Skip to content
auto-generated · daily

Security posture across every ecosystem.

47 critical/high severity findings across the monorepo — triage before merge.

Last generated 2026-08-01T04:24:44Z.

4Critical
43High
56Medium
10Low
31Info

Advisories

pie showData
    title Findings by Severity
    "Critical" : 4
    "High" : 43
    "Medium" : 56
    "Low" : 10
pie showData
    title Findings by Ecosystem
    "npm" : 98
    "Cargo" : 46
EcosystemCriticalHighMediumLowTotal
npm443411098
Cargo0015046
Python00000
CodeQL00000
Dependabot00000
Total4435610144
SeverityPackageAdvisoryLink
CriticalvitestWhen Vitest UI server is listening, arbitrary file can be…Details
Criticalshell-quoteshell-quote quote() does not escape newlines in object .o…Details
Criticalwebsocket-driverwebsocket-driver: Message corruption via abuse of protoco…Details
Criticaltarnode-tar: Decompression/parse DoS via unlimited inputDetails
HighrollupRollup 4 has Arbitrary File Write via Path TraversalDetails
HighkoaKoa has Host Header Injection via ctx.hostnameDetails
HighsvgoSVGO DoS through entity expansion in DOCTYPE (Billion Lau…Details
Hightartar has Hardlink Path Traversal via Drive-Relative LinkpathDetails
Hightarnode-tar Symlink Path Traversal via Drive-Relative LinkpathDetails
Highflattedflatted vulnerable to unbounded recursion DoS in parse() …Details
HighflattedPrototype Pollution via parse() in NodeJS flattedDetails
Highpath-to-regexppath-to-regexp vulnerable to Regular Expression Denial of…Details
HighpicomatchPicomatch has a ReDoS vulnerability via extglob quantifiersDetails
Highlodashlodash vulnerable to Code Injection via _.template impo…Details
Highfast-urifast-uri vulnerable to path traversal via percent-encoded…Details
Highfast-urifast-uri vulnerable to host confusion via percent-encoded…Details
Hightmptmp has Path Traversal via unsanitized prefix/postfix tha…Details
Highhttp-proxy-middlewarehttp-proxy-middleware: multipart/form-data field injectio…Details
Highundiciundici vulnerable to TLS certificate validation bypass vi…Details
HighnodemailerNodemailer: Message-level raw option bypasses disableFile…Details
Highundiciundici WebSocket client vulnerable to denial of service v…Details
Highundiciundici WebSocket client vulnerable to denial of service v…Details
Highundiciundici vulnerable to cross-origin request routing via SOC…Details
Highwsws: Memory exhaustion DoS from tiny fragments and data ch…Details
Highvitevite: server.fs.deny bypass on Windows alternate pathsDetails
Highvitevite: server.fs.deny bypass on Windows alternate pathsDetails
Highadm-zipadm-zip: Crafted ZIP file triggers 4GB memory allocationDetails
Highbrace-expansionbrace-expansion: DoS via exponential-time expansion of co…Details
Highbrace-expansionbrace-expansion: DoS via exponential-time expansion of co…Details
Highbrace-expansionbrace-expansion: DoS via exponential-time expansion of co…Details
Highjs-yamljs-yaml: YAML merge-key chains can force quadratic CPU co…Details
Highjs-yamljs-yaml: YAML merge-key chains can force quadratic CPU co…Details
Hightarnode-tar: Negative tar entry size causes infinite loop in…Details
Highshell-quoteshell-quote: Quadratic-complexity Denial of Service in `p…Details
HighaxiosAxios Node HTTP adapter can use an inherited proxy after …Details
HighimmutableImmutable.js List 32-bit trie overflow → unrecoverable DoSDetails
HighimmutableImmutabl: Hash-collision algorithmic complexity denial of…Details
HighsvgoSVGO removeScripts plugin leaves some executable scripts …Details
HighsvgoSVGO removeScripts plugin leaves some executable scripts …Details
Highfast-urifast-uri vulnerable to host confusion via literal backsla…Details
Highsharpsharp inherited vulnerabilities in libvips: CVE-2026-3332…Details
