CVE-2026-40468 Integer overflow vulnerability has been found in "builtin.c" program f ... |
gawk |
1:5.2.1-2+b1 |
- |
❌ |
CVE-2026-40469 gawk: gawk: Denial of Service due to integer overflow |
gawk |
1:5.2.1-2+b1 |
- |
❌ |
CVE-2025-66035 angular: Angular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLs |
@angular/common |
16.2.12 |
21.0.1 |
❌ |
CVE-2026-50170 @angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache |
@angular/common |
16.2.12 |
22.0.0-rc.2 |
❌ |
CVE-2026-50171 @angular/common: Angular @angular/common: Denial of Service via malformed digitsInfo parameter |
@angular/common |
16.2.12 |
22.0.0-rc.2 |
❌ |
CVE-2026-54266 @angular/common: Weak 32-Bit Cache Key Hashing in HttpTransferCache Leading to Cross-Request Data Leakage and State Poisoning |
@angular/common |
16.2.12 |
22.0.1 |
❌ |
CVE-2026-54268 @angular/common: Angular @angular/common: Denial of Service via crafted date format string |
@angular/common |
16.2.12 |
22.0.1 |
❌ |
CVE-2025-66412 angular: Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes |
@angular/compiler |
16.2.12 |
21.0.2 |
❌ |
CVE-2026-22610 angular: Angular: Cross-site scripting vulnerability in Template Compiler |
@angular/compiler |
16.2.12 |
21.1.0-rc.0 |
❌ |
CVE-2026-22610 angular: Angular: Cross-site scripting vulnerability in Template Compiler |
@angular/core |
16.2.12 |
21.1.0-rc.0 |
❌ |
CVE-2026-27970 @angular/core: Angular: Cross-site scripting via compromised translation files |
@angular/core |
16.2.12 |
21.2.0 |
❌ |
CVE-2026-54267 @angular/core: Angular Client Hydration DOM Clobbering & Response-Cache Poisoning |
@angular/core |
16.2.12 |
22.0.1 |
❌ |
CVE-2026-42264 axios: Axios: Prototype pollution allows information disclosure and request manipulation |
axios |
1.15.1 |
1.15.2 |
❌ |
CVE-2026-44486 axios: Axios: Information disclosure of proxy credentials via HTTP redirects |
axios |
1.15.1 |
1.16.0 |
❌ |
CVE-2026-44487 axios: Axios: Information disclosure of proxy credentials via redirect flows |
axios |
1.15.1 |
1.16.0 |
❌ |
CVE-2026-44488 axios: Axios: Denial of Service due to unenforced request and response size limits |
axios |
1.15.1 |
1.16.0 |
❌ |
CVE-2026-44492 axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization |
axios |
1.15.1 |
1.16.0 |
❌ |
CVE-2026-44494 axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution |
axios |
1.15.1 |
1.16.0 |
❌ |
CVE-2026-44495 axios: Axios: Information disclosure due to prototype pollution vulnerability |
axios |
1.15.1 |
1.15.2 |
❌ |
CVE-2026-44496 axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name |
axios |
1.15.1 |
1.16.0 |
❌ |
CVE-2026-13149 brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity |
brace-expansion |
5.0.5 |
5.0.7 |
❌ |
CVE-2026-14257 brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash |
brace-expansion |
5.0.5 |
5.0.8 |
❌ |
CVE-2026-33630 c-ares: c-ares: Use-after-free / double-free in query-completion handling |
c-ares |
1.34.6-r0 |
1.34.8-r0 |
❌ |
CVE-2026-13676 fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization |
fast-uri |
3.0.1 |
4.0.1 |
❌ |
CVE-2026-16221 Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ... |
fast-uri |
3.0.1 |
4.1.1 |
❌ |
