| brace-expansion |
CVE-2026-69152 |
高危 |
5.0.8 |
1.1.18, 2.1.4, 3.0.6, 5.0.9 |
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-69152
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-08-03 17:16 修改: 2026-08-05 14:58
|
| fast-uri |
CVE-2026-18446 |
高危 |
4.1.1 |
2.4.4, 3.1.5, 4.1.2 |
fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-18446
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-07-31 15:16 修改: 2026-07-31 18:17
|
| image-size |
CVE-2025-71329 |
高危 |
2.0.2 |
|
image-size: image-size: Denial of Service via crafted image buffer with zero-valued size field
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-71329
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-06-10 14:16 修改: 2026-06-17 10:04
|
| image-size |
CVE-2025-71330 |
高危 |
2.0.2 |
|
image-size: image-size: Denial of Service via crafted ICNS image buffer
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-71330
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-06-10 14:16 修改: 2026-06-17 10:04
|
| nanoid |
CVE-2026-67213 |
高危 |
3.3.16 |
3.3.18, 5.1.6 |
nanoid: nanoid: Denial of Service via infinite loop in random ID generation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-67213
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-07-29 14:16 修改: 2026-08-18 14:26
|
| nodemailer |
GHSA-p6gq-j5cr-w38f |
高危 |
7.0.13 |
9.0.1 |
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
漏洞详情: https://github.com/advisories/GHSA-p6gq-j5cr-w38f
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-06-18 14:28 修改: 2026-06-18 14:28
|
| sharp |
GHSA-f88m-g3jw-g9cj |
高危 |
0.34.5 |
0.35.0 |
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
漏洞详情: https://github.com/advisories/GHSA-f88m-g3jw-g9cj
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-07-21 22:07 修改: 2026-07-21 22:07
|
| undici |
CVE-2026-13697 |
高危 |
8.8.0 |
7.29.0, 8.9.0 |
undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-13697
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-07-29 17:16 修改: 2026-08-04 14:17
|
| file-type |
CVE-2026-32630 |
中危 |
20.4.1 |
21.3.2 |
file-type: file-type: Denial of Service via excessive memory growth from crafted ZIP files
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-32630
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-03-16 14:19 修改: 2026-06-17 10:36
|
| hono |
CVE-2026-69207 |
中危 |
4.12.32 |
4.12.34 |
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-69207
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-08-07 21:17 修改: 2026-08-10 14:17
|
| hono |
CVE-2026-71848 |
中危 |
4.12.32 |
4.12.34 |
Hono: Algorithmic Complexity DoS in Language Middleware
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-71848
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-08-07 19:18 修改: 2026-08-08 04:17
|
| hono |
CVE-2026-71850 |
中危 |
4.12.32 |
4.12.34 |
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-71850
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-08-07 19:18 修改: 2026-08-10 14:17
|
| @nestjs/core |
CVE-2026-35515 |
中危 |
10.4.22 |
11.1.18 |
@nestjs/core: Nest: Server-Sent Events (SSE) injection and spoofing via unsanitized newline characters
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-35515
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-04-07 16:16 修改: 2026-06-17 10:40
|
| dompurify |
GHSA-55q2-fjhq-7xh7 |
中危 |
3.4.12 |
3.4.13 |
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
漏洞详情: https://github.com/advisories/GHSA-55q2-fjhq-7xh7
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-08-07 15:30 修改: 2026-08-07 15:30
|
| dompurify |
CVE-2026-65898 |
中危 |
3.4.8 |
3.4.11 |
dompurify: DOMPurify: Cross-site scripting via permanent attribute allowlist pollution
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-65898
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-07-23 14:18 修改: 2026-07-28 15:54
|
| dompurify |
GHSA-55q2-fjhq-7xh7 |
中危 |
3.4.8 |
3.4.13 |
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
漏洞详情: https://github.com/advisories/GHSA-55q2-fjhq-7xh7
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-08-07 15:30 修改: 2026-08-07 15:30
|
| nodemailer |
GHSA-268h-hp4c-crq3 |
中危 |
7.0.13 |
8.0.9 |
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
漏洞详情: https://github.com/advisories/GHSA-268h-hp4c-crq3
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-06-15 17:36 修改: 2026-06-15 17:36
|
| nodemailer |
GHSA-r7g4-qg5f-qqm2 |
中危 |
7.0.13 |
8.0.8 |
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception
漏洞详情: https://github.com/advisories/GHSA-r7g4-qg5f-qqm2
