| shell-quote |
CVE-2026-9277 |
严重 |
1.8.2 |
1.8.4 |
shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-9277
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| @grpc/grpc-js |
CVE-2026-48068 |
高危 |
1.8.22 |
1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, 1.14.4 |
@grpc/grpc-js: A malformed request can cause a server crash
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48068
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| @grpc/grpc-js |
CVE-2026-48069 |
高危 |
1.8.22 |
1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, 1.14.4 |
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48069
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| @grpc/grpc-js |
CVE-2026-48069 |
高危 |
1.8.22 |
1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, 1.14.4 |
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48069
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| @opentelemetry/auto-instrumentations-node |
CVE-2026-44902 |
高危 |
0.56.1 |
0.75.0 |
Prometheus exporter process crash via malformed HTTP request
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44902
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-27 15:16 修改: 2026-05-29 15:42
|
| @opentelemetry/auto-instrumentations-node |
CVE-2026-44902 |
高危 |
0.56.1 |
0.75.0 |
Prometheus exporter process crash via malformed HTTP request
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44902
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-27 15:16 修改: 2026-05-29 15:42
|
| @opentelemetry/exporter-prometheus |
CVE-2026-44902 |
高危 |
0.57.2 |
0.217.0 |
Prometheus exporter process crash via malformed HTTP request
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44902
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-27 15:16 修改: 2026-05-29 15:42
|
| @opentelemetry/exporter-prometheus |
CVE-2026-44902 |
高危 |
0.57.2 |
0.217.0 |
Prometheus exporter process crash via malformed HTTP request
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44902
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-27 15:16 修改: 2026-05-29 15:42
|
| @opentelemetry/sdk-node |
CVE-2026-44902 |
高危 |
0.57.2 |
0.217.0 |
Prometheus exporter process crash via malformed HTTP request
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44902
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-27 15:16 修改: 2026-05-29 15:42
|
| @opentelemetry/sdk-node |
CVE-2026-44902 |
高危 |
0.57.2 |
0.217.0 |
Prometheus exporter process crash via malformed HTTP request
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44902
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-27 15:16 修改: 2026-05-29 15:42
|
| axios |
CVE-2026-44486 |
高危 |
1.15.2 |
1.16.0, 0.32.0 |
axios: Axios: Information disclosure of proxy credentials via HTTP redirects
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44486
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-06-11 17:16 修改: 2026-06-13 03:16
|
| axios |
CVE-2026-44486 |
高危 |
1.15.2 |
1.16.0, 0.32.0 |
axios: Axios: Information disclosure of proxy credentials via HTTP redirects
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44486
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-06-11 17:16 修改: 2026-06-13 03:16
|
| axios |
CVE-2026-44487 |
高危 |
1.15.2 |
1.16.0, 0.32.0 |
axios: Axios: Information disclosure of proxy credentials via redirect flows
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44487
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-06-11 17:16 修改: 2026-06-12 19:19
|
| axios |
CVE-2026-44487 |
高危 |
1.15.2 |
1.16.0, 0.32.0 |
axios: Axios: Information disclosure of proxy credentials via redirect flows
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44487
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-06-11 17:16 修改: 2026-06-12 19:19
|
| axios |
CVE-2026-44488 |
高危 |
1.15.2 |
1.16.0 |
axios: Axios: Denial of Service due to unenforced request and response size limits
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44488
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-06-11 17:16 修改: 2026-06-12 19:04
|
| axios |
CVE-2026-44488 |
高危 |
1.15.2 |
1.16.0 |
axios: Axios: Denial of Service due to unenforced request and response size limits
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44488
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-06-11 17:16 修改: 2026-06-12 19:04
|
| axios |
CVE-2026-44492 |
高危 |
1.15.2 |
1.16.0, 0.32.0 |
axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44492
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-06-11 17:16 修改: 2026-06-13 03:16
|
| axios |
CVE-2026-44492 |
高危 |
1.15.2 |
1.16.0, 0.32.0 |
axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44492
