auto-generated · daily
Security posture across every ecosystem.
47 critical/high severity findings across the monorepo — triage before merge.
Last generated 2026-08-01T04:24:44Z.
4Critical
43High
56Medium
10Low
31Info
Coverage
Ecosystem breakdown
Advisories
Severity distribution
Section titled “Severity distribution”pie showData
title Findings by Severity
"Critical" : 4
"High" : 43
"Medium" : 56
"Low" : 10Findings by ecosystem
Section titled “Findings by ecosystem”pie showData
title Findings by Ecosystem
"npm" : 98
"Cargo" : 46Summary
Section titled “Summary”| Ecosystem | Critical | High | Medium | Low | Total |
|---|---|---|---|---|---|
| npm | 4 | 43 | 41 | 10 | 98 |
| Cargo | 0 | 0 | 15 | 0 | 46 |
| Python | 0 | 0 | 0 | 0 | 0 |
| CodeQL | 0 | 0 | 0 | 0 | 0 |
| Dependabot | 0 | 0 | 0 | 0 | 0 |
| Total | 4 | 43 | 56 | 10 | 144 |
| Severity | Package | Advisory | Link |
|---|---|---|---|
| Critical | vitest | When Vitest UI server is listening, arbitrary file can be… | Details |
| Critical | shell-quote | shell-quote quote() does not escape newlines in object .o… | Details |
| Critical | websocket-driver | websocket-driver: Message corruption via abuse of protoco… | Details |
| Critical | tar | node-tar: Decompression/parse DoS via unlimited input | Details |
| High | rollup | Rollup 4 has Arbitrary File Write via Path Traversal | Details |
| High | koa | Koa has Host Header Injection via ctx.hostname | Details |
| High | svgo | SVGO DoS through entity expansion in DOCTYPE (Billion Lau… | Details |
| High | tar | tar has Hardlink Path Traversal via Drive-Relative Linkpath | Details |
| High | tar | node-tar Symlink Path Traversal via Drive-Relative Linkpath | Details |
| High | flatted | flatted vulnerable to unbounded recursion DoS in parse() … | Details |
| High | flatted | Prototype Pollution via parse() in NodeJS flatted | Details |
| High | path-to-regexp | path-to-regexp vulnerable to Regular Expression Denial of… | Details |
| High | picomatch | Picomatch has a ReDoS vulnerability via extglob quantifiers | Details |
| High | lodash | lodash vulnerable to Code Injection via _.template impo… | Details |
| High | fast-uri | fast-uri vulnerable to path traversal via percent-encoded… | Details |
| High | fast-uri | fast-uri vulnerable to host confusion via percent-encoded… | Details |
| High | tmp | tmp has Path Traversal via unsanitized prefix/postfix tha… | Details |
| High | http-proxy-middleware | http-proxy-middleware: multipart/form-data field injectio… | Details |
| High | undici | undici vulnerable to TLS certificate validation bypass vi… | Details |
| High | nodemailer | Nodemailer: Message-level raw option bypasses disableFile… | Details |
| High | undici | undici WebSocket client vulnerable to denial of service v… | Details |
| High | undici | undici WebSocket client vulnerable to denial of service v… | Details |
| High | undici | undici vulnerable to cross-origin request routing via SOC… | Details |
| High | ws | ws: Memory exhaustion DoS from tiny fragments and data ch… | Details |
| High | vite | vite: server.fs.deny bypass on Windows alternate paths | Details |
| High | vite | vite: server.fs.deny bypass on Windows alternate paths | Details |
| High | adm-zip | adm-zip: Crafted ZIP file triggers 4GB memory allocation | Details |
| High | brace-expansion | brace-expansion: DoS via exponential-time expansion of co… | Details |
| High | brace-expansion | brace-expansion: DoS via exponential-time expansion of co… | Details |
| High | brace-expansion | brace-expansion: DoS via exponential-time expansion of co… | Details |
| High | js-yaml | js-yaml: YAML merge-key chains can force quadratic CPU co… | Details |
| High | js-yaml | js-yaml: YAML merge-key chains can force quadratic CPU co… | Details |
| High | tar | node-tar: Negative tar entry size causes infinite loop in… | Details |
| High | shell-quote | shell-quote: Quadratic-complexity Denial of Service in `p… | Details |
| High | axios | Axios Node HTTP adapter can use an inherited proxy after … | Details |
| High | immutable | Immutable.js List 32-bit trie overflow → unrecoverable DoS | Details |
| High | immutable | Immutabl: Hash-collision algorithmic complexity denial of… | Details |
| High | svgo | SVGO removeScripts plugin leaves some executable scripts … | Details |
| High | svgo | SVGO removeScripts plugin leaves some executable scripts … | Details |
| High | fast-uri | fast-uri vulnerable to host confusion via literal backsla… | Details |
