| @braintree/sanitize-url |
CVE-2021-23648 |
MEDIUM |
3.1.0 |
6.0.0 |
https://access.redhat.com/errata/RHSA-2022:8057
https://access.redhat.com/security/cve/CVE-2021-23648
https://bugzilla.redhat.com/2044628
https://bugzilla.redhat.com/2045880
https://bugzilla.redhat.com/2050648
https://bugzilla.redhat.com/2050742
https://bugzilla.redhat.com/2050743
https://bugzilla.redhat.com/2065290
https://bugzilla.redhat.com/2107342
https://bugzilla.redhat.com/2107371
https://bugzilla.redhat.com/2107374
https://bugzilla.redhat.com/2107376
https://bugzilla.redhat.com/2107383
https://bugzilla.redhat.com/2107386
https://bugzilla.redhat.com/2107388
https://bugzilla.redhat.com/2107390
https://bugzilla.redhat.com/2107392
https://bugzilla.redhat.com/show_bug.cgi?id=2044628
https://bugzilla.redhat.com/show_bug.cgi?id=2045880
https://bugzilla.redhat.com/show_bug.cgi?id=2050648
https://bugzilla.redhat.com/show_bug.cgi?id=2050742
https://bugzilla.redhat.com/show_bug.cgi?id=2050743
https://bugzilla.redhat.com/show_bug.cgi?id=2055349
https://bugzilla.redhat.com/show_bug.cgi?id=2065290
https://bugzilla.redhat.com/show_bug.cgi?id=2104367
https://bugzilla.redhat.com/show_bug.cgi?id=2107342
https://bugzilla.redhat.com/show_bug.cgi?id=2107371
https://bugzilla.redhat.com/show_bug.cgi?id=2107374
https://bugzilla.redhat.com/show_bug.cgi?id=2107376
https://bugzilla.redhat.com/show_bug.cgi?id=2107383
https://bugzilla.redhat.com/show_bug.cgi?id=2107386
https://bugzilla.redhat.com/show_bug.cgi?id=2107388
https://bugzilla.redhat.com/show_bug.cgi?id=2107390
https://bugzilla.redhat.com/show_bug.cgi?id=2107392
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23648
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1705
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1962
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21673
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21698
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21702
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21703
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21713
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28131
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30630
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30631
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30632
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30633
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30635
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32148
https://errata.almalinux.org/9/ALSA-2022-8057.html
https://errata.rockylinux.org/RLSA-2022:8057
https://github.com/braintree/sanitize-url
https://github.com/braintree/sanitize-url/blob/main/src/index.ts%23L11
https://github.com/braintree/sanitize-url/pull/40
https://github.com/braintree/sanitize-url/pull/40/commits/e5afda45d9833682b705f73fc2c1265d34832183
https://linux.oracle.com/cve/CVE-2021-23648.html
https://linux.oracle.com/errata/ELSA-2022-8057.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ
https://nvd.nist.gov/vuln/detail/CVE-2021-23648
https://snyk.io/vuln/SNYK-JS-BRAINTREESANITIZEURL-2339882
https://www.cve.org/CVERecord?id=CVE-2021-23648
|
| @braintree/sanitize-url |
CVE-2022-48345 |
MEDIUM |
3.1.0 |
6.0.1 |
https://access.redhat.com/security/cve/CVE-2022-48345
https://github.com/braintree/sanitize-url
https://github.com/braintree/sanitize-url/commit/d4bdc89f1743fe3cdb7c3f24b06e4c875f349b0c
https://github.com/braintree/sanitize-url/compare/v6.0.0...v6.0.1
https://github.com/braintree/sanitize-url/compare/v6.0.1...v6.0.2
https://nvd.nist.gov/vuln/detail/CVE-2022-48345
https://www.cve.org/CVERecord?id=CVE-2022-48345
|
| axios |
CVE-2021-3749 |
HIGH |
0.19.2 |
0.21.2 |
https://access.redhat.com/security/cve/CVE-2021-3749
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
https://github.com/axios/axios
https://github.com/axios/axios/commit/5b457116e31db0e88fede6c428e969e87f290929
https://github.com/axios/axios/pull/3980
https://huntr.dev/bounties/1e8f07fc-c384-4ff9-8498-0690de2e8c31
https://huntr.dev/bounties/1e8f07fc-c384-4ff9-8498-0690de2e8c31/
https://lists.apache.org/thread.html/r075d464dce95cd13c03ff9384658edcccd5ab2983b82bfc72b62bb10%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r075d464dce95cd13c03ff9384658edcccd5ab2983b82bfc72b62bb10@%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r216f0fd0a3833856d6a6a1fada488cadba45f447d87010024328ccf2%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r216f0fd0a3833856d6a6a1fada488cadba45f447d87010024328ccf2@%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r3ae6d2654f92c5851bdb73b35e96b0e4e3da39f28ac7a1b15ae3aab8%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r3ae6d2654f92c5851bdb73b35e96b0e4e3da39f28ac7a1b15ae3aab8@%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r4bf1b32983f50be00f9752214c1b53738b621be1c2b0dbd68c7f2391%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r4bf1b32983f50be00f9752214c1b53738b621be1c2b0dbd68c7f2391@%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r7324ecc35b8027a51cb6ed629490fcd3b2d7cf01c424746ed5744bf1%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r7324ecc35b8027a51cb6ed629490fcd3b2d7cf01c424746ed5744bf1@%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r74d0b359408fff31f87445261f0ee13bdfcac7d66f6b8e846face321%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r74d0b359408fff31f87445261f0ee13bdfcac7d66f6b8e846face321@%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/ra15d63c54dc6474b29f72ae4324bcb03038758545b3ab800845de7a1%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/ra15d63c54dc6474b29f72ae4324bcb03038758545b3ab800845de7a1@%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/rc263bfc5b53afcb7e849605478d73f5556eb0c00d1f912084e407289%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/rc263bfc5b53afcb7e849605478d73f5556eb0c00d1f912084e407289@%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/rfa094029c959da0f7c8cd7dc9c4e59d21b03457bf0cedf6c93e1bb0a%40%3Cdev.druid.apache.org%3E