Highfast-xml-parserfast-xml-parser: Repeated DOCTYPE declarations reset enti…Details
HighpostcssPostCSS: Path Traversal in Previous Source Map Auto-Loadi…Details
Highfast-urifast-uri vulnerable to host confusion via failed IDN cano…Details
Highbrace-expansionbrace-expansion: DoS via unbounded expansion length causi…Details
Highbrace-expansionbrace-expansion: DoS via unbounded expansion length causi…Details
Highbrace-expansionbrace-expansion: DoS via unbounded expansion length causi…Details
Mediumvue-template-compilervue-template-compiler vulnerable to client-side Cross-Sit…Details
Mediummdast-util-to-hastmdast-util-to-hast has unsanitized class attributeDetails
Mediumajvajv has ReDoS when using $data optionDetails
Mediumajvajv has ReDoS when using $data optionDetails
Mediumqsqs’s arrayLimit bypass in its bracket notation allows DoS…Details
Mediumbrace-expansionbrace-expansion: Zero-step sequence causes process hang a…Details
MediumpicomatchPicomatch: Method Injection in POSIX Character Classes ca…Details
Mediumyamlyaml is vulnerable to Stack Overflow via deeply nested YA…Details
Mediumyamlyaml is vulnerable to Stack Overflow via deeply nested YA…Details
Mediumlodashlodash vulnerable to Prototype Pollution via array path b…Details
Mediumwsws: Uninitialized memory disclosureDetails
Mediumserialize-javascriptSerialize JavaScript has CPU Exhaustion Denial of Service…Details
Mediumuuiduuid: Missing buffer bounds check in v3/v5/v6 when buf is…Details
Mediumqsqs has a remotely triggerable DoS: qs.stringify crashes w…Details
MediumlodashLodash has Prototype Pollution Vulnerability in _.unsetDetails
Mediumtarnode-tar applies PAX size override to intermediary GNU lo…Details
Mediumvitelaunch-editor: NTLMv2 hash disclosure via UNC path handli…Details
Mediumvitelaunch-editor: NTLMv2 hash disclosure via UNC path handli…Details
Mediumlaunch-editorlaunch-editor: NTLMv2 hash disclosure via UNC path handli…Details
Mediumundiciundici vulnerable to HTTP header injection via Set-Cookie…Details
Mediumundiciundici vulnerable to HTTP header injection via Set-Cookie…Details
Mediumhttp-proxy-middlewarehttp-proxy-middleware router host+path substring matchi…Details
Mediumhttp-proxy-middlewarehttp-proxy-middleware router host+path substring matchi…Details
Mediumundiciundici vulnerable to cross-user information disclosure vi…Details
Mediumjs-yamlJS-YAML: Quadratic-complexity DoS in merge key handling v…Details
Mediumjs-yamlJS-YAML: Quadratic-complexity DoS in merge key handling v…Details
Mediumwebsocket-driverwebsocket-driver: Resource limit bypass via message compr…Details
MediumaxiosAxios: Excessive recursion in formDataToJSON can cause de…Details
MediumaxiosAxios: Prototype pollution auth subfields can inject Basi…Details
MediumaxiosAxios: Deep formToJSON Key Recursion Can Cause Denial of …Details
Mediumtarnode-tar: Process crash via PAX numeric path type confusionDetails
Mediumtarnode-tar: Uncaught Exception DoS via NUL byte in PAX path…Details
MediumaxiosAxios: Fetch adapter ReadableStream uploads bypass `max…Details
MediumaxiosAxios: Prototype pollution gadgets can alter axios reques…Details
MediumaxiosAxios: NO_PROXY bypass for 0.0.0.0 local addresses in axiosDetails
Mediumwebpack-dev-serverwebpack-dev-server vulnerable to cross-site request forge…Details
Mediumwebpack-dev-serverwebpack-dev-server vulnerable to denial of service via a …Details
MediumaxiosAxios form serializer maxDepth bypass via {} metatokenDetails
MediumaxiosAxios: Nested axios option objects can consume polluted p…Details
MediumaxiosAxios: HTTP/2 streamed uploads bypass maxBodyLengthDetails
Mediumtarnode-tar: Uncontrolled recursion in mapHas/filesFilter al…Details
