Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-jp82-f5mq-hwhp
  • npm/seroval
Seroval: Memory exhaustion via unchecked TypedArray length in JSON... 11 minutes ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-jqcg-44mw-7w3h
  • npm/proxy-addr
proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet 21 minutes ago
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-2mjx-qc3c-rqvc
  • crates.io/rustls
Rustls: TLS 1.3 handshake messages incorrectly accepted across encryption level... 21 minutes ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-6vc5-vf29-ffr2
  • npm/@nx/docker
@nx/docker: OS command injection in the @nx/docker release pipeline 22 minutes ago
  • Fix available
  • Severity - 7.3 (High)
GHSA-w2vw-w76x-qr89
  • npm/nx
Nx: OS command injection via git revisions and remote refs 23 minutes ago
  • Fix available
  • Severity - 8.5 (High)
GHSA-w3vv-58gj-gw77
  • npm/nx
Nx daemon and plugin worker sockets are accessible to other local users 23 minutes ago
  • Fix available
  • Severity - 8.5 (High)
GHSA-hrvq-x7jp-36xv
  • npm/nx
Nx: Path traversal in nx migrate package-migrations extraction 23 minutes ago
  • Fix available
  • Severity - 5.8 (Medium)
GHSA-vc2v-76pw-4v95
  • npm/compression
compression vulnerable to Denial of Service via memory leak on premature... 24 minutes ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-g7fw-3gjp-g5hf
  • npm/@openclaw/feishu
  • npm/@openclaw/googlechat
  • npm/@openclaw/matrix
  • npm/@openclaw/msteams
OpenClaw: Channel read actions could skip target allowlists 24 minutes ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-8fvv-fgr5-f8ch
  • PyPI/pymongo
pymongo: PYTHON-5994 Use exact match for file ID in GridFS delete methods 24 minutes ago
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-8fxw-fmj8-xp7j
  • Packagist/mongodb/mongodb
MongoDB: GridFS data disclosure and deletion via query-operator injection in... 25 minutes ago
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-5h3f-q97h-ccvc
  • npm/vm2
vm2: NodeVM custom resolution bypasses external path boundaries 27 minutes ago
  • Fix available
  • Severity - 9.5 (Critical)
GHSA-2v2p-6j97-cjg9
  • npm/vm2
vm2: Host Promise rejection from an exposed constructor can terminate the vm2... 32 minutes ago
  • Fix available
  • Severity - 8.9 (High)
GHSA-489w-w794-jq94
  • npm/vm2
vm2: NodeVM zlib Buffers expose pooled host memory across the VM boundary 51 minutes ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-6fw5-9hq8-w87g
  • npm/@graphql-tools/executor-legacy-ws
GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket... 55 minutes ago
  • Fix available
  • Severity - 7.4 (High)
GHSA-7mx3-vvmw-hjmv
  • npm/@graphql-tools/utils
GraphQL Tools has prototype pollution in well-established utility function... 55 minutes ago
  • Fix available
  • Severity - 8.2 (High)