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-06-11 17:16 修改: 2026-06-13 03:16
|
| axios |
CVE-2026-44494 |
高危 |
1.15.2 |
1.16.0 |
axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44494
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-06-11 17:16 修改: 2026-06-12 18:01
|
| axios |
CVE-2026-44494 |
高危 |
1.15.2 |
1.16.0 |
axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44494
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-06-11 17:16 修改: 2026-06-12 18:01
|
| axios |
CVE-2026-44496 |
高危 |
1.15.2 |
1.16.0, 0.32.0 |
axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44496
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-06-11 17:16 修改: 2026-06-12 18:00
|
| axios |
CVE-2026-44496 |
高危 |
1.15.2 |
1.16.0, 0.32.0 |
axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44496
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-06-11 17:16 修改: 2026-06-12 18:00
|
| fast-uri |
CVE-2026-6321 |
高危 |
3.1.0 |
3.1.1 |
fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6321
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-04 20:16 修改: 2026-05-12 18:54
|
| fast-uri |
CVE-2026-6321 |
高危 |
3.1.0 |
3.1.1 |
fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6321
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-04 20:16 修改: 2026-05-12 18:54
|
| fast-uri |
CVE-2026-6322 |
高危 |
3.1.0 |
3.1.2 |
fast-uri: fast-uri: URI authority bypass due to improper delimiter handling
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6322
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-05 11:16 修改: 2026-05-12 19:11
|
| fast-uri |
CVE-2026-6322 |
高危 |
3.1.0 |
3.1.2 |
fast-uri: fast-uri: URI authority bypass due to improper delimiter handling
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6322
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-05 11:16 修改: 2026-05-12 19:11
|
| fast-xml-parser |
CVE-2026-33036 |
高危 |
4.5.4 |
5.5.6, 4.5.5 |
fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33036
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-03-20 06:16 修改: 2026-03-23 16:28
|
| fast-xml-parser |
CVE-2026-33036 |
高危 |
4.5.4 |
5.5.6, 4.5.5 |
fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33036
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-03-20 06:16 修改: 2026-03-23 16:28
|
| form-data |
CVE-2026-12143 |
高危 |
4.0.5 |
2.5.6, 3.0.5, 4.0.6 |
form-data is a library for creating readable multipart/form-data strea ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-12143
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-06-12 19:16 修改: 2026-06-16 15:42
|
| form-data |
CVE-2026-12143 |
高危 |
4.0.5 |
2.5.6, 3.0.5, 4.0.6 |
form-data is a library for creating readable multipart/form-data strea ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-12143
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-06-12 19:16 修改: 2026-06-16 15:42
|
| hono |
CVE-2026-54290 |
高危 |
4.12.16 |
4.12.25 |
hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54290
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| http-proxy-middleware |
CVE-2026-55603 |
高危 |
3.0.5 |
3.0.7, 4.1.1 |
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55603
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| http-proxy-middleware |
CVE-2026-55603 |
高危 |
3.0.5 |
3.0.7, 4.1.1 |
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55603
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| lodash |
CVE-2026-4800 |
高危 |
4.17.21 |
4.18.0 |
lodash: lodash: Arbitrary code execution via untrusted input in template imports
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4800
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-03-31 20:16 修改: 2026-05-01 18:09
|
| lodash |
CVE-2026-4800 |
高危 |
4.17.21 |
4.18.0 |
lodash: lodash: Arbitrary code execution via untrusted input in template imports
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4800
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-03-31 20:16 修改: 2026-05-01 18:09
|
| lodash |
CVE-2026-4800 |
高危 |
4.17.21 |
4.18.0 |
lodash: lodash: Arbitrary code execution via untrusted input in template imports
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4800
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-03-31 20:16 修改: 2026-05-01 18:09
|
| minimatch |
CVE-2026-26996 |
高危 |
3.1.2 |
10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3 |
minimatch: minimatch: Denial of Service via specially crafted glob patterns
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-26996
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-02-20 03:16 修改: 2026-03-06 21:32
|
| minimatch |
CVE-2026-27903 |
高危 |
3.1.2 |
10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3 |
minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27903
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-02-26 02:16 修改: 2026-02-27 17:21
|
| minimatch |
CVE-2026-27904 |
高危 |
3.1.2 |
10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4 |
minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-27904
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-02-26 02:16 修改: 2026-02-27 17:16
|
| next |
CVE-2026-44573 |
高危 |
16.1.7 |
15.5.16, 16.2.5 |
next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44573
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-13 17:16 修改: 2026-05-14 12:24
|
| next |
CVE-2026-44574 |
高危 |
16.1.7 |
15.5.16, 16.2.5 |
Next.js: Next.js: Authorization bypass via crafted query parameters
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44574
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-13 17:16 修改: 2026-05-14 12:37
|
| next |
CVE-2026-44575 |
高危 |
16.1.7 |
15.5.16, 16.2.5 |
next.js: Next.js: Unauthorized access to protected content via middleware bypass
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44575
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-13 17:16 修改: 2026-05-14 12:38
|
| next |
CVE-2026-44578 |
高危 |
16.1.7 |
15.5.16, 16.2.5 |
Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44578
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-13 18:16 修改: 2026-05-14 18:34
|
| next |
CVE-2026-44579 |
高危 |
16.1.7 |
15.5.16, 16.2.5 |
next.js: Next.js: Denial of Service via crafted POST requests to server actions
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44579
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-13 18:16 修改: 2026-05-14 18:34
|
| next |
CVE-2026-45109 |
高危 |
16.1.7 |
15.5.18, 16.2.6 |
next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45109
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-13 18:16 修改: 2026-05-14 14:14
|
| next |
GHSA-8h8q-6873-q5fj |
高危 |
16.1.7 |
15.5.16, 16.2.5 |
Next.js Vulnerable to Denial of Service with Server Components
漏洞详情: https://github.com/advisories/GHSA-8h8q-6873-q5fj
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-11 14:50 修改: 2026-05-11 14:50
|
| next |
GHSA-q4gf-8mx6-v5v3 |
高危 |
16.1.7 |
15.5.15, 16.2.3 |
Next.js has a Denial of Service with Server Components
漏洞详情: https://github.com/advisories/GHSA-q4gf-8mx6-v5v3
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-04-10 15:35 修改: 2026-04-10 15:35
|
| path-to-regexp |
CVE-2026-4867 |
高危 |
0.1.12 |
0.1.13 |
path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4867
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-03-26 17:16 修改: 2026-04-16 18:01
|
| path-to-regexp |
CVE-2026-4867 |
高危 |
0.1.12 |
0.1.13 |
path-to-regexp: path-to-regexp: Denial of Service via catastrophic backtracking from malformed URL parameters
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-4867
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-03-26 17:16 修改: 2026-04-16 18:01
|
| protobufjs |
CVE-2026-48712 |
高危 |
7.5.8 |
7.6.1, 8.4.1 |
protobufjs: Denial of service through unbounded Any expansion during JSON conversion
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48712
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| protobufjs |
CVE-2026-48712 |
高危 |
7.5.8 |
7.6.1, 8.4.1 |
protobufjs: Denial of service through unbounded Any expansion during JSON conversion
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48712
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| serialize-javascript |
GHSA-5c6j-r48x-rmvq |
高危 |
6.0.2 |
7.0.3 |
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
漏洞详情: https://github.com/advisories/GHSA-5c6j-r48x-rmvq
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-02-28 02:50 修改: 2026-03-02 16:17
|
| @grpc/grpc-js |
CVE-2026-48068 |
高危 |
1.8.22 |
1.9.16, 1.10.12, 1.11.4, 1.12.7, 1.13.5, 1.14.4 |
@grpc/grpc-js: A malformed request can cause a server crash
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48068
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| systeminformation |
CVE-2026-26280 |
高危 |
5.30.7 |
5.30.8 |
systeminformation: systeminformation: Arbitrary command execution via unsanitized network interface parameter
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-26280
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-02-19 20:25 修改: 2026-02-20 20:10
|
| systeminformation |
CVE-2026-26318 |
高危 |
5.30.7 |
5.31.0 |
systeminformation: systeminformation: Arbitrary code execution via unsanitized `locate` output
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-26318
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-02-19 20:25 修改: 2026-02-20 19:51
|
| systeminformation |
CVE-2026-44724 |
高危 |