Lowdiffjsdiff has a Denial of Service vulnerability in parsePatc…Details
Lowqsqs’s arrayLimit bypass in comma parsing allows denial of …Details
Lowesbuildesbuild allows arbitrary file read when running the devel…Details
Lowundiciundici vulnerable to HTTP response queue poisoning via ke…Details
Lowundiciundici vulnerable to HTTP response queue poisoning via ke…Details
Lowundiciundici vulnerable to Set-Cookie SameSite attribute downgr…Details
Lowundiciundici vulnerable to Set-Cookie SameSite attribute downgr…Details
Low@babel/core@babel/core: Arbitrary File Read via sourceMappingURL Com…Details
Lowbody-parserbody-parser vulnerable to denial of service when invalid …Details
LowdompurifyDOMPurify: CUSTOM_ELEMENT_HANDLING bypasses `afterSanit…Details
SeverityPackageAdvisoryLink
MediumammoniaXSS in ammonia via SVG animate and set animation tags
Mediumquick-xmlQuadratic run time when checking a start tag for duplicat…Details
Mediumquick-xmlUnbounded namespace-declaration allocation in NsReaderDetails
Mediumquick-xmlQuadratic run time when checking a start tag for duplicat…Details
Mediumquick-xmlUnbounded namespace-declaration allocation in NsReaderDetails
MediumrsaMarvin Attack: potential key recovery through timing side…Details
Mediumrustls-webpkiName constraints for URI names were incorrectly accepted
Mediumrustls-webpkiName constraints were accepted for certificates asserting…
Mediumrustls-webpkiReachable panic in certificate revocation list parsing
Mediumrustls-webpkiName constraints for URI names were incorrectly accepted
Mediumrustls-webpkiCRLs not considered authoritative by Distribution Point d…
Mediumrustls-webpkiName constraints were accepted for certificates asserting…
Mediumrustls-webpkiReachable panic in certificate revocation list parsing
MediumsqlxBinary Protocol Misinterpretation caused by Truncating or…Details
MediumsteamworksDenial of service in Steamworks game clients/servers usin…Details
Infoatkgtk-rs GTK3 bindings - no longer maintainedDetails
Infoatk-sysgtk-rs GTK3 bindings - no longer maintainedDetails
Infobackoffbackoff is unmaintained.Details
InfobincodeBincode is unmaintainedDetails
InfobincodeBincode is unmaintainedDetails
Infocrypto-hashcrypto-hash crate is unmaintainedDetails
Infoderivativederivative is unmaintained; consider using an alternativeDetails
Infogdkgtk-rs GTK3 bindings - no longer maintainedDetails
Infogdk-sysgtk-rs GTK3 bindings - no longer maintainedDetails
Infogdkwayland-sysgtk-rs GTK3 bindings - no longer maintainedDetails
Infogdkx11gtk-rs GTK3 bindings - no longer maintainedDetails
Infogdkx11-sysgtk-rs GTK3 bindings - no longer maintainedDetails
Infogtkgtk-rs GTK3 bindings - no longer maintainedDetails
Infogtk-sysgtk-rs GTK3 bindings - no longer maintainedDetails
Infogtk3-macrosgtk-rs GTK3 bindings - no longer maintainedDetails
Infoinstantinstant is unmaintained
Infopastepaste - no longer maintainedDetails
Infoproc-macro-errorproc-macro-error is unmaintainedDetails
Inforustls-pemfilerustls-pemfile is unmaintainedDetails
Inforustls-pemfilerustls-pemfile is unmaintainedDetails
Inforustybuzzrustybuzz is unmaintainedDetails
Infoserde_cborserde_cbor is unmaintainedDetails
Infottf-parserttf-parser is unmaintainedDetails
Infounic-char-propertyunic-char-property is unmaintainedDetails
Infounic-char-rangeunic-char-range is unmaintainedDetails
Infounic-commonunic-common is unmaintainedDetails
Infounic-ucd-identunic-ucd-ident is unmaintainedDetails
Infounic-ucd-versionunic-ucd-version is unmaintainedDetails
Infoevent-listenerevent-listener allows !Send tags to cross thread boun…Details
InfoglibUnsoundness in Iterator and DoubleEndedIterator impls…Details
InfolruIterMut violates Stacked Borrows by invalidating intern…Details

Auto-generated by ci-daily-content.yml