| No Vulnerabilities found |
| No Misconfigurations found |
| body-parser |
CVE-2026-12590 |
LOW |
2.2.2 |
1.20.6, 2.3.0 |
https://access.redhat.com/security/cve/CVE-2026-12590
https://cna.openjsf.org/security-advisories.html
https://github.com/expressjs/body-parser
https://github.com/expressjs/body-parser/commit/2322e111cc321413ec2b7b76d01be533d3de9d7d
https://github.com/expressjs/body-parser/commit/3492672eee593d5c158f239b6e9115498a5dbeac
https://github.com/expressjs/body-parser/pull/698
https://github.com/expressjs/body-parser/pull/741
https://github.com/expressjs/body-parser/releases/tag/1.20.6
https://github.com/expressjs/body-parser/releases/tag/v2.3.0
https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6
https://nvd.nist.gov/vuln/detail/CVE-2026-12590
https://www.cve.org/CVERecord?id=CVE-2026-12590
|
| brace-expansion |
CVE-2026-14257 |
HIGH |
5.0.7 |
5.0.8, 3.0.3, 2.1.3, 1.1.17 |
https://access.redhat.com/security/cve/CVE-2026-14257
https://github.com/juliangruber/brace-expansion
https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d
https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5
https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031
https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb
https://github.com/juliangruber/brace-expansion/pull/129
https://github.com/juliangruber/brace-expansion/pull/130
https://github.com/juliangruber/brace-expansion/pull/136
https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-mh99-v99m-4gvg
https://nvd.nist.gov/vuln/detail/CVE-2026-14257
https://www.cve.org/CVERecord?id=CVE-2026-14257
https://www.npmjs.com/package/brace-expansion
|
| brace-expansion |
CVE-2026-69152 |
HIGH |
5.0.7 |
1.1.18, 2.1.4, 3.0.6, 5.0.9 |
https://access.redhat.com/security/cve/CVE-2026-69152
https://github.com/juliangruber/brace-expansion
https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d
https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac
https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf
https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031
https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895
https://nvd.nist.gov/vuln/detail/CVE-2026-69152
https://www.cve.org/CVERecord?id=CVE-2026-69152
|
| ip-address |
CVE-2026-69192 |
HIGH |
10.2.0 |
10.3.1 |
https://github.com/beaugunderson/ip-address
https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e
https://github.com/beaugunderson/ip-address/releases/tag/v10.3.1
https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr
|
| ip-address |
CVE-2026-54272 |
MEDIUM |
10.2.0 |
10.2.1 |
https://access.redhat.com/security/cve/CVE-2026-54272
https://github.com/beaugunderson/ip-address
https://github.com/beaugunderson/ip-address/commit/4a1f613f4c1bec915677dea923c10aaa09361ef9
https://github.com/beaugunderson/ip-address/releases/tag/v10.2.1
https://github.com/beaugunderson/ip-address/security/advisories/GHSA-22jq-vg5j-6vgg
https://nvd.nist.gov/vuln/detail/CVE-2026-54272
https://www.cve.org/CVERecord?id=CVE-2026-54272
|
| ip-address |
CVE-2026-69198 |
MEDIUM |
10.2.0 |
10.2.2 |
https://github.com/beaugunderson/ip-address
https://github.com/beaugunderson/ip-address/commit/488fe9bc7c35363b4b090494fc38c266d217740d
https://github.com/beaugunderson/ip-address/releases/tag/v10.2.2
https://github.com/beaugunderson/ip-address/security/advisories/GHSA-4xrf-jv44-h6hh
|
| postcss |
GHSA-r28c-9q8g-f849 |
HIGH |
8.5.16 |
8.5.18 |
https://github.com/postcss/postcss
https://github.com/postcss/postcss/commit/95663d3eb7ba26f4854dd19d3b4f4425760cf56c
https://github.com/postcss/postcss/releases/tag/8.5.18
https://github.com/postcss/postcss/security/advisories/GHSA-r28c-9q8g-f849
|
| postcss |
CVE-2026-69153 |
MEDIUM |
8.5.16 |
8.5.23 |
https://access.redhat.com/security/cve/CVE-2026-69153
https://github.com/postcss/postcss
https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8
https://github.com/postcss/postcss/releases/tag/8.5.19
https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp
https://nvd.nist.gov/vuln/detail/CVE-2026-69153