https://lists.apache.org/thread.html/rfa094029c959da0f7c8cd7dc9c4e59d21b03457bf0cedf6c93e1bb0a@%3Cdev.druid.apache.org%3E
https://lists.apache.org/thread.html/rfc5c478053ff808671aef170f3d9fc9d05cc1fab8fb64431edc66103%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/rfc5c478053ff808671aef170f3d9fc9d05cc1fab8fb64431edc66103@%3Ccommits.druid.apache.org%3E
https://nvd.nist.gov/vuln/detail/CVE-2021-3749
https://www.cve.org/CVERecord?id=CVE-2021-3749
https://www.npmjs.com/package/axios
https://www.oracle.com/security-alerts/cpujul2022.html
|
| axios |
CVE-2025-27152 |
HIGH |
0.19.2 |
1.8.2, 0.30.0 |
https://access.redhat.com/security/cve/CVE-2025-27152
https://github.com/axios/axios
https://github.com/axios/axios/commit/02c3c69ced0f8fd86407c23203835892313d7fde
https://github.com/axios/axios/commit/fb8eec214ce7744b5ca787f2c3b8339b2f54b00f
https://github.com/axios/axios/issues/6463
https://github.com/axios/axios/pull/6829
https://github.com/axios/axios/releases/tag/v1.8.2
https://github.com/axios/axios/security/advisories/GHSA-jr5f-v2jv-69x6
https://nvd.nist.gov/vuln/detail/CVE-2025-27152
https://www.cve.org/CVERecord?id=CVE-2025-27152
|
| axios |
CVE-2026-25639 |
HIGH |
0.19.2 |
1.13.5, 0.30.3 |
https://access.redhat.com/security/cve/CVE-2026-25639
https://github.com/axios/axios
https://github.com/axios/axios/commit/28c721588c7a77e7503d0a434e016f852c597b57
https://github.com/axios/axios/commit/d7ff1409c68168d3057fc3891f911b2b92616f9e
https://github.com/axios/axios/pull/7369
https://github.com/axios/axios/pull/7388
https://github.com/axios/axios/releases/tag/v0.30.3
https://github.com/axios/axios/releases/tag/v1.13.5
https://github.com/axios/axios/security/advisories/GHSA-43fc-jf86-j433
https://nvd.nist.gov/vuln/detail/CVE-2026-25639
https://www.cve.org/CVERecord?id=CVE-2026-25639
|
| axios |
CVE-2026-42033 |
HIGH |
0.19.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42033
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-pf86-5x62-jrwf
https://nvd.nist.gov/vuln/detail/CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
|
| axios |
CVE-2026-42035 |
HIGH |
0.19.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42035
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-6chq-wfr3-2hj9
https://nvd.nist.gov/vuln/detail/CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
|
| axios |
CVE-2026-42043 |
HIGH |
0.19.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42043
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-pmwg-cvhr-8vh7
https://nvd.nist.gov/vuln/detail/CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
|
| axios |
CVE-2026-44486 |
HIGH |
0.19.2 |
1.16.0, 0.32.0 |
https://access.redhat.com/security/cve/CVE-2026-44486
https://github.com/axios/axios
https://github.com/axios/axios/commit/afca61a070728e717203c2bc21e7b589b59b858b
https://github.com/axios/axios/pull/10794
https://github.com/axios/axios/releases/tag/v0.32.0
https://github.com/axios/axios/releases/tag/v1.16.0
https://github.com/axios/axios/security/advisories/GHSA-j5f8-grm9-p9fc
https://nvd.nist.gov/vuln/detail/CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
|
| axios |
CVE-2026-44487 |
HIGH |
0.19.2 |
1.16.0, 0.32.0 |
https://access.redhat.com/security/cve/CVE-2026-44487
https://github.com/axios/axios
https://github.com/axios/axios/releases/tag/v0.32.0
https://github.com/axios/axios/releases/tag/v1.16.0
https://github.com/axios/axios/security/advisories/GHSA-p92q-9vqr-4j8v
https://nvd.nist.gov/vuln/detail/CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
|
| axios |
CVE-2026-44492 |
HIGH |
0.19.2 |
1.16.0, 0.32.0 |
https://access.redhat.com/security/cve/CVE-2026-44492
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-pjwm-pj3p-43mv
https://nvd.nist.gov/vuln/detail/CVE-2025-62718
https://nvd.nist.gov/vuln/detail/CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
|
| axios |
CVE-2026-44495 |
HIGH |
0.19.2 |
1.15.2, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-44495
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-3g43-6gmg-66jw
https://nvd.nist.gov/vuln/detail/CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
|
| axios |
CVE-2026-44496 |
HIGH |
0.19.2 |
1.16.0, 0.32.0 |
https://access.redhat.com/security/cve/CVE-2026-44496
https://github.com/axios/axios
https://github.com/axios/axios/releases/tag/v0.32.0
https://github.com/axios/axios/releases/tag/v1.16.0
https://github.com/axios/axios/security/advisories/GHSA-hfxv-24rg-xrqf
https://nvd.nist.gov/vuln/detail/CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
|
| axios |
CVE-2020-28168 |
MEDIUM |
0.19.2 |
0.21.1 |
https://access.redhat.com/security/cve/CVE-2020-28168
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
https://github.com/axios/axios/commit/c7329fefc890050edd51e40e469a154d0117fc55
https://github.com/axios/axios/issues/3369
https://lists.apache.org/thread.html/r25d53acd06f29244b8a103781b0339c5e7efee9099a4d52f0c230e4a%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r25d53acd06f29244b8a103781b0339c5e7efee9099a4d52f0c230e4a@%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r954d80fd18e9dafef6e813963eb7e08c228151c2b6268ecd63b35d1f%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r954d80fd18e9dafef6e813963eb7e08c228151c2b6268ecd63b35d1f@%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/rdfd2901b8b697a3f6e2c9c6ecc688fd90d7f881937affb5144d61d6e%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/rdfd2901b8b697a3f6e2c9c6ecc688fd90d7f881937affb5144d61d6e@%3Ccommits.druid.apache.org%3E
https://nvd.nist.gov/vuln/detail/CVE-2020-28168
https://snyk.io/vuln/SNYK-JS-AXIOS-1038255
https://www.cve.org/CVERecord?id=CVE-2020-28168
https://www.npmjs.com/advisories/1594
https://www.npmjs.com/package/axios
|
| axios |
CVE-2023-45857 |
MEDIUM |
0.19.2 |
1.6.0, 0.28.0 |
https://access.redhat.com/security/cve/CVE-2023-45857
https://github.com/axios/axios
https://github.com/axios/axios/commit/2755df562b9c194fba6d8b609a383443f6a6e967