5.30.7 |
5.31.6 |
systeminformation: systeminformation: Command injection via NetworkManager connection profile name
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44724
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-27 20:16 修改: 2026-06-01 18:50
|
| validator |
CVE-2025-12758 |
高危 |
13.15.0 |
13.15.22 |
Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-12758
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2025-11-27 05:16 修改: 2026-01-29 23:16
|
| hono |
CVE-2026-54288 |
中危 |
4.12.16 |
4.12.25 |
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54288
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| hono |
CVE-2026-54289 |
中危 |
4.12.16 |
4.12.25 |
hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54289
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| axios |
CVE-2026-44490 |
中危 |
1.15.2 |
1.16.0, 0.32.0 |
axios: Axios: Information disclosure and denial of service due to prototype pollution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44490
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-06-11 17:16 修改: 2026-06-15 16:31
|
| axios |
CVE-2026-44490 |
中危 |
1.15.2 |
1.16.0, 0.32.0 |
axios: Axios: Information disclosure and denial of service due to prototype pollution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44490
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-06-11 17:16 修改: 2026-06-15 16:31
|
| http-proxy-middleware |
CVE-2026-55602 |
中危 |
3.0.5 |
3.0.6, 4.1.0, 2.0.10 |
http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55602
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| http-proxy-middleware |
CVE-2026-55602 |
中危 |
3.0.5 |
3.0.6, 4.1.0, 2.0.10 |
http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55602
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| ip-address |
CVE-2026-42338 |
中危 |
10.1.0 |
10.1.1 |
ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42338
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-12 20:16 修改: 2026-05-19 20:04
|
| ip-address |
CVE-2026-42338 |
中危 |
9.0.5 |
10.1.1 |
ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42338
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-12 20:16 修改: 2026-05-19 20:04
|
| ip-address |
CVE-2026-42338 |
中危 |
9.0.5 |
10.1.1 |
ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42338
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-12 20:16 修改: 2026-05-19 20:04
|
| js-yaml |
CVE-2026-53550 |
中危 |
4.1.1 |
4.2.0 |
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-53550
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| brace-expansion |
CVE-2026-33750 |
中危 |
2.0.2 |
5.0.5, 3.0.2, 2.0.3, 1.1.13 |
brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33750
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-03-27 15:16 修改: 2026-04-22 14:23
|
| @opentelemetry/core |
CVE-2026-54285 |
中危 |
1.30.1 |
2.8.0 |
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54285
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| @opentelemetry/core |
CVE-2026-54285 |
中危 |
1.30.1 |
2.8.0 |
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54285
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| lodash |
CVE-2025-13465 |
中危 |
4.17.21 |
4.17.23 |
lodash: prototype pollution in _.unset and _.omit functions
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13465
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-01-21 20:16 修改: 2026-06-02 14:16
|
| lodash |
CVE-2025-13465 |
中危 |
4.17.21 |
4.17.23 |
lodash: prototype pollution in _.unset and _.omit functions
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13465
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-01-21 20:16 修改: 2026-06-02 14:16
|
| lodash |
CVE-2025-13465 |
中危 |
4.17.21 |
4.17.23 |
lodash: prototype pollution in _.unset and _.omit functions
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-13465
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-01-21 20:16 修改: 2026-06-02 14:16
|
| lodash |
CVE-2026-2950 |
中危 |
4.17.21 |
4.18.0 |
lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2950
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-03-31 20:16 修改: 2026-04-07 16:12
|
| lodash |
CVE-2026-2950 |
中危 |
4.17.21 |
4.18.0 |
lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2950
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-03-31 20:16 修改: 2026-04-07 16:12
|
| lodash |
CVE-2026-2950 |
中危 |
4.17.21 |
4.18.0 |
lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-2950
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-03-31 20:16 修改: 2026-04-07 16:12
|
| @babel/runtime |
CVE-2025-27789 |
中危 |
7.24.6 |
7.26.10, 8.0.0-alpha.17 |
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-27789