https://www.cve.org/CVERecord?id=CVE-2026-69153
|
| tar |
GHSA-r292-9mhp-454m |
MEDIUM |
7.5.19 |
7.5.21 |
https://github.com/isaacs/node-tar
https://github.com/isaacs/node-tar/commit/631ae59121bf8fc8a22bbae35f074cb9b789cd4a
https://github.com/isaacs/node-tar/releases/tag/v7.5.21
https://github.com/isaacs/node-tar/security/advisories/GHSA-r292-9mhp-454m
|
| undici |
CVE-2026-15157 |
MEDIUM |
6.27.0 |
6.28.0, 7.29.0, 8.9.0 |
https://cna.openjsf.org/security-advisories.html
https://github.com/nodejs/undici
https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d
https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400
https://github.com/nodejs/undici/commit/7d3cf924c262c486bc77f951348f4e5c847b7b42
https://github.com/nodejs/undici/releases/tag/v6.28.0
https://github.com/nodejs/undici/releases/tag/v7.29.0
https://github.com/nodejs/undici/releases/tag/v8.9.0
https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5
https://nvd.nist.gov/vuln/detail/CVE-2026-15157
|
| undici |
CVE-2026-16728 |
MEDIUM |
6.27.0 |
6.28.0, 7.29.0, 8.9.0 |
https://cna.openjsf.org/security-advisories.html
https://github.com/nodejs/undici
https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c
https://github.com/nodejs/undici/commit/2b3f749336d356bbbc50192f87f6cf7bc714721a
https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7
https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420
https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e
https://github.com/nodejs/undici/commit/e11a68ed4ff345c79402476f7a00d473443e318d
https://github.com/nodejs/undici/releases/tag/v6.28.0
https://github.com/nodejs/undici/releases/tag/v7.29.0
https://github.com/nodejs/undici/releases/tag/v8.9.0
https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524
https://hackerone.com/reports/3828685
https://nvd.nist.gov/vuln/detail/CVE-2026-16728
|
| undici |
CVE-2026-16729 |
MEDIUM |
6.27.0 |
6.28.0, 7.29.0, 8.9.0 |
https://cna.openjsf.org/security-advisories.html
https://github.com/nodejs/undici
https://github.com/nodejs/undici/commit/10d93fc332f2c8c161982dec3833201de29891b5
https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef
https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235
https://github.com/nodejs/undici/releases/tag/v6.28.0
https://github.com/nodejs/undici/releases/tag/v7.29.0
https://github.com/nodejs/undici/releases/tag/v8.9.0
https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm
https://nvd.nist.gov/vuln/detail/CVE-2026-16729
|
| No Misconfigurations found |
| No Vulnerabilities found |
| No Misconfigurations found |
| golang.org/x/text |
CVE-2026-56852 |
HIGH |
v0.38.0 |
0.39.0 |
https://go.dev/cl/794100
https://go.dev/issue/80142
https://nvd.nist.gov/vuln/detail/CVE-2026-56852
https://pkg.go.dev/vuln/GO-2026-5970
|
| stdlib |
CVE-2026-39822 |
HIGH |
v1.26.4 |
1.25.12, 1.26.5, 1.27.0-rc.2 |
https://access.redhat.com/errata/RHSA-2026:38878
https://access.redhat.com/security/cve/CVE-2026-39822
https://bugzilla.redhat.com/2498152
https://bugzilla.redhat.com/show_bug.cgi?id=2498152
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822
https://errata.almalinux.org/9/ALSA-2026-38878.html
https://errata.rockylinux.org/RLSA-2026:38495
https://go.dev/cl/797880
https://go.dev/issue/79005
https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
https://linux.oracle.com/cve/CVE-2026-39822.html
https://linux.oracle.com/errata/ELSA-2026-38995.html
https://nvd.nist.gov/vuln/detail/CVE-2026-39822
https://pkg.go.dev/vuln/GO-2026-4970
https://www.cve.org/CVERecord?id=CVE-2026-39822
|
| stdlib |
CVE-2026-42505 |
MEDIUM |
v1.26.4 |
1.25.12, 1.26.5, 1.27.0-rc.2 |
https://access.redhat.com/security/cve/CVE-2026-42505
https://go.dev/cl/775960
https://go.dev/issue/79282
https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
https://nvd.nist.gov/vuln/detail/CVE-2026-42505
https://pkg.go.dev/vuln/GO-2026-5856
https://www.cve.org/CVERecord?id=CVE-2026-42505
|
| No Misconfigurations found |
| golang.org/x/text |
CVE-2026-56852 |
HIGH |
v0.38.0 |
0.39.0 |
https://go.dev/cl/794100
https://go.dev/issue/80142