https://github.com/axios/axios/commit/96ee232bd3ee4de2e657333d4d2191cd389e14d0
https://github.com/axios/axios/issues/6006
https://github.com/axios/axios/issues/6022
https://github.com/axios/axios/pull/6028
https://github.com/axios/axios/pull/6091
https://github.com/axios/axios/releases/tag/v0.28.0
https://github.com/axios/axios/releases/tag/v1.6.0
https://nvd.nist.gov/vuln/detail/CVE-2023-45857
https://security.netapp.com/advisory/ntap-20240621-0006
https://security.netapp.com/advisory/ntap-20240621-0006/
https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
https://www.cve.org/CVERecord?id=CVE-2023-45857
|
| axios |
CVE-2025-62718 |
MEDIUM |
0.19.2 |
1.15.0, 0.31.0 |
https://access.redhat.com/security/cve/CVE-2025-62718
https://datatracker.ietf.org/doc/html/rfc1034#section-3.1
https://datatracker.ietf.org/doc/html/rfc3986#section-3.2.2
https://github.com/axios/axios
https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c
https://github.com/axios/axios/commit/fb3befb6daac6cad26b2e54094d0f2d9e47f24df
https://github.com/axios/axios/pull/10661
https://github.com/axios/axios/pull/10688
https://github.com/axios/axios/releases/tag/v0.31.0
https://github.com/axios/axios/releases/tag/v1.15.0
https://github.com/axios/axios/security/advisories/GHSA-3p68-rc4w-qgx5
https://nvd.nist.gov/vuln/detail/CVE-2025-62718
https://www.cve.org/CVERecord?id=CVE-2025-62718
|
| axios |
CVE-2026-40175 |
MEDIUM |
0.19.2 |
1.15.0, 0.31.0 |
https://access.redhat.com/security/cve/CVE-2026-40175
https://cert-portal.siemens.com/productcert/html/ssa-876049.html
https://github.com/axios/axios
https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c
https://github.com/axios/axios/commit/363185461b90b1b78845dc8a99a1f103d9b122a1
https://github.com/axios/axios/pull/10660
https://github.com/axios/axios/pull/10660#issuecomment-4224168081
https://github.com/axios/axios/pull/10688
https://github.com/axios/axios/releases/tag/v0.31.0
https://github.com/axios/axios/releases/tag/v1.15.0
https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx
https://nvd.nist.gov/vuln/detail/CVE-2026-40175
https://www.cve.org/CVERecord?id=CVE-2026-40175
|
| axios |
CVE-2026-42034 |
MEDIUM |
0.19.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42034
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-5c9x-8gcm-mpgx
https://nvd.nist.gov/vuln/detail/CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
|
| axios |
CVE-2026-42036 |
MEDIUM |
0.19.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42036
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-vf2m-468p-8v99
https://nvd.nist.gov/vuln/detail/CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
|
| axios |
CVE-2026-42038 |
MEDIUM |
0.19.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42038
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-m7pr-hjqh-92cm
https://nvd.nist.gov/vuln/detail/CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
|
| axios |
CVE-2026-42039 |
MEDIUM |
0.19.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42039
https://github.com/axios/axios
https://github.com/axios/axios/commit/85132ffba1a77609ea5d101c8a413dea7174932f
https://github.com/axios/axios/releases/tag/v1.15.1
https://github.com/axios/axios/security/advisories/GHSA-62hf-57xw-28j9
https://nvd.nist.gov/vuln/detail/CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
|
| axios |
CVE-2026-42041 |
MEDIUM |
0.19.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42041
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-w9j2-pvgh-6h63
https://nvd.nist.gov/vuln/detail/CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
|
| axios |
CVE-2026-42042 |
MEDIUM |
0.19.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42042
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-xx6v-rp6x-q39c
https://nvd.nist.gov/vuln/detail/CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
|
| axios |
CVE-2026-44490 |
MEDIUM |
0.19.2 |
1.16.0, 0.32.0 |
https://access.redhat.com/security/cve/CVE-2026-44490
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-898c-q2cr-xwhg
https://nvd.nist.gov/vuln/detail/CVE-2018-16487
https://nvd.nist.gov/vuln/detail/CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
|
| axios |
CVE-2026-42040 |
LOW |
0.19.2 |
1.15.1, 0.31.1 |
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-xhjh-pmcv-23jw
https://nvd.nist.gov/vuln/detail/CVE-2026-42040
|
| axios |
CVE-2025-27152 |
HIGH |
0.27.2 |
1.8.2, 0.30.0 |
https://access.redhat.com/security/cve/CVE-2025-27152
https://github.com/axios/axios
https://github.com/axios/axios/commit/02c3c69ced0f8fd86407c23203835892313d7fde
https://github.com/axios/axios/commit/fb8eec214ce7744b5ca787f2c3b8339b2f54b00f
https://github.com/axios/axios/issues/6463
https://github.com/axios/axios/pull/6829
https://github.com/axios/axios/releases/tag/v1.8.2
https://github.com/axios/axios/security/advisories/GHSA-jr5f-v2jv-69x6
https://nvd.nist.gov/vuln/detail/CVE-2025-27152
https://www.cve.org/CVERecord?id=CVE-2025-27152
|
| axios |
CVE-2026-25639 |
HIGH |
0.27.2 |
1.13.5, 0.30.3 |
https://access.redhat.com/security/cve/CVE-2026-25639
https://github.com/axios/axios
https://github.com/axios/axios/commit/28c721588c7a77e7503d0a434e016f852c597b57
https://github.com/axios/axios/commit/d7ff1409c68168d3057fc3891f911b2b92616f9e
https://github.com/axios/axios/pull/7369
https://github.com/axios/axios/pull/7388
https://github.com/axios/axios/releases/tag/v0.30.3
https://github.com/axios/axios/releases/tag/v1.13.5
https://github.com/axios/axios/security/advisories/GHSA-43fc-jf86-j433
https://nvd.nist.gov/vuln/detail/CVE-2026-25639
https://www.cve.org/CVERecord?id=CVE-2026-25639
|
| axios |
CVE-2026-42033 |
HIGH |
0.27.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42033
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-pf86-5x62-jrwf
https://nvd.nist.gov/vuln/detail/CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
|
| axios |
CVE-2026-42035 |