CVE-2026-6321 fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies |
fast-uri |
3.0.1 |
3.1.1 |
❌ |
CVE-2026-6322 fast-uri: fast-uri: URI authority bypass due to improper delimiter handling |
fast-uri |
3.0.1 |
3.1.2 |
❌ |
CVE-2026-12143 form-data: form-data: Form field override via CRLF injection |
form-data |
4.0.5 |
4.0.6 |
❌ |
CVE-2026-40467 Use After Free vulnerability has been found in "io.c" program file of ... |
gawk |
1:5.2.1-2+b1 |
- |
❌ |
CVE-2026-40553 Buffer overflow vulnerability has been found in "extension/readdir.c" ... |
gawk |
1:5.2.1-2+b1 |
- |
❌ |
CVE-2026-33540 github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL |
github.com/distribution/distribution |
v2.8.2+incompatible |
- |
❌ |
CVE-2026-35172 github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion |
github.com/distribution/distribution |
v2.8.2+incompatible |
- |
❌ |
GHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities |
google.golang.org/grpc |
v1.81.1 |
1.82.1 |
✅ |
GHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities |
google.golang.org/grpc |
v1.79.3 |
1.82.1 |
✅ |
GHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities |
google.golang.org/grpc |
v1.80.0 |
1.82.1 |
✅ |
GHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities |
google.golang.org/grpc |
v1.81.0 |
1.82.1 |
✅ |
CVE-2026-29063 immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution |
immutable |
3.8.2 |
5.1.5 |
❌ |
CVE-2026-59879 Immutable.js provides many Persistent Immutable data structures. Prior ... |
immutable |
3.8.2 |
5.1.8 |
❌ |
CVE-2026-59880 Immutable.js provides many Persistent Immutable data structures. Prior ... |
immutable |
3.8.2 |
5.1.8 |
❌ |
CVE-2026-59869 js-yaml: js-yaml: Denial of Service via crafted YAML documents |
js-yaml |
4.1.1 |
4.3.0 |
❌ |
CVE-2026-59869 js-yaml: js-yaml: Denial of Service via crafted YAML documents |
js-yaml |
4.1.0 |
4.3.0 |
❌ |
CVE-2026-54369 acl: Symlink traversal privilege escalation via libacl functions |
libacl1 |
2.3.2-2+b1 |
- |
❌ |
CVE-2026-4878 libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() |
libcap2 |
1:2.75-10+b8 |
1:2.75-10+deb13u1 |
❌ |
CVE-2026-11352 curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability |
libcurl |
8.20.0-r1 |
8.21.0-r0 |
❌ |
CVE-2026-11586 curl: curl: Denial of Service via WebSocket PING flood |
libcurl |
8.20.0-r1 |
8.21.0-r0 |
❌ |
CVE-2026-12064 curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP |
libcurl |
8.20.0-r1 |
8.21.0-r0 |
❌ |
CVE-2026-8286 curl: curl: Insecure connection establishment due to TLS configuration mismatch |
libcurl |
8.20.0-r1 |
8.21.0-r0 |
❌ |
CVE-2026-8925 curl: curl: Double-free vulnerability in SASL authentication |
libcurl |
8.20.0-r1 |
8.21.0-r0 |
❌ |
CVE-2026-8927 curl: Information disclosure due to uncleared proxy authentication state |
libcurl |
8.20.0-r1 |
8.21.0-r0 |
❌ |
CVE-2026-8932 libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse |
libcurl |
8.20.0-r1 |
8.21.0-r0 |
❌ |
CVE-2026-9079 libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials |
libcurl |
8.20.0-r1 |
8.21.0-r0 |
❌ |
CVE-2026-9080 libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback |
libcurl |
8.20.0-r1 |
8.21.0-r0 |
❌ |
