| tar |
CVE-2026-59873 |
严重 |
7.5.15 |
7.5.19 |
tar: node-tar: Denial of Service via crafted gzip bomb
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59873
镜像层: sha256:56224b926eb7d8392d979f8c18df796b6646d595a5a7684682bb10815f41ccc1
发布日期: 2026-07-08 16:16 修改: 2026-07-10 18:57
|
| tar |
CVE-2026-59873 |
严重 |
7.5.16 |
7.5.19 |
tar: node-tar: Denial of Service via crafted gzip bomb
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59873
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-08 16:16 修改: 2026-07-10 18:57
|
| axios |
GHSA-gcfj-64vw-6mp9 |
高危 |
1.16.1 |
0.33.0, 1.18.0 |
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
漏洞详情: https://github.com/advisories/GHSA-gcfj-64vw-6mp9
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:40 修改: 2026-07-20 22:40
|
| brace-expansion |
CVE-2026-13149 |
高危 |
2.1.0 |
5.0.7, 1.1.16, 2.1.2 |
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-13149
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-30 10:16 修改: 2026-07-08 12:17
|
| brace-expansion |
CVE-2026-13149 |
高危 |
5.0.6 |
5.0.7, 1.1.16, 2.1.2 |
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-13149
镜像层: sha256:56224b926eb7d8392d979f8c18df796b6646d595a5a7684682bb10815f41ccc1
发布日期: 2026-06-30 10:16 修改: 2026-07-08 12:17
|
| brace-expansion |
CVE-2026-13149 |
高危 |
5.0.6 |
5.0.7, 1.1.16, 2.1.2 |
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-13149
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-30 10:16 修改: 2026-07-08 12:17
|
| form-data |
CVE-2026-12143 |
高危 |
4.0.4 |
2.5.6, 3.0.5, 4.0.6 |
form-data: form-data: Form field override via CRLF injection
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-12143
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-12 19:16 修改: 2026-07-20 12:17
|
| http-proxy-middleware |
CVE-2026-55603 |
高危 |
3.0.5 |
3.0.7, 4.1.1 |
http-proxy-middleware: http-proxy-middleware: Data integrity compromise via CR/LF injection
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55603
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-22 21:16 修改: 2026-06-24 16:44
|
| js-yaml |
CVE-2026-59869 |
高危 |
4.1.1 |
3.15.0, 4.3.0 |
js-yaml: js-yaml: Denial of Service via crafted YAML documents
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59869
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-08 16:16 修改: 2026-07-13 15:05
|
| linkify-it |
CVE-2026-48801 |
高危 |
5.0.0 |
5.0.1 |
linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48801
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-14 21:17 修改: 2026-07-15 20:21
|
| multer |
CVE-2026-5079 |
高危 |
2.1.1 |
2.2.0, 3.0.0-alpha.2 |
Multer vulnerable to Denial of Service via deeply nested field names
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5079
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-15 14:16 修改: 2026-06-17 10:58
|
| nodemailer |
GHSA-p6gq-j5cr-w38f |
高危 |
8.0.10 |
9.0.1 |
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
漏洞详情: https://github.com/advisories/GHSA-p6gq-j5cr-w38f
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-18 14:28 修改: 2026-06-18 14:28
|
| protobufjs |
CVE-2026-48712 |
高危 |
7.5.8 |
7.6.1, 8.4.1 |
protobufjs: protobufjs: Denial of Service via uncontrolled recursion with crafted protobuf payload
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-48712
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-22 18:16 修改: 2026-06-26 20:04
|
| shell-quote |
CVE-2026-13311 |
高危 |
1.8.4 |
1.9.0 |
shell-quote: shell-quote/parse: shell-quote: Denial of Service due to inefficient input parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-13311
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-25 05:16 修改: 2026-06-26 19:03
|
| adm-zip |
CVE-2026-39244 |
高危 |
0.5.16 |
0.6.0 |
adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-39244
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-10 17:16 修改: 2026-07-10 19:17
|
| tar |
CVE-2026-59874 |
高危 |
7.5.15 |
7.5.18 |
tar: Node-tar: Denial of Service via malformed tar archive header
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59874
镜像层: sha256:56224b926eb7d8392d979f8c18df796b6646d595a5a7684682bb10815f41ccc1
发布日期: 2026-07-08 16:16 修改: 2026-07-10 18:54
|
| axios |
GHSA-gcfj-64vw-6mp9 |
高危 |
1.16.1 |
0.33.0, 1.18.0 |
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
漏洞详情: https://github.com/advisories/GHSA-gcfj-64vw-6mp9
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:40 修改: 2026-07-20 22:40