HIGH |
0.27.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42035
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-6chq-wfr3-2hj9
https://nvd.nist.gov/vuln/detail/CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
|
| axios |
CVE-2026-42043 |
HIGH |
0.27.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42043
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-pmwg-cvhr-8vh7
https://nvd.nist.gov/vuln/detail/CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
|
| axios |
CVE-2026-44486 |
HIGH |
0.27.2 |
1.16.0, 0.32.0 |
https://access.redhat.com/security/cve/CVE-2026-44486
https://github.com/axios/axios
https://github.com/axios/axios/commit/afca61a070728e717203c2bc21e7b589b59b858b
https://github.com/axios/axios/pull/10794
https://github.com/axios/axios/releases/tag/v0.32.0
https://github.com/axios/axios/releases/tag/v1.16.0
https://github.com/axios/axios/security/advisories/GHSA-j5f8-grm9-p9fc
https://nvd.nist.gov/vuln/detail/CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
|
| axios |
CVE-2026-44487 |
HIGH |
0.27.2 |
1.16.0, 0.32.0 |
https://access.redhat.com/security/cve/CVE-2026-44487
https://github.com/axios/axios
https://github.com/axios/axios/releases/tag/v0.32.0
https://github.com/axios/axios/releases/tag/v1.16.0
https://github.com/axios/axios/security/advisories/GHSA-p92q-9vqr-4j8v
https://nvd.nist.gov/vuln/detail/CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
|
| axios |
CVE-2026-44492 |
HIGH |
0.27.2 |
1.16.0, 0.32.0 |
https://access.redhat.com/security/cve/CVE-2026-44492
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-pjwm-pj3p-43mv
https://nvd.nist.gov/vuln/detail/CVE-2025-62718
https://nvd.nist.gov/vuln/detail/CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
|
| axios |
CVE-2026-44495 |
HIGH |
0.27.2 |
1.15.2, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-44495
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-3g43-6gmg-66jw
https://nvd.nist.gov/vuln/detail/CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
|
| axios |
CVE-2026-44496 |
HIGH |
0.27.2 |
1.16.0, 0.32.0 |
https://access.redhat.com/security/cve/CVE-2026-44496
https://github.com/axios/axios
https://github.com/axios/axios/releases/tag/v0.32.0
https://github.com/axios/axios/releases/tag/v1.16.0
https://github.com/axios/axios/security/advisories/GHSA-hfxv-24rg-xrqf
https://nvd.nist.gov/vuln/detail/CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
|
| axios |
CVE-2023-45857 |
MEDIUM |
0.27.2 |
1.6.0, 0.28.0 |
https://access.redhat.com/security/cve/CVE-2023-45857
https://github.com/axios/axios
https://github.com/axios/axios/commit/2755df562b9c194fba6d8b609a383443f6a6e967
https://github.com/axios/axios/commit/96ee232bd3ee4de2e657333d4d2191cd389e14d0
https://github.com/axios/axios/issues/6006
https://github.com/axios/axios/issues/6022
https://github.com/axios/axios/pull/6028
https://github.com/axios/axios/pull/6091
https://github.com/axios/axios/releases/tag/v0.28.0
https://github.com/axios/axios/releases/tag/v1.6.0
https://nvd.nist.gov/vuln/detail/CVE-2023-45857
https://security.netapp.com/advisory/ntap-20240621-0006
https://security.netapp.com/advisory/ntap-20240621-0006/
https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
https://www.cve.org/CVERecord?id=CVE-2023-45857
|
| axios |
CVE-2025-62718 |
MEDIUM |
0.27.2 |
1.15.0, 0.31.0 |
https://access.redhat.com/security/cve/CVE-2025-62718
https://datatracker.ietf.org/doc/html/rfc1034#section-3.1
https://datatracker.ietf.org/doc/html/rfc3986#section-3.2.2
https://github.com/axios/axios
https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c
https://github.com/axios/axios/commit/fb3befb6daac6cad26b2e54094d0f2d9e47f24df
https://github.com/axios/axios/pull/10661
https://github.com/axios/axios/pull/10688
https://github.com/axios/axios/releases/tag/v0.31.0
https://github.com/axios/axios/releases/tag/v1.15.0
https://github.com/axios/axios/security/advisories/GHSA-3p68-rc4w-qgx5
https://nvd.nist.gov/vuln/detail/CVE-2025-62718
https://www.cve.org/CVERecord?id=CVE-2025-62718
|
| axios |
CVE-2026-40175 |
MEDIUM |
0.27.2 |
1.15.0, 0.31.0 |
https://access.redhat.com/security/cve/CVE-2026-40175
https://cert-portal.siemens.com/productcert/html/ssa-876049.html
https://github.com/axios/axios
https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c
https://github.com/axios/axios/commit/363185461b90b1b78845dc8a99a1f103d9b122a1
https://github.com/axios/axios/pull/10660
https://github.com/axios/axios/pull/10660#issuecomment-4224168081
https://github.com/axios/axios/pull/10688
https://github.com/axios/axios/releases/tag/v0.31.0
https://github.com/axios/axios/releases/tag/v1.15.0
https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx
https://nvd.nist.gov/vuln/detail/CVE-2026-40175
https://www.cve.org/CVERecord?id=CVE-2026-40175
|
| axios |
CVE-2026-42034 |
MEDIUM |
0.27.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42034
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-5c9x-8gcm-mpgx
https://nvd.nist.gov/vuln/detail/CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
|
| axios |
CVE-2026-42036 |
MEDIUM |
0.27.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42036
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-vf2m-468p-8v99
https://nvd.nist.gov/vuln/detail/CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
|
| axios |
CVE-2026-42038 |
MEDIUM |
0.27.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42038
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-m7pr-hjqh-92cm
https://nvd.nist.gov/vuln/detail/CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
|
| axios |
CVE-2026-42039 |
MEDIUM |
0.27.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42039
https://github.com/axios/axios
https://github.com/axios/axios/commit/85132ffba1a77609ea5d101c8a413dea7174932f
https://github.com/axios/axios/releases/tag/v1.15.1
https://github.com/axios/axios/security/advisories/GHSA-62hf-57xw-28j9