CVE-2026-9545 libcurl: libcurl: Information disclosure via cached SSL session and early data |
libcurl |
8.20.0-r1 |
8.21.0-r0 |
❌ |
CVE-2026-9546 libcurl: libcurl: Information disclosure due to persistent Referer header |
libcurl |
8.20.0-r1 |
8.21.0-r0 |
❌ |
CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass |
libcurl |
8.20.0-r1 |
8.21.0-r0 |
❌ |
CVE-2026-45447 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() |
libssl3t64 |
3.5.5-1~deb13u2 |
3.5.6-1~deb13u2 |
❌ |
CVE-2025-69720 ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution. |
libtinfo6 |
6.5+20250216-2 |
- |
❌ |
CVE-2026-45447 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() |
openssl-provider-legacy |
3.5.5-1~deb13u2 |
3.5.6-1~deb13u2 |
❌ |
CVE-2026-50151 oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload |
oras.land/oras-go/v2 |
v2.6.0 |
2.6.1 |
❌ |
CVE-2026-50163 oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks |
oras.land/oras-go/v2 |
v2.6.0 |
- |
❌ |
CVE-2026-33671 picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns |
picomatch |
2.3.1 |
4.0.4 |
❌ |
CVE-2026-45623 PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments |
postcss |
8.4.47 |
8.5.12 |
❌ |
GHSA-r28c-9q8g-f849 PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure |
postcss |
8.4.47 |
8.5.18 |
❌ |
CVE-2026-39822 os: golang: Go os.Root: Symlink following vulnerability allows directory traversal |
stdlib |
v1.26.4 |
1.27.0-rc.2 |
❌ |
CVE-2026-50557 @angular/compiler: @angular/core: Angular: Template and Attribute Namespace Sanitization Bypass (XSS) |
@angular/compiler |
16.2.12 |
22.0.0-rc.2 |
❌ |
CVE-2026-54265 @angular/compiler: Angular: Two-Way Property Binding Sanitization Bypass (XSS) |
@angular/compiler |
16.2.12 |
22.0.1 |
❌ |
CVE-2026-50557 @angular/compiler: @angular/core: Angular: Template and Attribute Namespace Sanitization Bypass (XSS) |
@angular/core |
16.2.12 |
22.0.0-rc.2 |
❌ |
CVE-2026-52725 @angular/core: @angular/core: Cross-Site Scripting (XSS) via dynamic component creation bypass |
@angular/core |
16.2.12 |
22.0.0-rc.2 |
❌ |
CVE-2025-69873 ajv: ReDoS via $data reference |
ajv |
8.17.1 |
8.18.0 |
❌ |
CVE-2026-42044 axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget |
axios |
1.15.1 |
1.15.2 |
❌ |
CVE-2026-44490 axios: Axios: Information disclosure and denial of service due to prototype pollution |
axios |
1.15.1 |
1.16.0 |
❌ |
GHSA-42h9-826w-cgv3 Axios: Excessive recursion in formDataToJSON can cause denial of service |
axios |
1.15.1 |
1.18.0 |
❌ |
GHSA-7q8q-rj6j-mhjq Axios: Nested axios option objects can consume polluted prototype values |
axios |
1.15.1 |
1.18.0 |
❌ |
GHSA-f4gw-2p7v-4548 Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios |
axios |
1.15.1 |
1.18.0 |
❌ |
GHSA-hcpx-6fm6-wx23 Axios form serializer maxDepth bypass via {} metatoken |
axios |
1.15.1 |
1.18.0 |
❌ |
GHSA-jqh4-m9w3-8hp9 Axios: Fetch adapter ReadableStream uploads bypass maxBodyLength |
axios |
1.15.1 |
1.18.0 |
❌ |
GHSA-mmx7-hfxf-jppx Axios: Prototype pollution gadgets can alter axios request construction |
axios |
1.15.1 |
1.18.0 |
❌ |
GHSA-mwf2-3pr3-8698 Axios: HTTP/2 streamed uploads bypass maxBodyLength |
axios |
1.15.1 |
1.18.0 |
❌ |