|
| tar |
CVE-2026-59874 |
高危 |
7.5.16 |
7.5.18 |
tar: Node-tar: Denial of Service via malformed tar archive header
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59874
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-08 16:16 修改: 2026-07-10 18:54
|
| tmp |
CVE-2026-49982 |
高危 |
0.2.6 |
0.2.7 |
tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-49982
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-11 17:16 修改: 2026-06-17 10:55
|
| undici |
CVE-2026-12151 |
高危 |
6.24.1 |
6.27.0, 7.28.0, 8.5.0 |
undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-12151
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-17 17:16 修改: 2026-07-16 12:17
|
| undici |
CVE-2026-12151 |
高危 |
6.26.0 |
6.27.0, 7.28.0, 8.5.0 |
undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-12151
镜像层: sha256:56224b926eb7d8392d979f8c18df796b6646d595a5a7684682bb10815f41ccc1
发布日期: 2026-06-17 17:16 修改: 2026-07-16 12:17
|
| undici |
CVE-2026-12151 |
高危 |
7.27.2 |
6.27.0, 7.28.0, 8.5.0 |
undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-12151
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-17 17:16 修改: 2026-07-16 12:17
|
| undici |
CVE-2026-6734 |
高危 |
7.27.2 |
7.28.0, 8.2.0 |
undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6734
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-17 18:18 修改: 2026-07-16 12:18
|
| undici |
CVE-2026-9697 |
高危 |
7.27.2 |
7.28.0, 8.5.0 |
undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-9697
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-17 18:18 修改: 2026-07-16 12:18
|
| @opentelemetry/core |
CVE-2026-54285 |
中危 |
2.0.0 |
2.8.0 |
@opentelemetry/core: opentelemetry-js: @opentelemetry/core: Denial of Service via oversized baggage HTTP headers
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54285
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-22 18:16 修改: 2026-06-23 16:17
|
| @opentelemetry/core |
CVE-2026-54285 |
中危 |
2.1.0 |
2.8.0 |
@opentelemetry/core: opentelemetry-js: @opentelemetry/core: Denial of Service via oversized baggage HTTP headers
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54285
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-22 18:16 修改: 2026-06-23 16:17
|
| @opentelemetry/core |
CVE-2026-54285 |
中危 |
2.7.1 |
2.8.0 |
@opentelemetry/core: opentelemetry-js: @opentelemetry/core: Denial of Service via oversized baggage HTTP headers
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54285
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-22 18:16 修改: 2026-06-23 16:17
|
| file-type |
CVE-2026-31808 |
中危 |
16.5.4 |
21.3.1 |
file-type: file-type: Denial of Service due to infinite loop in ASF file parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31808
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-03-10 21:16 修改: 2026-06-17 10:34
|
| axios |
GHSA-42h9-826w-cgv3 |
中危 |
1.16.1 |
0.33.0, 1.18.0 |
Axios: Excessive recursion in formDataToJSON can cause denial of service
漏洞详情: https://github.com/advisories/GHSA-42h9-826w-cgv3
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 17:58 修改: 2026-07-20 17:58
|
| axios |
GHSA-42h9-826w-cgv3 |
中危 |
1.16.1 |
0.33.0, 1.18.0 |
Axios: Excessive recursion in formDataToJSON can cause denial of service
漏洞详情: https://github.com/advisories/GHSA-42h9-826w-cgv3
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 17:58 修改: 2026-07-20 17:58
|
| http-proxy-middleware |
CVE-2026-55602 |
中危 |
3.0.5 |
3.0.6, 4.1.0, 2.0.10 |
http-proxy-middleware: http-proxy-middleware: Unintended backend routing due to crafted Host header
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-55602
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-22 18:16 修改: 2026-06-26 20:06
|
| axios |
GHSA-7q8q-rj6j-mhjq |
中危 |
1.16.1 |
0.33.0, 1.18.0 |
Axios: Nested axios option objects can consume polluted prototype values
漏洞详情: https://github.com/advisories/GHSA-7q8q-rj6j-mhjq
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:37 修改: 2026-07-20 22:37
|
| js-yaml |
CVE-2026-53550 |
中危 |
4.1.1 |
4.2.0, 3.15.0 |
js-yaml: js-yaml: Denial of Service via crafted YAML merge keys
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-53550
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-22 16:16 修改: 2026-07-09 20:33
|
| axios |
GHSA-7q8q-rj6j-mhjq |
中危 |
1.16.1 |
0.33.0, 1.18.0 |
Axios: Nested axios option objects can consume polluted prototype values
漏洞详情: https://github.com/advisories/GHSA-7q8q-rj6j-mhjq