https://nvd.nist.gov/vuln/detail/CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
|
| axios |
CVE-2026-42041 |
MEDIUM |
0.27.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42041
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-w9j2-pvgh-6h63
https://nvd.nist.gov/vuln/detail/CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
|
| axios |
CVE-2026-42042 |
MEDIUM |
0.27.2 |
1.15.1, 0.31.1 |
https://access.redhat.com/security/cve/CVE-2026-42042
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-xx6v-rp6x-q39c
https://nvd.nist.gov/vuln/detail/CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
|
| axios |
CVE-2026-44490 |
MEDIUM |
0.27.2 |
1.16.0, 0.32.0 |
https://access.redhat.com/security/cve/CVE-2026-44490
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-898c-q2cr-xwhg
https://nvd.nist.gov/vuln/detail/CVE-2018-16487
https://nvd.nist.gov/vuln/detail/CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
|
| axios |
CVE-2026-42040 |
LOW |
0.27.2 |
1.15.1, 0.31.1 |
https://github.com/axios/axios
https://github.com/axios/axios/security/advisories/GHSA-xhjh-pmcv-23jw
https://nvd.nist.gov/vuln/detail/CVE-2026-42040
|
| d3-color |
GHSA-36jr-mh4h-2g58 |
HIGH |
1.4.1 |
3.1.0 |
https://github.com/d3/d3-color
https://github.com/d3/d3-color/pull/100
https://github.com/d3/d3-color/releases/tag/v3.1.0
https://security.snyk.io/vuln/SNYK-JS-D3COLOR-1076592
|
| dompurify |
CVE-2024-48910 |
CRITICAL |
2.3.5 |
2.4.2 |
https://access.redhat.com/security/cve/CVE-2024-48910
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/commit/d1dd0374caef2b4c56c3bd09fe1988c3479166dc
https://github.com/cure53/DOMPurify/security/advisories/GHSA-p3vf-v8qc-cwcr
https://lists.debian.org/debian-lts-announce/2025/02/msg00010.html
https://nvd.nist.gov/vuln/detail/CVE-2024-48910
https://www.cve.org/CVERecord?id=CVE-2024-48910
|
| dompurify |
CVE-2024-45801 |
HIGH |
2.3.5 |
2.5.4, 3.1.3 |
https://access.redhat.com/security/cve/CVE-2024-45801
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/commit/1e520262bf4c66b5efda49e2316d6d1246ca7b21
https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc
https://github.com/cure53/DOMPurify/security/advisories/GHSA-mmhx-hmjr-r674
https://nvd.nist.gov/vuln/detail/CVE-2024-45801
https://www.cve.org/CVERecord?id=CVE-2024-45801
|
| dompurify |
CVE-2024-47875 |
HIGH |
2.3.5 |
2.5.0, 3.1.3 |
http://seclists.org/fulldisclosure/2025/Apr/14
https://access.redhat.com/errata/RHSA-2024:9473
https://access.redhat.com/security/cve/CVE-2024-47875
https://bugzilla.redhat.com/2310528
https://bugzilla.redhat.com/2318052
https://bugzilla.redhat.com/show_bug.cgi?id=2310528
https://bugzilla.redhat.com/show_bug.cgi?id=2318052
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34156
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-47875
https://errata.almalinux.org/9/ALSA-2024-9473.html
https://errata.rockylinux.org/RLSA-2024:9473
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/blob/0ef5e537a514f904b6aa1d7ad9e749e365d7185f/test/test-suite.js#L2098
https://github.com/cure53/DOMPurify/commit/0ef5e537a514f904b6aa1d7ad9e749e365d7185f
https://github.com/cure53/DOMPurify/commit/6ea80cd8b47640c20f2f230c7920b1f4ce4fdf7a
https://github.com/cure53/DOMPurify/security/advisories/GHSA-gx9m-whjm-85jf
https://linux.oracle.com/cve/CVE-2024-47875.html
https://linux.oracle.com/errata/ELSA-2024-9473.html
https://lists.debian.org/debian-lts-announce/2025/02/msg00010.html
https://nvd.nist.gov/vuln/detail/CVE-2024-47875
https://www.cve.org/CVERecord?id=CVE-2024-47875
|
| dompurify |
CVE-2025-26791 |
MEDIUM |
2.3.5 |
3.2.4 |
https://access.redhat.com/security/cve/CVE-2025-26791
https://ensy.zip/posts/dompurify-323-bypass
https://ensy.zip/posts/dompurify-323-bypass/
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02
https://github.com/cure53/DOMPurify/releases/tag/3.2.4
https://nsysean.github.io/posts/dompurify-323-bypass
https://nsysean.github.io/posts/dompurify-323-bypass/
https://nvd.nist.gov/vuln/detail/CVE-2025-26791
https://www.cve.org/CVERecord?id=CVE-2025-26791
|
| dompurify |
CVE-2026-41239 |
MEDIUM |
2.3.5 |
3.4.0 |
https://access.redhat.com/security/cve/CVE-2026-41239
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/releases/tag/3.4.0
https://github.com/cure53/DOMPurify/security/advisories/GHSA-crv5-9vww-q3g8
https://nvd.nist.gov/vuln/detail/CVE-2026-41239
https://www.cve.org/CVERecord?id=CVE-2026-41239
|
| dompurify |
CVE-2026-41240 |
MEDIUM |
2.3.5 |
3.4.0 |
https://access.redhat.com/security/cve/CVE-2026-41240
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/commit/c361baa18dbdcb3344a41110f4c48ad85bf48f80
https://github.com/cure53/DOMPurify/releases/tag/3.4.0
https://github.com/cure53/DOMPurify/security/advisories/GHSA-h7mw-gpvr-xq4m
https://nvd.nist.gov/vuln/detail/CVE-2026-41240
https://www.cve.org/CVERecord?id=CVE-2026-41240
|
| dompurify |
CVE-2026-49458 |
MEDIUM |
2.3.5 |
3.4.6 |
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-hpcv-96wg-7vj8
|
| dompurify |
CVE-2026-49459 |
MEDIUM |
2.3.5 |
3.4.6 |
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-r47g-fvhr-h676
|
| dompurify |
CVE-2026-49978 |
MEDIUM |
2.3.5 |
3.4.7 |
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-rp9w-3fw7-7cwq
|
| dompurify |
GHSA-39q2-94rc-95cp |
MEDIUM |
2.3.5 |
3.4.0 |
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-39q2-94rc-95cp
|
| dompurify |
GHSA-76mc-f452-cxcm |
MEDIUM |
2.3.5 |
3.4.7 |
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-76mc-f452-cxcm
|
| dompurify |
GHSA-cj63-jhhr-wcxv |
MEDIUM |
2.3.5 |
3.3.2 |
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/releases/tag/3.3.2
https://github.com/cure53/DOMPurify/security/advisories/GHSA-cj63-jhhr-wcxv
|
| dompurify |
GHSA-cjmm-f4jc-qw8r |
MEDIUM |
2.3.5 |
3.3.2 |
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/releases/tag/3.3.2
https://github.com/cure53/DOMPurify/security/advisories/GHSA-cjmm-f4jc-qw8r
|
| dompurify |
GHSA-h8r8-wccr-v5f2 |
MEDIUM |
2.3.5 |