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-06-15 17:34 修改: 2026-06-15 17:34
|
| nodemailer |
GHSA-vvjj-xcjg-gr5g |
中危 |
7.0.13 |
8.0.5 |
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
漏洞详情: https://github.com/advisories/GHSA-vvjj-xcjg-gr5g
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-04-08 15:05 修改: 2026-04-08 15:05
|
| nodemailer |
GHSA-wqvq-jvpq-h66f |
中危 |
7.0.13 |
8.0.9 |
Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization
漏洞详情: https://github.com/advisories/GHSA-wqvq-jvpq-h66f
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-06-15 17:35 修改: 2026-06-15 17:35
|
| @opentelemetry/core |
CVE-2026-54285 |
中危 |
1.30.1 |
2.8.0 |
@opentelemetry/core: opentelemetry-js: @opentelemetry/core: Denial of Service via oversized baggage HTTP headers
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-54285
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-06-22 18:16 修改: 2026-06-23 16:17
|
| file-type |
CVE-2026-31808 |
中危 |
20.4.1 |
21.3.1 |
file-type: file-type: Denial of Service due to infinite loop in ASF file parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-31808
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-03-10 21:16 修改: 2026-06-17 10:34
|
| undici |
CVE-2026-14643 |
中危 |
8.8.0 |
7.29.0, 8.9.0 |
undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-14643
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-07-29 22:16 修改: 2026-08-04 15:53
|
| undici |
CVE-2026-15157 |
中危 |
8.8.0 |
6.28.0, 7.29.0, 8.9.0 |
undici: undici: HTTP header injection via unvalidated blob-like body type property
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-15157
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-07-29 22:16 修改: 2026-08-04 15:41
|
| undici |
CVE-2026-16728 |
中危 |
8.8.0 |
6.28.0, 7.29.0, 8.9.0 |
undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-16728
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-07-29 21:17 修改: 2026-08-04 14:06
|
| undici |
CVE-2026-16729 |
中危 |
8.8.0 |
6.28.0, 7.29.0, 8.9.0 |
undici: Undici: Cookie attribute injection allows bypassing security protections
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-16729
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-07-29 17:16 修改: 2026-08-05 15:18
|
| uuid |
CVE-2026-41907 |
中危 |
8.3.2 |
11.1.1, 12.0.1, 13.0.1 |
uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41907
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-04-24 19:17 修改: 2026-06-17 10:47
|
| uuid |
CVE-2026-41907 |
中危 |
9.0.1 |
11.1.1, 12.0.1, 13.0.1 |
uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-41907
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-04-24 19:17 修改: 2026-06-17 10:47
|
| dompurify |
GHSA-c2j3-45gr-mqc4 |
低危 |
3.4.8 |
3.4.12 |
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
漏洞详情: https://github.com/advisories/GHSA-c2j3-45gr-mqc4
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-07-21 19:41 修改: 2026-07-21 19:41
|
| @tootallnate/once |
CVE-2026-3449 |
低危 |
1.1.2 |
3.0.1, 2.0.1 |
@tootallnate/once: @tootallnate/once: Denial of Service due to incorrect control flow scoping with AbortSignal
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3449
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-03-03 05:17 修改: 2026-06-17 10:43
|
| hono |
CVE-2026-71849 |
低危 |
4.12.32 |
4.12.34 |
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-71849
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-08-07 19:18 修改: 2026-08-10 13:20
|
| body-parser |
CVE-2026-12590 |
低危 |
1.20.4 |
1.20.6, 2.3.0 |
body-parser: body-parser: Denial of Service via invalid limit option
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-12590
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-07-09 11:16 修改: 2026-07-10 02:45
|
| @ai-sdk/provider-utils |
CVE-2026-8769 |
低危 |
2.2.8 |
|
@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8769
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-05-17 23:17 修改: 2026-06-17 11:04
|
| nodemailer |
GHSA-c7w3-x93f-qmm8 |
低危 |
7.0.13 |
8.0.4 |
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter
漏洞详情: https://github.com/advisories/GHSA-c7w3-x93f-qmm8
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-03-26 22:26 修改: 2026-03-26 22:26
|
| dompurify |
CVE-2026-65899 |
低危 |
3.4.8 |
3.4.9 |
dompurify: DOMPurify: Client-side arbitrary code execution due to improper Trusted Types policy reset
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-65899
镜像层: sha256:001e70429ed41c9c46e559b4018372ea2836db1e938254ed9b0d74c3d12f1a63
发布日期: 2026-07-23 14:18 修改: 2026-07-28 15:53
|