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:37 修改: 2026-07-20 22:37
|
| axios |
GHSA-f4gw-2p7v-4548 |
中危 |
1.16.1 |
1.18.0, 0.33.0 |
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
漏洞详情: https://github.com/advisories/GHSA-f4gw-2p7v-4548
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:20 修改: 2026-07-20 22:20
|
| multer |
CVE-2026-5038 |
中危 |
2.1.1 |
2.2.0, 3.0.0-alpha.2 |
Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-5038
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-15 16:16 修改: 2026-06-17 10:58
|
| axios |
GHSA-f4gw-2p7v-4548 |
中危 |
1.16.1 |
1.18.0, 0.33.0 |
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
漏洞详情: https://github.com/advisories/GHSA-f4gw-2p7v-4548
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:20 修改: 2026-07-20 22:20
|
| axios |
GHSA-hcpx-6fm6-wx23 |
中危 |
1.16.1 |
0.33.0, 1.18.0 |
Axios form serializer maxDepth bypass via {} metatoken
漏洞详情: https://github.com/advisories/GHSA-hcpx-6fm6-wx23
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:38 修改: 2026-07-20 22:38
|
| protobufjs |
CVE-2026-54269 |
中危 |
7.5.8 |
7.6.3, 8.6.0 |
protobufjs: protobufjs-cli: protobufjs: Denial of Service due to name collision with runtime helpers
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54269
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-22 18:16 修改: 2026-06-24 20:40
|
| protobufjs |
CVE-2026-59877 |
中危 |
7.5.8 |
7.6.5, 8.6.6 |
protobufjs: Denial of Service via infinite loop in .proto option parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59877
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-08 16:16 修改: 2026-07-10 18:53
|
| axios |
GHSA-hcpx-6fm6-wx23 |
中危 |
1.16.1 |
0.33.0, 1.18.0 |
Axios form serializer maxDepth bypass via {} metatoken
漏洞详情: https://github.com/advisories/GHSA-hcpx-6fm6-wx23
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:38 修改: 2026-07-20 22:38
|
| showdown |
CVE-2024-1899 |
中危 |
2.1.0 |
|
Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-1899
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2024-02-26 19:15 修改: 2026-06-17 07:05
|
| axios |
GHSA-jqh4-m9w3-8hp9 |
中危 |
1.16.1 |
1.18.0 |
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
漏洞详情: https://github.com/advisories/GHSA-jqh4-m9w3-8hp9
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:27 修改: 2026-07-20 22:27
|
| axios |
GHSA-jqh4-m9w3-8hp9 |
中危 |
1.16.1 |
1.18.0 |
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
漏洞详情: https://github.com/advisories/GHSA-jqh4-m9w3-8hp9
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:27 修改: 2026-07-20 22:27
|
| tar |
CVE-2026-53655 |
中危 |
7.5.15 |
7.5.16 |
node-tar: node-tar: File smuggling due to inconsistent tar archive parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-53655
镜像层: sha256:56224b926eb7d8392d979f8c18df796b6646d595a5a7684682bb10815f41ccc1
发布日期: 2026-06-22 16:16 修改: 2026-06-26 20:03
|
| tar |
CVE-2026-59871 |
中危 |
7.5.15 |
7.5.18 |
node-tar: node-tar: Denial of Service due to incorrect PAX path handling
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59871
镜像层: sha256:56224b926eb7d8392d979f8c18df796b6646d595a5a7684682bb10815f41ccc1
发布日期: 2026-07-08 16:16 修改: 2026-07-10 19:02
|
| tar |
CVE-2026-59875 |
中危 |
7.5.15 |
7.5.17 |
node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59875
镜像层: sha256:56224b926eb7d8392d979f8c18df796b6646d595a5a7684682bb10815f41ccc1
发布日期: 2026-07-08 16:16 修改: 2026-07-10 19:10
|
| axios |
GHSA-mmx7-hfxf-jppx |
中危 |
1.16.1 |
1.18.0, 0.33.0 |
Axios: Prototype pollution gadgets can alter axios request construction
漏洞详情: https://github.com/advisories/GHSA-mmx7-hfxf-jppx
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:25 修改: 2026-07-20 22:25
|
| axios |
GHSA-mmx7-hfxf-jppx |
中危 |
1.16.1 |
1.18.0, 0.33.0 |
Axios: Prototype pollution gadgets can alter axios request construction
漏洞详情: https://github.com/advisories/GHSA-mmx7-hfxf-jppx
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:25 修改: 2026-07-20 22:25
|
| tar |
CVE-2026-59871 |
中危 |
7.5.16 |
7.5.18 |
node-tar: node-tar: Denial of Service due to incorrect PAX path handling
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59871
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-08 16:16 修改: 2026-07-10 19:02
|
| tar |
CVE-2026-59875 |
中危 |
7.5.16 |
7.5.17 |
node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59875
