VulnSea

Tagged “npm”

CVEs tagged npm, newest first.

1010 CVEsRSS

CVE-2026-47219High· 7.5
2mo ago

find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server (CVE-2026-47219)

A flaw was found in find-my-way, a routing module for Node.js. A remote attacker could exploit this vulnerability when find-my-way is used with Node's HTTP/2 server. By sending specially crafted HTTP/2 method values, an attacker can cause …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.46%via CSAF
CVE-2026-54272High· 7.2
2mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifie…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v.9.6)EPSS 0.43%via NVD
CVE-2026-55685Medium· 6.5
2mo ago

react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests (CVE-2026-55685)

A flaw was found in React Router. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and…

▾ SunlitRed Hat · Red Hat OpenShift AI 3.4EPSS 0.71%via CSAF
CVE-2026-45623High· 7.5
2mo ago

postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623)

A flaw was found in PostCSS, a tool that processes CSS files. An attacker who provides specially crafted CSS input containing a malicious source map comment can cause the system to read arbitrary files from the local filesystem. This can l…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.61%via CSAF
GHSA-8q49-2h5h-434xMedium· 5.9
2mo ago

FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller

FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller

▾ Sunlitfrontmcp · @frontmcp/adaptersvia GHSA
GHSA-pvcr-8mvp-w8qrHigh· 7.7
2mo ago

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-cr7p-cr3q-h5cmMedium· 5.3
2mo ago

Budibase: Account Enumeration via Login Lockout Response Differential

Budibase: Account Enumeration via Login Lockout Response Differential

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-pmpg-2mxq-6xwrHigh· 7.1
2mo ago

Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete

Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-v42f-v8xc-j435High· 8.5
2mo ago

Budibase: SSRF via DNS rebinding in the REST datasource integration

Budibase: SSRF via DNS rebinding in the REST datasource integration

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-hfhx-w8p8-4hc7Medium
2mo ago

Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-g5vv-q72c-7j78High· 7.5
2mo ago

@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion

@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion

▾ Twilightanephenix · @anephenix/hubvia GHSA
GHSA-vh45-f885-3848Critical· 9.1
2mo ago

sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock

sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock

▾ Midnightsm-crypto · sm-cryptovia GHSA
GHSA-6v4m-fw66-8r4xMedium
2mo ago

Shescape: Path disclosure on Unix with Zsh

Shescape: Path disclosure on Unix with Zsh

▾ Sunlitshescape · shescapevia GHSA
GHSA-w4hw-qcx7-56prCritical
2mo ago

Shescape: Shell injection via unescaped parentheses on Windows with CMD

Shescape: Shell injection via unescaped parentheses on Windows with CMD

▾ Midnightshescape · shescapevia GHSA
GHSA-q53c-4prm-w95qMedium
2mo ago

Shescape: Home-directory disclosure in assignment context on Unix with Dash

Shescape: Home-directory disclosure in assignment context on Unix with Dash

▾ Sunlitshescape · shescapevia GHSA
GHSA-gm3r-q2wp-hw87High
2mo ago

Shescape: Quadratic-time denial of service in the flag-protection

Shescape: Quadratic-time denial of service in the flag-protection

▾ Twilightshescape · shescapevia GHSA
GHSA-3r53-75j5-3g7jMedium· 5.6
2mo ago

Quasar: Prototype pollution in the extend() utility

Quasar: Prototype pollution in the extend() utility

▾ Sunlitquasar · quasarvia GHSA
CVE-2026-44907High· 7.5
2mo ago

react-server-dom: Denial of Service in Server Functions

react-server-dom: Denial of Service in Server Functions

▾ Twilightreact-server-dom-webpack · react-server-dom-webpackEPSS 0.60%via GHSA
GHSA-j9fc-w3mr-x6mvHigh· 8.8
2mo ago

Budibase: Privilege escalation via public role assignment API missing app-level authorization

Budibase: Privilege escalation via public role assignment API missing app-level authorization

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-4qcj-m5wp-jmf4Medium· 4.3
2mo ago

Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings

Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-fcrw-f7gg-6g9fMedium· 4.9
2mo ago

Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users

Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-c8vc-7pv3-g98pHigh
2mo ago

Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)

Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-q6x4-v3qx-85qwCritical· 9.6
2mo ago

Budibase: SQL Injection via `multipleStatements: true`

Budibase: SQL Injection via `multipleStatements: true`

▾ Midnightbudibase · @budibase/servervia GHSA
GHSA-ppr4-5f46-j9c6High
2mo ago

Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile

Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-xcx6-4f2g-hhgxHigh· 7.7
2mo ago

Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs

Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-xg5g-26x8-cvf4High· 8.5
2mo ago

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-hp6v-6jw7-gv2fCritical
2mo ago

Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified

Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified

▾ Midnightbudibase · @budibase/servervia GHSA
GHSA-mqhr-6j6h-74p5Critical
2mo ago

Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak

Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak

▾ Midnightbudibase · @budibase/servervia GHSA
GHSA-hr66-5mqr-8mpxHigh· 7.5
2mo ago

Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-gh4h-34gr-87r7Medium· 5.7
2mo ago

Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders

Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders

▾ Sunlitbudibase · @budibase/servervia GHSA
CVEs tagged “npm” — page 15 · VulnSea