| High | sharp | sharp inherited vulnerabilities in libvips: CVE-2026-3332… | Details |
| High | fast-xml-parser | fast-xml-parser: Repeated DOCTYPE declarations reset enti… | Details |
| High | postcss | PostCSS: Path Traversal in Previous Source Map Auto-Loadi… | Details |
| High | fast-uri | fast-uri vulnerable to host confusion via failed IDN cano… | Details |
| High | brace-expansion | brace-expansion: DoS via unbounded expansion length causi… | Details |
| High | brace-expansion | brace-expansion: DoS via unbounded expansion length causi… | Details |
| High | brace-expansion | brace-expansion: DoS via unbounded expansion length causi… | Details |
| Medium | vue-template-compiler | vue-template-compiler vulnerable to client-side Cross-Sit… | Details |
| Medium | mdast-util-to-hast | mdast-util-to-hast has unsanitized class attribute | Details |
| Medium | ajv | ajv has ReDoS when using $data option | Details |
| Medium | ajv | ajv has ReDoS when using $data option | Details |
| Medium | qs | qs’s arrayLimit bypass in its bracket notation allows DoS… | Details |
| Medium | brace-expansion | brace-expansion: Zero-step sequence causes process hang a… | Details |
| Medium | picomatch | Picomatch: Method Injection in POSIX Character Classes ca… | Details |
| Medium | yaml | yaml is vulnerable to Stack Overflow via deeply nested YA… | Details |
| Medium | yaml | yaml is vulnerable to Stack Overflow via deeply nested YA… | Details |
| Medium | lodash | lodash vulnerable to Prototype Pollution via array path b… | Details |
| Medium | ws | ws: Uninitialized memory disclosure | Details |
| Medium | serialize-javascript | Serialize JavaScript has CPU Exhaustion Denial of Service… | Details |
| Medium | uuid | uuid: Missing buffer bounds check in v3/v5/v6 when buf is… | Details |
| Medium | qs | qs has a remotely triggerable DoS: qs.stringify crashes w… | Details |
| Medium | lodash | Lodash has Prototype Pollution Vulnerability in _.unset… | Details |
| Medium | tar | node-tar applies PAX size override to intermediary GNU lo… | Details |
| Medium | vite | launch-editor: NTLMv2 hash disclosure via UNC path handli… | Details |
| Medium | vite | launch-editor: NTLMv2 hash disclosure via UNC path handli… | Details |
| Medium | launch-editor | launch-editor: NTLMv2 hash disclosure via UNC path handli… | Details |
| Medium | undici | undici vulnerable to HTTP header injection via Set-Cookie… | Details |
| Medium | undici | undici vulnerable to HTTP header injection via Set-Cookie… | Details |
| Medium | http-proxy-middleware | http-proxy-middleware router host+path substring matchi… | Details |
| Medium | http-proxy-middleware | http-proxy-middleware router host+path substring matchi… | Details |
| Medium | undici | undici vulnerable to cross-user information disclosure vi… | Details |
| Medium | js-yaml | JS-YAML: Quadratic-complexity DoS in merge key handling v… | Details |
| Medium | js-yaml | JS-YAML: Quadratic-complexity DoS in merge key handling v… | Details |
| Medium | websocket-driver | websocket-driver: Resource limit bypass via message compr… | Details |
| Medium | axios | Axios: Excessive recursion in formDataToJSON can cause de… | Details |
| Medium | axios | Axios: Prototype pollution auth subfields can inject Basi… | Details |
| Medium | axios | Axios: Deep formToJSON Key Recursion Can Cause Denial of … | Details |
| Medium | tar | node-tar: Process crash via PAX numeric path type confusion | Details |
| Medium | tar | node-tar: Uncaught Exception DoS via NUL byte in PAX path… | Details |
| Medium | axios | Axios: Fetch adapter ReadableStream uploads bypass `max… | Details |
| Medium | axios | Axios: Prototype pollution gadgets can alter axios reques… | Details |
| Medium | axios | Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios | Details |
| Medium | webpack-dev-server | webpack-dev-server vulnerable to cross-site request forge… | Details |
| Medium | webpack-dev-server | webpack-dev-server vulnerable to denial of service via a … | Details |
| Medium | axios | Axios form serializer maxDepth bypass via {} metatoken | Details |
| Medium | axios | Axios: Nested axios option objects can consume polluted p… | Details |
| Medium | axios | Axios: HTTP/2 streamed uploads bypass maxBodyLength | Details |
| Medium | tar | node-tar: Uncontrolled recursion in mapHas/filesFilter al… | Details |
| Low | diff | jsdiff has a Denial of Service vulnerability in parsePatc… | Details |