3.3.2 |
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/releases/tag/3.3.2
https://github.com/cure53/DOMPurify/security/advisories/GHSA-h8r8-wccr-v5f2
|
| dompurify |
GHSA-vxr8-fq34-vvx9 |
LOW |
2.3.5 |
3.4.9 |
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-vxr8-fq34-vvx9
|
| dompurify |
GHSA-x4vx-rjvf-j5p4 |
LOW |
2.3.5 |
|
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/security/advisories/GHSA-x4vx-rjvf-j5p4
|
| follow-redirects |
CVE-2023-26159 |
MEDIUM |
1.15.0 |
1.15.4 |
https://access.redhat.com/security/cve/CVE-2023-26159
https://github.com/follow-redirects/follow-redirects
https://github.com/follow-redirects/follow-redirects/commit/7a6567e16dfa9ad18a70bfe91784c28653fbf19d
https://github.com/follow-redirects/follow-redirects/issues/235
https://github.com/follow-redirects/follow-redirects/pull/236
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZZ425BFKNBQ6AK7I5SAM56TWON5OF2XM
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZZ425BFKNBQ6AK7I5SAM56TWON5OF2XM/
https://nvd.nist.gov/vuln/detail/CVE-2023-26159
https://security.netapp.com/advisory/ntap-20241108-0002
https://security.netapp.com/advisory/ntap-20241108-0002/
https://security.snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-6141137
https://ubuntu.com/security/notices/USN-8217-1
https://www.cve.org/CVERecord?id=CVE-2023-26159
|
| follow-redirects |
CVE-2024-28849 |
MEDIUM |
1.15.0 |
1.15.6 |
https://access.redhat.com/security/cve/CVE-2024-28849
https://fetch.spec.whatwg.org/#authentication-entries
https://github.com/follow-redirects/follow-redirects
https://github.com/follow-redirects/follow-redirects/commit/c4f847f85176991f95ab9c88af63b1294de8649b
https://github.com/follow-redirects/follow-redirects/commit/c4f847f85176991f95ab9c88af63b1294de8649b (v1.15.6)
https://github.com/follow-redirects/follow-redirects/security/advisories/GHSA-cxjh-pqwp-8mfp
https://github.com/psf/requests/issues/1885
https://hackerone.com/reports/2390009
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOIF4EPQUCKDBEVTGRQDZ3CGTYQHPO7Z
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOIF4EPQUCKDBEVTGRQDZ3CGTYQHPO7Z/
https://nvd.nist.gov/vuln/detail/CVE-2024-28849
https://ubuntu.com/security/notices/USN-8217-1
https://www.cve.org/CVERecord?id=CVE-2024-28849
|
| follow-redirects |
GHSA-r4q5-vmmm-2653 |
MEDIUM |
1.15.0 |
1.16.0 |
https://github.com/follow-redirects/follow-redirects
https://github.com/follow-redirects/follow-redirects/commit/844c4d302ac963d29bdb5dc1754ec7df3d70d7f9
https://github.com/follow-redirects/follow-redirects/security/advisories/GHSA-r4q5-vmmm-2653
|
| follow-redirects |
CVE-2022-0155 |
HIGH |
1.5.10 |
1.14.7 |
https://access.redhat.com/security/cve/CVE-2022-0155
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
https://github.com/follow-redirects/follow-redirects
https://github.com/follow-redirects/follow-redirects/commit/8b347cbcef7c7b72a6e9be20f5710c17d6163c22
https://github.com/follow-redirects/follow-redirects/commit/8b347cbcef7c7b72a6e9be20f5710c17d6163c22 (v1.14.7)
https://github.com/follow-redirects/follow-redirects/issues/183
https://huntr.dev/bounties/fc524e4b-ebb6-427d-ab67-a64181020406
https://huntr.dev/bounties/fc524e4b-ebb6-427d-ab67-a64181020406/
https://nvd.nist.gov/vuln/detail/CVE-2022-0155
https://ubuntu.com/security/notices/USN-8217-1
https://www.cve.org/CVERecord?id=CVE-2022-0155
|
| follow-redirects |
CVE-2022-0536 |
MEDIUM |
1.5.10 |
1.14.8 |
https://access.redhat.com/security/cve/CVE-2022-0536
https://github.com/follow-redirects/follow-redirects
https://github.com/follow-redirects/follow-redirects/commit/62e546a99c07c3ee5e4e0718c84a6ca127c5c445
https://huntr.dev/bounties/7cf2bf90-52da-4d59-8028-a73b132de0db
https://nvd.nist.gov/vuln/detail/CVE-2022-0536
https://ubuntu.com/security/notices/USN-8217-1
https://www.cve.org/CVERecord?id=CVE-2022-0536
|
| follow-redirects |
CVE-2023-26159 |
MEDIUM |
1.5.10 |
1.15.4 |
https://access.redhat.com/security/cve/CVE-2023-26159
https://github.com/follow-redirects/follow-redirects
https://github.com/follow-redirects/follow-redirects/commit/7a6567e16dfa9ad18a70bfe91784c28653fbf19d
https://github.com/follow-redirects/follow-redirects/issues/235
https://github.com/follow-redirects/follow-redirects/pull/236
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZZ425BFKNBQ6AK7I5SAM56TWON5OF2XM
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZZ425BFKNBQ6AK7I5SAM56TWON5OF2XM/
https://nvd.nist.gov/vuln/detail/CVE-2023-26159
https://security.netapp.com/advisory/ntap-20241108-0002
https://security.netapp.com/advisory/ntap-20241108-0002/
https://security.snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-6141137
https://ubuntu.com/security/notices/USN-8217-1
https://www.cve.org/CVERecord?id=CVE-2023-26159
|
| follow-redirects |
CVE-2024-28849 |
MEDIUM |
1.5.10 |
1.15.6 |
https://access.redhat.com/security/cve/CVE-2024-28849
https://fetch.spec.whatwg.org/#authentication-entries
https://github.com/follow-redirects/follow-redirects
https://github.com/follow-redirects/follow-redirects/commit/c4f847f85176991f95ab9c88af63b1294de8649b
https://github.com/follow-redirects/follow-redirects/commit/c4f847f85176991f95ab9c88af63b1294de8649b (v1.15.6)
https://github.com/follow-redirects/follow-redirects/security/advisories/GHSA-cxjh-pqwp-8mfp
https://github.com/psf/requests/issues/1885
https://hackerone.com/reports/2390009
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOIF4EPQUCKDBEVTGRQDZ3CGTYQHPO7Z
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOIF4EPQUCKDBEVTGRQDZ3CGTYQHPO7Z/
https://nvd.nist.gov/vuln/detail/CVE-2024-28849
https://ubuntu.com/security/notices/USN-8217-1
https://www.cve.org/CVERecord?id=CVE-2024-28849
|
| follow-redirects |
GHSA-r4q5-vmmm-2653 |
MEDIUM |
1.5.10 |
1.16.0 |
https://github.com/follow-redirects/follow-redirects
https://github.com/follow-redirects/follow-redirects/commit/844c4d302ac963d29bdb5dc1754ec7df3d70d7f9
