Open Source Vulnerabilities
nodemailer
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
nodemailer
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
nodemailer
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
nodemailer
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
nodemailer
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
nodemailer
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
@typespec/openapi3, @typespec/compiler
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
@typespec/openapi3/ @typespec/compiler
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
multer
multer vulnerable to Denial of Service via crafted multipart field names
multer
multer vulnerable to Denial of Service via crafted multipart field names
multer
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
multer
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
multer
multer vulnerable to file size limit bypass via async fileFilter race condition
multer
multer vulnerable to file size limit bypass via async fileFilter race condition
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
n8n: Expression Sandbox Escape in Editor-UI Enables Stored Cross-User JavaScript Execution
n8n: Expression Sandbox Escape in Editor-UI Enables Stored Cross-User JavaScript Execution
multer
multer vulnerable to Denial of Service via oversized array index in field names
multer
multer vulnerable to Denial of Service via oversized array index in field names
morgan
morgan vulnerable to Log Forging via unescaped Unicode line separators
morgan
morgan vulnerable to Log Forging via unescaped Unicode line separators
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
winml-cli
Windows ML CLI: CORS misconfig enables localhost RCE
winml-cli
Windows ML CLI: CORS misconfig enables localhost RCE
mongodb/mongodb, mongodb/mongodb
mongodb: Reject "." and NUL bytes in database and collection names
mongodb/mongodb/ mongodb/mongodb
mongodb: Reject "." and NUL bytes in database and collection names
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
astro
Astro: Remote code execution through AVIF image optimization
astro
Astro: Remote code execution through AVIF image optimization
astro
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
astro
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
composer/composer, composer/composer
Composer arbitrary command execution via a malicious package's Perforce source URL
composer/composer/ composer/composer
Composer arbitrary command execution via a malicious package's Perforce source URL
sharp
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
sharp
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
js-yaml, js-yaml
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
js-yaml/ js-yaml
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
phpseclib, phpseclib
phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery
phpseclib/ phpseclib
phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
@tiptap/core
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
@tiptap/core
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
hono
Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
hono
Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
hono
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
hono
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
hono
Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
hono
Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
google.golang.org/grpc, google.golang.org/grpc, google.golang.org/grpc
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
google.golang.org/grpc/ google.golang.org/grpc/ google.golang.org/grpc
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
next, next
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
next/ next
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
svgo, svgo, svgo
SVGO: removeScripts allows executable links through namespace and control-character bypasses
svgo/ svgo/ svgo
SVGO: removeScripts allows executable links through namespace and control-character bypasses
svgo, svgo, svgo
SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements
svgo/ svgo/ svgo
SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
nodemailer
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
nodemailer
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
@xmldom/xmldom, @xmldom/xmldom, xmldom
xmldom: Processing Instruction Target Injection Bypasses requireWellFormed
@xmldom/xmldom/ @xmldom/xmldom/ xmldom
xmldom: Processing Instruction Target Injection Bypasses requireWellFormed
@xmldom/xmldom
xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator
@xmldom/xmldom
xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator
@xmldom/xmldom, @xmldom/xmldom, xmldom
xmldom: DocType `name` Injection Bypasses requireWellFormed
@xmldom/xmldom/ @xmldom/xmldom/ xmldom
xmldom: DocType `name` Injection Bypasses requireWellFormed
@xmldom/xmldom
xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path
@xmldom/xmldom
xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path