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-08 16:16 修改: 2026-07-10 19:10
|
| axios |
GHSA-mwf2-3pr3-8698 |
中危 |
1.16.1 |
1.18.0 |
Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
漏洞详情: https://github.com/advisories/GHSA-mwf2-3pr3-8698
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:37 修改: 2026-07-20 22:37
|
| axios |
GHSA-mwf2-3pr3-8698 |
中危 |
1.16.1 |
1.18.0 |
Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
漏洞详情: https://github.com/advisories/GHSA-mwf2-3pr3-8698
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 22:37 修改: 2026-07-20 22:37
|
| undici |
CVE-2026-9679 |
中危 |
6.24.1 |
6.27.0, 7.28.0, 8.5.0 |
undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-9679
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-17 18:18 修改: 2026-06-25 17:43
|
| axios |
GHSA-pmv8-rq9r-6j72 |
中危 |
1.16.1 |
0.33.0, 1.18.0 |
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
漏洞详情: https://github.com/advisories/GHSA-pmv8-rq9r-6j72
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 17:48 修改: 2026-07-20 17:48
|
| undici |
CVE-2026-9679 |
中危 |
6.26.0 |
6.27.0, 7.28.0, 8.5.0 |
undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-9679
镜像层: sha256:56224b926eb7d8392d979f8c18df796b6646d595a5a7684682bb10815f41ccc1
发布日期: 2026-06-17 18:18 修改: 2026-06-25 17:43
|
| axios |
GHSA-pmv8-rq9r-6j72 |
中危 |
1.16.1 |
0.33.0, 1.18.0 |
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
漏洞详情: https://github.com/advisories/GHSA-pmv8-rq9r-6j72
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 17:48 修改: 2026-07-20 17:48
|
| axios |
GHSA-xj6q-8x83-jv6g |
中危 |
1.16.1 |
1.18.0 |
Axios: Prototype pollution auth subfields can inject Basic auth
漏洞详情: https://github.com/advisories/GHSA-xj6q-8x83-jv6g
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 17:51 修改: 2026-07-20 17:51
|
| axios |
GHSA-xj6q-8x83-jv6g |
中危 |
1.16.1 |
1.18.0 |
Axios: Prototype pollution auth subfields can inject Basic auth
漏洞详情: https://github.com/advisories/GHSA-xj6q-8x83-jv6g
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-20 17:51 修改: 2026-07-20 17:51
|
| undici |
CVE-2026-9678 |
中危 |
7.27.2 |
7.28.0, 8.5.0 |
undici: Undici: Information disclosure due to improper cache-control header parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-9678
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-17 18:18 修改: 2026-06-25 17:44
|
| undici |
CVE-2026-9679 |
中危 |
7.27.2 |
6.27.0, 7.28.0, 8.5.0 |
undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-9679
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-17 18:18 修改: 2026-06-25 17:43
|
| undici |
CVE-2026-6733 |
低危 |
6.24.1 |
6.27.0, 7.28.0, 8.5.0 |
undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery.
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6733
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-17 18:18 修改: 2026-06-27 23:46
|
| body-parser |
CVE-2026-12590 |
低危 |
2.2.1 |
1.20.6, 2.3.0 |
body-parser: body-parser: Denial of Service via invalid limit option
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-12590
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-07-09 11:16 修改: 2026-07-10 02:45
|
| undici |
CVE-2026-11525 |
低危 |
6.24.1 |
6.27.0, 7.28.0, 8.5.0 |
undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-11525
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-17 18:17 修改: 2026-06-25 17:46
|
| undici |
CVE-2026-11525 |
低危 |
6.26.0 |
6.27.0, 7.28.0, 8.5.0 |
undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-11525
镜像层: sha256:56224b926eb7d8392d979f8c18df796b6646d595a5a7684682bb10815f41ccc1
发布日期: 2026-06-17 18:17 修改: 2026-06-25 17:46
|
| undici |
CVE-2026-6733 |
低危 |
6.26.0 |
6.27.0, 7.28.0, 8.5.0 |
undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery.
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6733
镜像层: sha256:56224b926eb7d8392d979f8c18df796b6646d595a5a7684682bb10815f41ccc1
发布日期: 2026-06-17 18:18 修改: 2026-06-27 23:46
|
| undici |
CVE-2026-11525 |
低危 |
7.27.2 |
6.27.0, 7.28.0, 8.5.0 |
undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-11525
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-17 18:17 修改: 2026-06-25 17:46
|
| undici |
CVE-2026-6733 |
低危 |
7.27.2 |
6.27.0, 7.28.0, 8.5.0 |
undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery.
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6733
镜像层: sha256:939e6b7a99d863ffe6875301b9be88e6652143972d92d4799083150b44cd31fb
发布日期: 2026-06-17 18:18 修改: 2026-06-27 23:46
|