https://github.com/follow-redirects/follow-redirects/security/advisories/GHSA-r4q5-vmmm-2653
|
| form-data |
CVE-2025-7783 |
CRITICAL |
4.0.0 |
2.5.4, 3.0.4, 4.0.4 |
https://access.redhat.com/security/cve/CVE-2025-7783
https://github.com/benweissmann/CVE-2025-7783-poc
https://github.com/form-data/form-data
https://github.com/form-data/form-data/commit/3d1723080e6577a66f17f163ecd345a21d8d0fd0
https://github.com/form-data/form-data/security/advisories/GHSA-fjxv-7rqg-78g4
https://lists.debian.org/debian-lts-announce/2025/07/msg00023.html
https://nvd.nist.gov/vuln/detail/CVE-2025-7783
https://ubuntu.com/security/notices/USN-7976-1
https://www.cve.org/CVERecord?id=CVE-2025-7783
|
| form-data |
CVE-2026-12143 |
HIGH |
4.0.0 |
2.5.6, 3.0.5, 4.0.6 |
https://cwe.mitre.org/data/definitions/93.html
https://github.com/form-data/form-data
https://github.com/form-data/form-data/commit/64190db548c0179e37206858e39f27cf513e9435
https://github.com/form-data/form-data/commit/be3f3cf553978bac15a5182f1f3c3d2d38ccf229
https://github.com/form-data/form-data/commit/c7133499c2ee1b80c678e411244f4442bf902045
https://github.com/form-data/form-data/security/advisories/GHSA-hmw2-7cc7-3qxx
https://html.spec.whatwg.org/multipage/form-control-infrastructure.html#multipart-form-data
https://nvd.nist.gov/vuln/detail/CVE-2026-12143
https://www.npmjs.com/package/form-data
|
| katex |
CVE-2024-28243 |
MEDIUM |
0.12.0 |
0.16.10 |
https://github.com/KaTeX/KaTeX
https://github.com/KaTeX/KaTeX/commit/e88b4c357f978b1bca8edfe3297f0aa309bcbe34
https://github.com/KaTeX/KaTeX/commit/e88b4c357f978b1bca8edfe3297f0aa309bcbe34 (v0.16.10)
https://github.com/KaTeX/KaTeX/security/advisories/GHSA-64fm-8hw2-v72w
https://github.com/github/advisory-database/pull/6777
https://nvd.nist.gov/vuln/detail/CVE-2024-28243
https://ubuntu.com/security/notices/USN-7572-1
https://www.cve.org/CVERecord?id=CVE-2024-28243
|
| katex |
CVE-2024-28245 |
MEDIUM |
0.12.0 |
0.16.10 |
https://github.com/KaTeX/KaTeX
https://github.com/KaTeX/KaTeX/commit/c5897fcd1f73da9612a53e6b5544f1d776e17770
https://github.com/KaTeX/KaTeX/commit/c5897fcd1f73da9612a53e6b5544f1d776e17770 (v0.16.10)
https://github.com/KaTeX/KaTeX/security/advisories/GHSA-f98w-7cxr-ff2h
https://nvd.nist.gov/vuln/detail/CVE-2024-28245
https://ubuntu.com/security/notices/USN-7572-1
https://www.cve.org/CVERecord?id=CVE-2024-28245
|
| katex |
CVE-2024-28246 |
MEDIUM |
0.12.0 |
0.16.10 |
https://github.com/KaTeX/KaTeX
https://github.com/KaTeX/KaTeX/commit/fc5af64183a3ceb9be9d1c23a275999a728593de
https://github.com/KaTeX/KaTeX/commit/fc5af64183a3ceb9be9d1c23a275999a728593de (v0.16.10)
https://github.com/KaTeX/KaTeX/security/advisories/GHSA-3wc5-fcw2-2329
https://nvd.nist.gov/vuln/detail/CVE-2024-28246
https://ubuntu.com/security/notices/USN-7572-1
https://www.cve.org/CVERecord?id=CVE-2024-28246
|
| katex |
CVE-2025-23207 |
MEDIUM |
0.12.0 |
0.16.21 |
https://access.redhat.com/security/cve/CVE-2025-23207
https://github.com/KaTeX/KaTeX
https://github.com/KaTeX/KaTeX/commit/ff289955e81aab89086eef09254cbf88573d415c
https://github.com/KaTeX/KaTeX/commit/ff289955e81aab89086eef09254cbf88573d415c (v0.16.21)
https://github.com/KaTeX/KaTeX/security/advisories/GHSA-cg87-wmx4-v546
https://nvd.nist.gov/vuln/detail/CVE-2025-23207
https://ubuntu.com/security/notices/USN-7572-1
https://www.cve.org/CVERecord?id=CVE-2025-23207
|
| lodash |
CVE-2026-4800 |
HIGH |
4.17.21 |
4.18.0 |
https://access.redhat.com/errata/RHSA-2026:10710
https://access.redhat.com/security/cve/CVE-2026-4800
https://bugzilla.redhat.com/2453496
https://bugzilla.redhat.com/show_bug.cgi?id=2431740
https://bugzilla.redhat.com/show_bug.cgi?id=2453496
https://cna.openjsf.org/security-advisories.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13465
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-4800
https://errata.almalinux.org/9/ALSA-2026-10710.html
https://errata.rockylinux.org/RLSA-2026:24331
https://github.com/advisories/GHSA-35jh-r3h4-6jhm
https://github.com/lodash/lodash
https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c
https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc
https://linux.oracle.com/cve/CVE-2026-4800.html
https://linux.oracle.com/errata/ELSA-2026-10713.html
https://nvd.nist.gov/vuln/detail/CVE-2026-4800
https://ubuntu.com/security/notices/USN-8411-1
https://www.cve.org/CVERecord?id=CVE-2026-4800
|
| lodash |
CVE-2025-13465 |
MEDIUM |
4.17.21 |
4.17.23 |
https://access.redhat.com/errata/RHSA-2026:2452
https://access.redhat.com/security/cve/CVE-2025-13465
https://bugzilla.redhat.com/2431740
https://bugzilla.redhat.com/show_bug.cgi?id=2425946
https://bugzilla.redhat.com/show_bug.cgi?id=2430538
https://bugzilla.redhat.com/show_bug.cgi?id=2431036
https://bugzilla.redhat.com/show_bug.cgi?id=2431740
https://bugzilla.redhat.com/show_bug.cgi?id=2433645
https://cert-portal.siemens.com/productcert/html/ssa-253495.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-13465
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15284
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23745
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23950
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24842
https://errata.almalinux.org/9/ALSA-2026-2452.html
https://errata.rockylinux.org/RLSA-2026:18868
https://github.com/lodash/lodash
https://github.com/lodash/lodash/commit/edadd452146f7e4bad4ea684e955708931d84d81
https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg
https://linux.oracle.com/cve/CVE-2025-13465.html
https://linux.oracle.com/errata/ELSA-2026-2452.html
https://nvd.nist.gov/vuln/detail/CVE-2025-13465
https://ubuntu.com/security/notices/USN-8411-1
https://www.cve.org/CVERecord?id=CVE-2025-13465
|
| lodash |
CVE-2026-2950 |
MEDIUM |
4.17.21 |
4.18.0 |
https://access.redhat.com/security/cve/CVE-2026-2950
https://github.com/lodash/lodash
https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh
https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg
https://nvd.nist.gov/vuln/detail/CVE-2026-2950
