4f6315c02c05b830ed2b4
https://github.com/jashkenas/underscore/commit/a6e23ae9647461ec33ad9f92a2ecfc220eea0a84
https://github.com/jashkenas/underscore/issues/3011
https://github.com/jashkenas/underscore/security/advisories/GHSA-qpx9-hpmf-5gmw
https://nvd.nist.gov/vuln/detail/CVE-2026-27601
https://underscorejs.org/#1.13.8
https://underscorejs.org/#flatten
https://underscorejs.org/#isEqual
https://www.cve.org/CVERecord?id=CVE-2026-27601
|
| No Misconfigurations found |