https://nvd.nist.gov/vuln/detail/CVE-2026-56852
https://pkg.go.dev/vuln/GO-2026-5970
|
| stdlib |
CVE-2026-39822 |
HIGH |
v1.26.4 |
1.25.12, 1.26.5, 1.27.0-rc.2 |
https://access.redhat.com/errata/RHSA-2026:38878
https://access.redhat.com/security/cve/CVE-2026-39822
https://bugzilla.redhat.com/2498152
https://bugzilla.redhat.com/show_bug.cgi?id=2498152
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822
https://errata.almalinux.org/9/ALSA-2026-38878.html
https://errata.rockylinux.org/RLSA-2026:38495
https://go.dev/cl/797880
https://go.dev/issue/79005
https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
https://linux.oracle.com/cve/CVE-2026-39822.html
https://linux.oracle.com/errata/ELSA-2026-38995.html
https://nvd.nist.gov/vuln/detail/CVE-2026-39822
https://pkg.go.dev/vuln/GO-2026-4970
https://www.cve.org/CVERecord?id=CVE-2026-39822
|
| stdlib |
CVE-2026-42505 |
MEDIUM |
v1.26.4 |
1.25.12, 1.26.5, 1.27.0-rc.2 |
https://access.redhat.com/security/cve/CVE-2026-42505
https://go.dev/cl/775960
https://go.dev/issue/79282
https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
https://nvd.nist.gov/vuln/detail/CVE-2026-42505
https://pkg.go.dev/vuln/GO-2026-5856
https://www.cve.org/CVERecord?id=CVE-2026-42505
|
| No Misconfigurations found |
| golang.org/x/text |
CVE-2026-56852 |
HIGH |
v0.38.0 |
0.39.0 |
https://go.dev/cl/794100
https://go.dev/issue/80142
https://nvd.nist.gov/vuln/detail/CVE-2026-56852
https://pkg.go.dev/vuln/GO-2026-5970
|
| stdlib |
CVE-2026-39822 |
HIGH |
v1.26.4 |
1.25.12, 1.26.5, 1.27.0-rc.2 |
https://access.redhat.com/errata/RHSA-2026:38878
https://access.redhat.com/security/cve/CVE-2026-39822
https://bugzilla.redhat.com/2498152
https://bugzilla.redhat.com/show_bug.cgi?id=2498152
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822
https://errata.almalinux.org/9/ALSA-2026-38878.html
https://errata.rockylinux.org/RLSA-2026:38495
https://go.dev/cl/797880
https://go.dev/issue/79005
https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
https://linux.oracle.com/cve/CVE-2026-39822.html
https://linux.oracle.com/errata/ELSA-2026-38995.html
https://nvd.nist.gov/vuln/detail/CVE-2026-39822
https://pkg.go.dev/vuln/GO-2026-4970
https://www.cve.org/CVERecord?id=CVE-2026-39822
|
| stdlib |
CVE-2026-42505 |
MEDIUM |
v1.26.4 |
1.25.12, 1.26.5, 1.27.0-rc.2 |
https://access.redhat.com/security/cve/CVE-2026-42505
https://go.dev/cl/775960
https://go.dev/issue/79282
https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
https://nvd.nist.gov/vuln/detail/CVE-2026-42505
https://pkg.go.dev/vuln/GO-2026-5856
https://www.cve.org/CVERecord?id=CVE-2026-42505
|
| No Misconfigurations found |
| golang.org/x/text |
CVE-2026-56852 |
HIGH |
v0.38.0 |
0.39.0 |
https://go.dev/cl/794100
https://go.dev/issue/80142
https://nvd.nist.gov/vuln/detail/CVE-2026-56852
https://pkg.go.dev/vuln/GO-2026-5970
|
| stdlib |
CVE-2026-39822 |
HIGH |
v1.26.4 |
1.25.12, 1.26.5, 1.27.0-rc.2 |
https://access.redhat.com/errata/RHSA-2026:38878
https://access.redhat.com/security/cve/CVE-2026-39822
https://bugzilla.redhat.com/2498152
https://bugzilla.redhat.com/show_bug.cgi?id=2498152
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39822
https://errata.almalinux.org/9/ALSA-2026-38878.html
https://errata.rockylinux.org/RLSA-2026:38495
https://go.dev/cl/797880
https://go.dev/issue/79005
https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
https://linux.oracle.com/cve/CVE-2026-39822.html
https://linux.oracle.com/errata/ELSA-2026-38995.html
https://nvd.nist.gov/vuln/detail/CVE-2026-39822
https://pkg.go.dev/vuln/GO-2026-4970
https://www.cve.org/CVERecord?id=CVE-2026-39822
|
| stdlib |
CVE-2026-42505 |
MEDIUM |
v1.26.4 |
1.25.12, 1.26.5, 1.27.0-rc.2 |
https://access.redhat.com/security/cve/CVE-2026-42505
https://go.dev/cl/775960
https://go.dev/issue/79282
https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
https://nvd.nist.gov/vuln/detail/CVE-2026-42505
https://pkg.go.dev/vuln/GO-2026-5856
https://www.cve.org/CVERecord?id=CVE-2026-42505
|
| No Misconfigurations found |