Tagged “npm”
CVEs tagged npm, newest first.
1010 CVEsRSS
CVE-2026-54269Medium· 5.3protobufjs : Schema-derived names can shadow runtime-significant properties
protobufjs : Schema-derived names can shadow runtime-significant properties
CVE-2026-48712High· 7.5protobufjs: Denial of service through unbounded Any expansion during JSON conversion
protobufjs: Denial of service through unbounded Any expansion during JSON conversion
GHSA-r7g4-qg5f-qqm2Medium· 6.5Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
GHSA-wqvq-jvpq-h66fMedium· 5.4Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
GHSA-268h-hp4c-crq3Medium· 5.4Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
CVE-2026-49459Medium· 6.1DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
CVE-2026-49458Medium· 6.1DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
GHSA-76mc-f452-cxcmMedium· 6.1DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`
DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`
GHSA-x4vx-rjvf-j5p4LowDOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects
DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects
GHSA-gvmj-g25r-r7wrLowDOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes
DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes
CVE-2026-53633Critical· 9.8Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
CVE-2026-53663Low· 3.1React Router: Potential CSRF via PUT/PATCH/DELETE document requests
React Router: Potential CSRF via PUT/PATCH/DELETE document requests
GHSA-vxr8-fq34-vvx9LowDOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output
DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output
CVE-2026-54270Medium· 5.3protobufjs: Memory amplification from preserved unknown fields in binary decode
protobufjs: Memory amplification from preserved unknown fields in binary decode
CVE-2026-54271High· 8.2protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names
protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names
CVE-2026-48125Medium· 5.3UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`
UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`
CVE-2026-54257CriticalElectron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
CVE-2026-54281HighNest: Middleware Bypass on Fastify via Trailing Slash
Nest: Middleware Bypass on Fastify via Trailing Slash
CVE-2026-54285Medium· 5.3OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
CVE-2026-48988Medium· 5.3markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
CVE-2026-11417High· 7.3PoCaws-cdk-lib: OS Command Injection in NodejsFunction Bundling
aws-cdk-lib: OS Command Injection in NodejsFunction Bundling
GHSA-rq7w-g337-39qqLowNuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`
Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`
CVE-2026-30120Critical· 9.8Remotion: remote code execution (RCE) vulnerability
Remotion: remote code execution (RCE) vulnerability
CVE-2026-30121Critical· 9.1Remotion: arbitrary file write vulnerability
Remotion: arbitrary file write vulnerability
CVE-2026-5038High· 7.5⚖ disputedmulter: Multer: Denial of Service via aborted or malformed multipart uploads (CVE-2026-5038)
A flaw was found in multer. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by initiating and then aborting or sending malformed multipart uploads. This action leaves orphaned partial files on the disk, whi…
CVE-2026-5079High· 7.5multer: Multer: Denial of Service via deeply nested field names in multipart form data (CVE-2026-5079)
A flaw was found in Multer. A remote attacker can exploit this vulnerability by sending a single HTTP request with crafted multipart form data containing deeply nested field names. This can force the allocation of deeply nested object stru…
CVE-2026-48128MediumBudibase: SSRF via User-Controlled queryId in Automation Execute Query Step
Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step
CVE-2026-48146High· 7.7Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
CVE-2026-48147Medium· 6.5Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
CVE-2026-48148MediumBudibase: Unvalidated VectorDB Host Parameter Enables SSRF
Budibase: Unvalidated VectorDB Host Parameter Enables SSRF