GHSA-pmv8-rq9r-6j72 Axios: Deep formToJSON Key Recursion Can Cause Denial of Service |
axios |
1.15.1 |
1.18.0 |
❌ |
CVE-2026-45149 brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges |
brace-expansion |
5.0.5 |
5.0.6 |
❌ |
CVE-2026-41238 DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollution |
dompurify |
3.3.3 |
3.4.0 |
❌ |
CVE-2026-41239 DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressions |
dompurify |
3.3.3 |
3.4.0 |
❌ |
CVE-2026-41240 DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization |
dompurify |
3.3.3 |
3.4.0 |
❌ |
CVE-2026-49458 dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes |
dompurify |
3.3.3 |
3.4.6 |
❌ |
CVE-2026-49459 dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution |
dompurify |
3.3.3 |
3.4.6 |
❌ |
CVE-2026-49978 dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution |
dompurify |
3.3.3 |
3.4.7 |
❌ |
CVE-2026-65898 DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when ... |
dompurify |
3.3.3 |
3.4.11 |
❌ |
CVE-2026-65902 DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct refe ... |
dompurify |
3.3.3 |
3.4.7 |
❌ |
CVE-2026-65903 DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function ... |
dompurify |
3.3.3 |
3.4.0 |
❌ |
CVE-2026-45249 Apache ECharts has a cross-site scripting (XSS) vulnerability |
echarts |
5.5.1 |
6.1.0 |
❌ |
GHSA-r4q5-vmmm-2653 follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets |
follow-redirects |
1.15.11 |
1.16.0 |
❌ |
CVE-2026-41888 github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion |
github.com/distribution/distribution |
v2.8.2+incompatible |
- |
❌ |
CVE-2025-47909 Hosts listed in TrustedOrigins implicitly allow requests from the corr ... |
github.com/gorilla/csrf |
v1.7.3 |
- |
❌ |
CVE-2026-49834 sigstore-go is a Go library for Sigstore signing and verification. Pri ... |
github.com/sigstore/sigstore-go |
v1.1.4 |
1.2.0 |
❌ |
CVE-2026-49835 timestamp-authority: Sigstore Timestamp Authority: Denial of Service via unbounded metric label cardinality |
github.com/sigstore/timestamp-authority/v2 |
v2.0.6 |
2.1.0 |
❌ |
CVE-2025-64718 js-yaml: js-yaml prototype pollution in merge |
js-yaml |
4.1.0 |
4.1.1 |
❌ |
CVE-2026-53550 js-yaml: js-yaml: Denial of Service via crafted YAML merge keys |
js-yaml |
4.1.1 |
4.2.0 |
❌ |
CVE-2026-53550 js-yaml: js-yaml: Denial of Service via crafted YAML merge keys |
js-yaml |
4.1.0 |
4.2.0 |
❌ |
CVE-2026-54370 acl: TOCTOU Symlink Traversal via getfacl/setfacl |
libacl1 |
2.3.2-2+b1 |
- |
❌ |
CVE-2026-54371 attr: Symlink Traversal Privilege Escalation via getfattr and setfattr |
libattr1 |
1:2.5.2-3 |
- |
❌ |
Zero CVE Daily Report
Generated:
2026-07-25T05:27:09.449ZStatus
automation/zero-cve8gears.container-registry.com/8gcr/harbor-core:latest,8gears.container-registry.com/8gcr/harbor-jobservice:latest,8gears.container-registry.com/8gcr/harbor-registryctl:latest,8gears.container-registry.com/8gcr/harbor-exporter:latest,8gears.container-registry.com/8gcr/harbor-portal:latest,8gears.container-registry.com/8gcr/harbor-registry:latest,8gears.container-registry.com/8gcr/trivy-adapter:latestVulnerabilities
Integer overflow vulnerability has been found in "builtin.c" program f ...