https://ubuntu.com/security/notices/USN-8411-1
https://www.cve.org/CVERecord?id=CVE-2026-2950
|
| markdown-it |
CVE-2026-48988 |
MEDIUM |
12.3.2 |
14.2.0 |
https://github.com/markdown-it/markdown-it
https://github.com/markdown-it/markdown-it/security/advisories/GHSA-6v5v-wf23-fmfq
|
| mermaid |
GHSA-m4gq-x24j-jpmf |
HIGH |
8.14.0 |
10.9.3 |
https://github.com/cure53/DOMPurify/security/advisories/GHSA-mmhx-hmjr-r674
https://github.com/mermaid-js/mermaid
https://github.com/mermaid-js/mermaid/commit/6c785c93166c151d27d328ddf68a13d9d65adc00
https://github.com/mermaid-js/mermaid/commit/92a07ffe40aab2769dd1c3431b4eb5beac282b34
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-m4gq-x24j-jpmf
|
| mermaid |
CVE-2022-31108 |
MEDIUM |
8.14.0 |
9.1.2 |
https://github.com/mermaid-js/mermaid
https://github.com/mermaid-js/mermaid/commit/0ae1bdb61adff1cd485caff8c62ec6b8ac57b225
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-x3vm-38hw-55wf
https://nvd.nist.gov/vuln/detail/CVE-2022-31108
|
| mermaid |
CVE-2026-41148 |
MEDIUM |
8.14.0 |
11.15.0, 10.9.6 |
https://github.com/mermaid-js/mermaid
https://github.com/mermaid-js/mermaid/commit/8fead23c59166b7bab6a39eac81acebee2859102
https://github.com/mermaid-js/mermaid/commit/e9b0f34d8d82a6260077764ee45e1d7d90957a0f
https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0
https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-xcj9-5m2h-648r
https://mermaid.js.org/config/schema-docs/config.html#securitylevel
https://nvd.nist.gov/vuln/detail/CVE-2026-41148
|
| mermaid |
CVE-2026-41149 |
MEDIUM |
8.14.0 |
11.15.0, 10.9.6 |
https://github.com/mermaid-js/mermaid
https://github.com/mermaid-js/mermaid/commit/37ff937f1da2e19f882fd1db01235db4d01f4056
https://github.com/mermaid-js/mermaid/commit/4e2d512bf5bf6f9de1a8f0a48da78dc4d09ac4f3
https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0
https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-ghcm-xqfw-q4vr
https://mermaid.js.org/config/schema-docs/config.html#securitylevel
https://nvd.nist.gov/vuln/detail/CVE-2026-41149
|
| mermaid |
CVE-2026-41150 |
MEDIUM |
8.14.0 |
11.15.0, 10.9.6 |
https://access.redhat.com/security/cve/CVE-2026-41150
https://github.com/mermaid-js/mermaid
https://github.com/mermaid-js/mermaid/commit/a59ea56174712ee5430dfd5bc877cb5151f501a6
https://github.com/mermaid-js/mermaid/commit/faafb5d49106dd32c367f3882505f2dd625aa30e
https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0
https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6m6c-36f7-fhxh
https://nvd.nist.gov/vuln/detail/CVE-2026-41150
https://www.cve.org/CVERecord?id=CVE-2026-41150
|
| mermaid |
CVE-2026-41159 |
MEDIUM |
8.14.0 |
11.15.0, 10.9.6 |
https://github.com/mermaid-js/mermaid
https://github.com/mermaid-js/mermaid/commit/64769738d5b59211e1decb471ffbaca8afec51aa
https://github.com/mermaid-js/mermaid/commit/64769738d5b59211e1decb471ffbaca8afec51aahttps://github.com/mermaid-js/mermaid/commit/a9d9f0d8eb790349121508688cd338253fd80d76
https://github.com/mermaid-js/mermaid/commit/a9d9f0d8eb790349121508688cd338253fd80d76
https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0
https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.15.0
https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-87f9-hvmw-gh4p
https://nvd.nist.gov/vuln/detail/CVE-2026-41159
|
| moment |
CVE-2022-31129 |
HIGH |
2.29.3 |
2.29.4 |
https://access.redhat.com/security/cve/CVE-2022-31129
https://github.com/moment/moment
https://github.com/moment/moment/commit/9a3b5894f3d5d602948ac8a02e4ee528a49ca3a3
https://github.com/moment/moment/pull/6015#issuecomment-1152961973
https://github.com/moment/moment/pull/6015/commits/4bbb9f3ccbe231de40207503f344fe5ce97584f4
https://github.com/moment/moment/pull/6015/commits/bfd4f2375d5c1a2106246721d693a9611dddfbfe
https://github.com/moment/moment/pull/6015/commits/dc0d180e90d8a84f7ff13572363330a22b3ea504
https://github.com/moment/moment/security/advisories/GHSA-wc69-rhjr-hc9g
https://huntr.dev/bounties/f0952b67-f2ff-44a9-a9cd-99e0a87cb633
https://huntr.dev/bounties/f0952b67-f2ff-44a9-a9cd-99e0a87cb633/
https://lists.debian.org/debian-lts-announce/2023/01/msg00035.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IWY24RJA3SBJGA5N4CU4VBPHJPPPJL5O
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IWY24RJA3SBJGA5N4CU4VBPHJPPPJL5O/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IWY24RJA3SBJGA5N4CU4VBPHJPPPJL5O
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO
https://nvd.nist.gov/vuln/detail/CVE-2022-31129
https://security.netapp.com/advisory/ntap-20221014-0003
https://security.netapp.com/advisory/ntap-20221014-0003/
https://security.netapp.com/advisory/ntap-20241108-0002
https://security.netapp.com/advisory/ntap-20241108-0002/
https://ubuntu.com/security/notices/USN-5559-1
https://ubuntu.com/security/notices/USN-6550-1
https://www.cve.org/CVERecord?id=CVE-2022-31129
|
| vue |
CVE-2024-9506 |
LOW |
2.6.14 |
3.0.0-alpha.0 |
https://access.redhat.com/security/cve/CVE-2024-9506
https://github.com/vuejs/core
https://nvd.nist.gov/vuln/detail/CVE-2024-9506
https://www.cve.org/CVERecord?id=CVE-2024-9506
https://www.herodevs.com/vulnerability-directory/cve-2024-9506
|
| vue-template-compiler |
CVE-2024-6783 |
MEDIUM |
2.6.14 |
3.0.0 |
https://github.com/advisories/GHSA-g3ch-rx76-35fx
https://github.com/vuejs/vue
https://nvd.nist.gov/vuln/detail/CVE-2024-6783
https://www.herodevs.com/vulnerability-directory/cve-2024-6783
https://www.herodevs.com/vulnerability-directory/cve-2024-6783---vue-client-side-xss
|
| No Misconfigurations found |
| No Vulnerabilities found |
| Dockerfile Security Check |
DS002 |
Image user should not be 'root' |
HIGH |
Specify at least 1 USER command in Dockerfile with non-root user as argument
https://avd.aquasec.com/misconfig/ds002
|
| Dockerfile Security Check |
DS026 |
No HEALTHCHECK defined |
LOW |
Add HEALTHCHECK instruction in your Dockerfile
https://avd.aquasec.com/misconfig/ds026
|