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2025-03-11 20:15 修改: 2026-04-15 00:35
|
| @opentelemetry/core |
CVE-2026-54285 |
中危 |
1.15.2 |
2.8.0 |
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54285
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| @opentelemetry/core |
CVE-2026-54285 |
中危 |
1.15.2 |
2.8.0 |
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54285
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| nanoid |
CVE-2024-55565 |
中危 |
3.3.7 |
5.0.9, 3.3.8 |
nanoid: nanoid mishandles non-integer values
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-55565
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2024-12-09 02:15 修改: 2026-04-15 00:35
|
| @opentelemetry/core |
CVE-2026-54285 |
中危 |
1.25.1 |
2.8.0 |
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54285
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| fast-xml-parser |
CVE-2026-33349 |
中危 |
4.5.4 |
4.5.5, 5.5.7 |
fast-xml-parser: fast-xml-parser: Denial of Service via unbounded entity expansion due to incorrect configuration limit handling
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33349
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-03-24 20:16 修改: 2026-03-26 13:01
|
| fast-xml-parser |
CVE-2026-33349 |
中危 |
4.5.4 |
4.5.5, 5.5.7 |
fast-xml-parser: fast-xml-parser: Denial of Service via unbounded entity expansion due to incorrect configuration limit handling
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-33349
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-03-24 20:16 修改: 2026-03-26 13:01
|
| fast-xml-parser |
CVE-2026-41650 |
中危 |
4.5.4 |
5.7.0 |
fast-xml-parser: fast-xml-parser: XML injection via improper escaping of comment and CDATA sequences
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41650
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-07 15:16 修改: 2026-05-12 20:30
|
| fast-xml-parser |
CVE-2026-41650 |
中危 |
4.5.4 |
5.7.0 |
fast-xml-parser: fast-xml-parser: XML injection via improper escaping of comment and CDATA sequences
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41650
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-07 15:16 修改: 2026-05-12 20:30
|
| follow-redirects |
GHSA-r4q5-vmmm-2653 |
中危 |
1.15.11 |
1.16.0 |
follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets
漏洞详情: https://github.com/advisories/GHSA-r4q5-vmmm-2653
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-04-14 01:11 修改: 2026-04-14 01:11
|
| follow-redirects |
GHSA-r4q5-vmmm-2653 |
中危 |
1.15.11 |
1.16.0 |
follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets
漏洞详情: https://github.com/advisories/GHSA-r4q5-vmmm-2653
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-04-14 01:11 修改: 2026-04-14 01:11
|
| @opentelemetry/core |
CVE-2026-54285 |
中危 |
1.25.1 |
2.8.0 |
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54285
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| next |
CVE-2026-44576 |
中危 |
16.1.7 |
15.5.16, 16.2.5 |
Next.js: Next.js: Cache poisoning vulnerability in React Server Components
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44576
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-13 17:16 修改: 2026-05-14 13:44
|
| next |
CVE-2026-44577 |
中危 |
16.1.7 |
15.5.16, 16.2.5 |
Next.js: Next.js: Denial of Service via Image Optimization API
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44577
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-13 17:16 修改: 2026-05-13 20:00
|
| next |
CVE-2026-44580 |
中危 |
16.1.7 |
15.5.16, 16.2.5 |
Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44580
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-13 18:16 修改: 2026-05-14 18:33
|
| next |
CVE-2026-44581 |
中危 |
16.1.7 |
15.5.16, 16.2.5 |
next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44581
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-13 18:16 修改: 2026-05-14 18:30
|
| @opentelemetry/core |
CVE-2026-54285 |
中危 |
1.25.1 |
2.8.0 |
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54285
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| @opentelemetry/core |
CVE-2026-54285 |
中危 |
1.25.1 |
2.8.0 |
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54285
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| postcss |
CVE-2026-41305 |
中危 |
8.4.31 |
8.5.10 |
postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41305
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-04-24 03:16 修改: 2026-04-24 17:16
|
| hono |
CVE-2026-44457 |
中危 |
4.12.16 |
4.12.18 |
Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44457
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-13 16:16 修改: 2026-05-13 18:34
|
| hono |
CVE-2026-44458 |
中危 |
4.12.16 |
4.12.18 |