gawk1:5.2.1-2+b1gawk: gawk: Denial of Service due to integer overflow
gawk1:5.2.1-2+b1angular: Angular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLs
@angular/common16.2.1221.0.1@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache
@angular/common16.2.1222.0.0-rc.2@angular/common: Angular @angular/common: Denial of Service via malformed digitsInfo parameter
@angular/common16.2.1222.0.0-rc.2@angular/common: Weak 32-Bit Cache Key Hashing in
HttpTransferCacheLeading to Cross-Request Data Leakage and State Poisoning@angular/common16.2.1222.0.1@angular/common: Angular @angular/common: Denial of Service via crafted date format string
@angular/common16.2.1222.0.1angular: Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes
@angular/compiler16.2.1221.0.2angular: Angular: Cross-site scripting vulnerability in Template Compiler
@angular/compiler16.2.1221.1.0-rc.0angular: Angular: Cross-site scripting vulnerability in Template Compiler
@angular/core16.2.1221.1.0-rc.0@angular/core: Angular: Cross-site scripting via compromised translation files
@angular/core16.2.1221.2.0@angular/core: Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
@angular/core16.2.1222.0.1axios: Axios: Prototype pollution allows information disclosure and request manipulation
axios1.15.11.15.2axios: Axios: Information disclosure of proxy credentials via HTTP redirects
axios1.15.11.16.0axios: Axios: Information disclosure of proxy credentials via redirect flows
axios1.15.11.16.0axios: Axios: Denial of Service due to unenforced request and response size limits
axios1.15.11.16.0axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
axios1.15.11.16.0axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
axios1.15.11.16.0axios: Axios: Information disclosure due to prototype pollution vulnerability
axios1.15.11.15.2axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
axios1.15.11.16.0brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
brace-expansion5.0.55.0.7brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
brace-expansion5.0.55.0.8c-ares: c-ares: Use-after-free / double-free in query-completion handling
c-ares1.34.6-r01.34.8-r0fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
fast-uri3.0.14.0.1Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...
fast-uri3.0.14.1.1fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies
fast-uri3.0.13.1.1fast-uri: fast-uri: URI authority bypass due to improper delimiter handling
fast-uri3.0.13.1.2form-data: form-data: Form field override via CRLF injection
form-data4.0.54.0.6Use After Free vulnerability has been found in "io.c" program file of ...
gawk1:5.2.1-2+b1Buffer overflow vulnerability has been found in "extension/readdir.c" ...
gawk1:5.2.1-2+b1github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL
github.com/distribution/distributionv2.8.2+incompatiblegithub.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion
github.com/distribution/distributionv2.8.2+incompatiblegRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
google.golang.org/grpcv1.81.11.82.1gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
google.golang.org/grpcv1.79.31.82.1gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
google.golang.org/grpcv1.80.01.82.1gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
google.golang.org/grpcv1.81.01.82.1immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution
immutable3.8.25.1.5Immutable.js provides many Persistent Immutable data structures. Prior ...
immutable3.8.25.1.8Immutable.js provides many Persistent Immutable data structures. Prior ...
immutable3.8.25.1.8js-yaml: js-yaml: Denial of Service via crafted YAML documents
js-yaml4.1.14.3.0js-yaml: js-yaml: Denial of Service via crafted YAML documents
js-yaml4.1.04.3.0acl: Symlink traversal privilege escalation via libacl functions
libacl12.3.2-2+b1libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()
libcap21:2.75-10+b81:2.75-10+deb13u1curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability
libcurl8.20.0-r18.21.0-r0curl: curl: Denial of Service via WebSocket PING flood
libcurl8.20.0-r18.21.0-r0curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP
libcurl8.20.0-r18.21.0-r0curl: curl: Insecure connection establishment due to TLS configuration mismatch
libcurl8.20.0-r18.21.0-r0curl: curl: Double-free vulnerability in SASL authentication
libcurl8.20.0-r18.21.0-r0curl: Information disclosure due to uncleared proxy authentication state
libcurl8.20.0-r18.21.0-r0libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse
libcurl8.20.0-r18.21.0-r0libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials
libcurl8.20.0-r18.21.0-r0libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback
libcurl8.20.0-r18.21.0-r0libcurl: libcurl: Information disclosure via cached SSL session and early data
libcurl8.20.0-r18.21.0-r0libcurl: libcurl: Information disclosure due to persistent Referer header
libcurl8.20.0-r18.21.0-r0curl: curl: Man-in-the-middle attack via SSH host key bypass
libcurl8.20.0-r18.21.0-r0openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
libssl3t643.5.5-1~deb13u23.5.6-1~deb13u2ncurses: ncurses: Buffer overflow vulnerability may lead to arbitrary code execution.