| Low | qs | qs’s arrayLimit bypass in comma parsing allows denial of … | Details |
| Low | esbuild | esbuild allows arbitrary file read when running the devel… | Details |
| Low | undici | undici vulnerable to HTTP response queue poisoning via ke… | Details |
| Low | undici | undici vulnerable to HTTP response queue poisoning via ke… | Details |
| Low | undici | undici vulnerable to Set-Cookie SameSite attribute downgr… | Details |
| Low | undici | undici vulnerable to Set-Cookie SameSite attribute downgr… | Details |
| Low | @babel/core | @babel/core: Arbitrary File Read via sourceMappingURL Com… | Details |
| Low | body-parser | body-parser vulnerable to denial of service when invalid … | Details |
| Low | dompurify | DOMPurify: CUSTOM_ELEMENT_HANDLING bypasses `afterSanit… | Details |
| Severity | Package | Advisory | Link |
|---|---|---|---|
| Medium | ammonia | XSS in ammonia via SVG animate and set animation tags | |
| Medium | quick-xml | Quadratic run time when checking a start tag for duplicat… | Details |
| Medium | quick-xml | Unbounded namespace-declaration allocation in NsReader … | Details |
| Medium | quick-xml | Quadratic run time when checking a start tag for duplicat… | Details |
| Medium | quick-xml | Unbounded namespace-declaration allocation in NsReader … | Details |
| Medium | rsa | Marvin Attack: potential key recovery through timing side… | Details |
| Medium | rustls-webpki | Name constraints for URI names were incorrectly accepted | |
| Medium | rustls-webpki | Name constraints were accepted for certificates asserting… | |
| Medium | rustls-webpki | Reachable panic in certificate revocation list parsing | |
| Medium | rustls-webpki | Name constraints for URI names were incorrectly accepted | |
| Medium | rustls-webpki | CRLs not considered authoritative by Distribution Point d… | |
| Medium | rustls-webpki | Name constraints were accepted for certificates asserting… | |
| Medium | rustls-webpki | Reachable panic in certificate revocation list parsing | |
| Medium | sqlx | Binary Protocol Misinterpretation caused by Truncating or… | Details |
| Medium | steamworks | Denial of service in Steamworks game clients/servers usin… | Details |
| Info | atk | gtk-rs GTK3 bindings - no longer maintained | Details |
| Info | atk-sys | gtk-rs GTK3 bindings - no longer maintained | Details |
| Info | backoff | backoff is unmaintained. | Details |
| Info | bincode | Bincode is unmaintained | Details |
| Info | bincode | Bincode is unmaintained | Details |
| Info | crypto-hash | crypto-hash crate is unmaintained | Details |
| Info | derivative | derivative is unmaintained; consider using an alternative | Details |
| Info | gdk | gtk-rs GTK3 bindings - no longer maintained | Details |
| Info | gdk-sys | gtk-rs GTK3 bindings - no longer maintained | Details |
| Info | gdkwayland-sys | gtk-rs GTK3 bindings - no longer maintained | Details |
| Info | gdkx11 | gtk-rs GTK3 bindings - no longer maintained | Details |
| Info | gdkx11-sys | gtk-rs GTK3 bindings - no longer maintained | Details |
| Info | gtk | gtk-rs GTK3 bindings - no longer maintained | Details |
| Info | gtk-sys | gtk-rs GTK3 bindings - no longer maintained | Details |
| Info | gtk3-macros | gtk-rs GTK3 bindings - no longer maintained | Details |
| Info | instant | instant is unmaintained | |
| Info | paste | paste - no longer maintained | Details |
| Info | proc-macro-error | proc-macro-error is unmaintained | Details |
| Info | rustls-pemfile | rustls-pemfile is unmaintained | Details |
| Info | rustls-pemfile | rustls-pemfile is unmaintained | Details |
| Info | rustybuzz | rustybuzz is unmaintained | Details |
| Info | serde_cbor | serde_cbor is unmaintained | Details |
| Info | ttf-parser | ttf-parser is unmaintained | Details |
| Info | unic-char-property | unic-char-property is unmaintained | Details |
| Info | unic-char-range | unic-char-range is unmaintained | Details |
| Info | unic-common | unic-common is unmaintained | Details |
| Info | unic-ucd-ident | unic-ucd-ident is unmaintained | Details |
| Info | unic-ucd-version | unic-ucd-version is unmaintained | Details |
| Info | event-listener | event-listener allows !Send tags to cross thread boun… | Details |
| Info | glib | Unsoundness in Iterator and DoubleEndedIterator impls… | Details |
| Info | lru | IterMut violates Stacked Borrows by invalidating intern… | Details |
Python
Section titled “Python”CodeQL
Section titled “CodeQL”Dependabot
Section titled “Dependabot”Auto-generated by ci-daily-content.yml