Hono has CSS Declaration Injection via Style Object Values in JSX SSR
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44458
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-13 16:16 修改: 2026-05-13 18:32
|
| protobufjs |
CVE-2026-54269 |
中危 |
7.5.8 |
7.6.3, 8.6.0 |
protobufjs : Schema-derived names can shadow runtime-significant properties
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54269
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| protobufjs |
CVE-2026-54269 |
中危 |
7.5.8 |
7.6.3, 8.6.0 |
protobufjs : Schema-derived names can shadow runtime-significant properties
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54269
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| qs |
CVE-2026-8723 |
中危 |
6.14.2 |
6.15.2 |
### Summary `qs.stringify` throws `TypeError` when called with `arr ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8723
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-17 00:16 修改: 2026-05-18 20:23
|
| qs |
CVE-2026-8723 |
中危 |
6.14.2 |
6.15.2 |
### Summary `qs.stringify` throws `TypeError` when called with `arr ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8723
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-17 00:16 修改: 2026-05-18 20:23
|
| hono |
CVE-2026-47673 |
中危 |
4.12.16 |
4.12.21 |
Hono: JWT middleware accepts any Authorization scheme, not only Bearer
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47673
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-28 17:16 修改: 2026-05-29 17:05
|
| serialize-javascript |
CVE-2026-34043 |
中危 |
6.0.2 |
7.0.5 |
serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34043
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-03-31 03:15 修改: 2026-04-03 16:53
|
| hono |
CVE-2026-47674 |
中危 |
4.12.16 |
4.12.21 |
Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47674
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-28 17:16 修改: 2026-05-29 16:57
|
| hono |
CVE-2026-47675 |
中危 |
4.12.16 |
4.12.21 |
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47675
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-28 17:16 修改: 2026-05-29 16:56
|
| hono |
CVE-2026-47676 |
中危 |
4.12.16 |
4.12.21 |
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-47676
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-28 17:16 修改: 2026-05-29 16:55
|
| hono |
CVE-2026-54286 |
中危 |
4.12.16 |
4.12.25 |
hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54286
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| uuid |
CVE-2026-41907 |
中危 |
8.3.2 |
11.1.1, 12.0.1, 13.0.1 |
uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41907
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-04-24 19:17 修改: 2026-05-11 13:53
|
| uuid |
CVE-2026-41907 |
中危 |
8.3.2 |
11.1.1, 12.0.1, 13.0.1 |
uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41907
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-04-24 19:17 修改: 2026-05-11 13:53
|
| hono |
CVE-2026-54287 |
中危 |
4.12.16 |
4.12.25 |
hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54287
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 0001-01-01 00:00 修改: 0001-01-01 00:00
|
| validator |
CVE-2025-56200 |
中危 |
13.15.0 |
13.15.20 |
validator.js has a URL validation bypass vulnerability in its isURL function
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-56200
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2025-09-30 18:15 修改: 2025-10-18 01:48
|
| next |
CVE-2026-44582 |
低危 |
16.1.7 |
15.5.16, 16.2.5 |
Next.js: Next.js: Cache poisoning allows incorrect response delivery
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44582
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-13 18:16 修改: 2026-05-14 18:15
|
| axios |
CVE-2026-44489 |
低危 |
1.15.2 |
1.16.0 |
axios: Axios: Information disclosure via Prototype Pollution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44489
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-06-11 17:16 修改: 2026-06-15 16:13
|
| axios |
CVE-2026-44489 |
低危 |
1.15.2 |
1.16.0 |
axios: Axios: Information disclosure via Prototype Pollution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44489
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-06-11 17:16 修改: 2026-06-15 16:13
|
| hono |
CVE-2026-44459 |
低危 |
4.12.16 |
4.12.18 |
Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44459
镜像层: sha256:4bdcfde779836e1f822ad0952d397a8f15a57402378a5f2784a2ab7680f92d21
发布日期: 2026-05-13 16:16 修改: 2026-05-13 18:21
|
| next |
CVE-2026-44572 |
低危 |
16.1.7 |
15.5.16, 16.2.5 |
next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44572
镜像层: sha256:04916a151b3ca5a3523ab6f2401203a461c4cc2f936dff948a7f7409f906f17a
发布日期: 2026-05-13 16:16 修改: 2026-05-15 15:46
|