Open Source Vulnerabilities
@xmldom/xmldom
xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator
@xmldom/xmldom
xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator
@xmldom/xmldom, @xmldom/xmldom, xmldom
xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content
@xmldom/xmldom/ @xmldom/xmldom/ xmldom
xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content
@xmldom/xmldom, @xmldom/xmldom, xmldom
xmldom: Quadratic-time attribute deduplication
@xmldom/xmldom/ @xmldom/xmldom/ xmldom
xmldom: Quadratic-time attribute deduplication
@xmldom/xmldom
xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser
@xmldom/xmldom
xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser
@xmldom/xmldom, @xmldom/xmldom, xmldom
xmldom: Quadratic-memory consumption
@xmldom/xmldom/ @xmldom/xmldom/ xmldom
xmldom: Quadratic-memory consumption
@xmldom/xmldom, @xmldom/xmldom, xmldom
xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
@xmldom/xmldom/ @xmldom/xmldom/ xmldom
xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
@xmldom/xmldom
xmldom: HTML raw-text closing-tag case mismatch causes output amplification
@xmldom/xmldom
xmldom: HTML raw-text closing-tag case mismatch causes output amplification
predis/predis
Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections
predis/predis
Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections
cakephp/cakephp, cakephp/cakephp, cakephp/cakephp, cakephp/database, cakephp/database, cakephp/database
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
cakephp/cakephp/ cakephp/cakephp/ cakephp/cakephp/ cakephp/database/ cakephp/database/ cakephp/database
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
cakephp/cakephp, cakephp/cakephp, cakephp/cakephp, cakephp/cakephp, cakephp/cakephp
CakePHP: SmtpTransport vulnerable to CRLF header injection
cakephp/cakephp/ cakephp/cakephp/ cakephp/cakephp/ cakephp/cakephp/ cakephp/cakephp
CakePHP: SmtpTransport vulnerable to CRLF header injection
joi, @hapi/joi, joi
joi: Prototype pollution via a `__proto__` language key in custom messages
joi/ @hapi/joi/ joi
joi: Prototype pollution via a `__proto__` language key in custom messages
colord
Colord: Slow rejection of oversized malformed color strings
colord
Colord: Slow rejection of oversized malformed color strings
next, next
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
next/ next
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
joi, joi
joi: object().rename() with a template target can set the validated object's prototype
joi/ joi
joi: object().rename() with a template target can set the validated object's prototype
maplibre-gl
MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip
maplibre-gl
MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip
google.golang.org/grpc
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
google.golang.org/grpc
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
httpx2
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
httpx2
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
@vitest/mocker, vitest, vitest, @vitest/mocker
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
@vitest/mocker/ vitest/ vitest/ @vitest/mocker
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
httpx2
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
httpx2
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
httpx2
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
httpx2
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
httpx2
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
httpx2
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
httpcore2, httpx2
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
httpcore2/ httpx2
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
vllm
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
vllm
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
maatwebsite/excel
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path
maatwebsite/excel
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path
@xmldom/xmldom
xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions
@xmldom/xmldom
xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions
@xmldom/xmldom, @xmldom/xmldom, xmldom
xmldom: Element name injection via createElement() bypasses requireWellFormed
@xmldom/xmldom/ @xmldom/xmldom/ xmldom
xmldom: Element name injection via createElement() bypasses requireWellFormed
@xmldom/xmldom, @xmldom/xmldom, xmldom
xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed
@xmldom/xmldom/ @xmldom/xmldom/ xmldom
xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed
Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64
Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability
Microsoft.WindowsDesktop.App.Runtime.win-x64/ Microsoft.WindowsDesktop.App.Runtime.win-x86/ Microsoft.WindowsDesktop.App.Runtime.win-arm64/ Microsoft.WindowsDesktop.App.Runtime.win-x64/ Microsoft.WindowsDesktop.App.Runtime.win-x86/ Microsoft.WindowsDesktop.App.Runtime.win-arm64/ Microsoft.WindowsDesktop.App.Runtime.win-x64/ Microsoft.WindowsDesktop.App.Runtime.win-x86/ Microsoft.WindowsDesktop.App.Runtime.win-arm64
Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability
nltk
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks
nltk
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks
nltk
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
nltk
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
nltk
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
nltk
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
Microsoft.Native.Quic.MsQuic.OpenSSL, Microsoft.Native.Quic.MsQuic.Schannel, Microsoft.Native.Quic.MsQuic.OpenSSL, Microsoft.Native.Quic.MsQuic.Schannel
Microsoft QUIC: Remote Code Execution Vulnerability
Microsoft.Native.Quic.MsQuic.OpenSSL/ Microsoft.Native.Quic.MsQuic.Schannel/ Microsoft.Native.Quic.MsQuic.OpenSSL/ Microsoft.Native.Quic.MsQuic.Schannel
Microsoft QUIC: Remote Code Execution Vulnerability
Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git, Microsoft.SourceLink.AzureRepos.Git, Microsoft.SourceLink.AzureRepos.Git, Microsoft.SourceLink.AzureRepos.Git, Microsoft.SourceLink.AzureRepos.Git
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability
Microsoft.Build.Tasks.Git/ Microsoft.Build.Tasks.Git/ Microsoft.Build.Tasks.Git/ Microsoft.Build.Tasks.Git/ Microsoft.SourceLink.AzureRepos.Git/ Microsoft.SourceLink.AzureRepos.Git/ Microsoft.SourceLink.AzureRepos.Git/ Microsoft.SourceLink.AzureRepos.Git
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability
vllm
vLLM: Cross-User Data Leak Vulnerability
libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl
libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl
libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl
libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl
libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl
libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl
libhtml-formhandler-perl/ libhtml-formhandler-perl/ libhtml-formhandler-perl
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method
HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping
HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping
HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message
HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message
Open-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authentication
Open-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authentication
gitpython
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
gitpython
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