libtinfo66.5+20250216-2openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
openssl-provider-legacy3.5.5-1~deb13u23.5.6-1~deb13u2oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload
oras.land/oras-go/v2v2.6.02.6.1oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks
oras.land/oras-go/v2v2.6.0picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns
picomatch2.3.14.0.4PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
postcss8.4.478.5.12PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
postcss8.4.478.5.18os: golang: Go os.Root: Symlink following vulnerability allows directory traversal
stdlibv1.26.41.27.0-rc.2@angular/compiler: @angular/core: Angular: Template and Attribute Namespace Sanitization Bypass (XSS)
@angular/compiler16.2.1222.0.0-rc.2@angular/compiler: Angular: Two-Way Property Binding Sanitization Bypass (XSS)
@angular/compiler16.2.1222.0.1@angular/compiler: @angular/core: Angular: Template and Attribute Namespace Sanitization Bypass (XSS)
@angular/core16.2.1222.0.0-rc.2@angular/core: @angular/core: Cross-Site Scripting (XSS) via dynamic component creation bypass
@angular/core16.2.1222.0.0-rc.2ajv: ReDoS via $data reference
ajv8.17.18.18.0axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget
axios1.15.11.15.2axios: Axios: Information disclosure and denial of service due to prototype pollution
axios1.15.11.16.0Axios: Excessive recursion in formDataToJSON can cause denial of service
axios1.15.11.18.0Axios: Nested axios option objects can consume polluted prototype values
axios1.15.11.18.0Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
axios1.15.11.18.0Axios form serializer maxDepth bypass via {} metatoken
axios1.15.11.18.0Axios: Fetch adapter
ReadableStreamuploads bypassmaxBodyLengthaxios1.15.11.18.0Axios: Prototype pollution gadgets can alter axios request construction
axios1.15.11.18.0Axios: HTTP/2 streamed uploads bypass
maxBodyLengthaxios1.15.11.18.0Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
axios1.15.11.18.0brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges
brace-expansion5.0.55.0.6DOMPurify: DOMPurify: Cross-Site Scripting bypass via prototype pollution
dompurify3.3.33.4.0DOMPurify: Vue 2: DOMPurify: Cross-site scripting due to incomplete sanitization of template expressions
dompurify3.3.33.4.0DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization
dompurify3.3.33.4.0dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes
dompurify3.3.33.4.6dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution
dompurify3.3.33.4.6dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution
dompurify3.3.33.4.7DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when ...
dompurify3.3.33.4.11DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct refe ...
dompurify3.3.33.4.7DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function ...
dompurify3.3.33.4.0Apache ECharts has a cross-site scripting (XSS) vulnerability
echarts5.5.16.1.0follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets
follow-redirects1.15.111.16.0github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion
github.com/distribution/distributionv2.8.2+incompatibleHosts listed in TrustedOrigins implicitly allow requests from the corr ...
github.com/gorilla/csrfv1.7.3sigstore-go is a Go library for Sigstore signing and verification. Pri ...
github.com/sigstore/sigstore-gov1.1.41.2.0timestamp-authority: Sigstore Timestamp Authority: Denial of Service via unbounded metric label cardinality
github.com/sigstore/timestamp-authority/v2v2.0.62.1.0js-yaml: js-yaml prototype pollution in merge
js-yaml4.1.04.1.1js-yaml: js-yaml: Denial of Service via crafted YAML merge keys
js-yaml4.1.14.2.0js-yaml: js-yaml: Denial of Service via crafted YAML merge keys
js-yaml4.1.04.2.0acl: TOCTOU Symlink Traversal via getfacl/setfacl
libacl12.3.2-2+b1attr: Symlink Traversal Privilege Escalation via getfattr and setfattr
libattr11:2.5.2-3Showing 100 of 194 findings. See workflow artifacts for full JSON reports.
Go Module Updates
github.com/goharbor/harbor/srcv1.26.5go.opentelemetry.io/otelv1.43.0v1.44.0v1.44.0Scanner Status