| @ai-sdk/provider-utils |
CVE-2026-8769 |
LOW |
3.0.30 |
|
https://gist.github.com/YLChen-007/fb1096bc8428bed9a428f764d9d103bb
https://github.com/vercel/ai
https://nvd.nist.gov/vuln/detail/CVE-2026-8769
https://vuldb.com/submit/811406
https://vuldb.com/vuln/364394
https://vuldb.com/vuln/364394/cti
|
| brace-expansion |
CVE-2026-69152 |
HIGH |
5.0.8 |
1.1.18, 2.1.4, 3.0.6, 5.0.9 |
https://access.redhat.com/security/cve/CVE-2026-69152
https://github.com/juliangruber/brace-expansion
https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d
https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac
https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf
https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031
https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895
https://nvd.nist.gov/vuln/detail/CVE-2026-69152
https://www.cve.org/CVERecord?id=CVE-2026-69152
|
| dompurify |
GHSA-55q2-fjhq-7xh7 |
MEDIUM |
3.4.12 |
3.4.13 |
https://github.com/cure53/DOMPurify
https://github.com/cure53/DOMPurify/commit/3067f7746769
https://github.com/cure53/DOMPurify/pull/1557
https://github.com/cure53/DOMPurify/releases/tag/3.4.13
https://github.com/cure53/DOMPurify/security/advisories/GHSA-55q2-fjhq-7xh7
|
| fast-uri |
CVE-2026-18446 |
HIGH |
3.1.4 |
2.4.4, 3.1.5, 4.1.2 |
https://access.redhat.com/security/cve/CVE-2026-18446
https://cna.openjsf.org/security-advisories.html
https://github.com/fastify/fast-uri
https://github.com/fastify/fast-uri/commit/f3c6c905f47831007490f466c5945012e905cc52
https://github.com/fastify/fast-uri/releases/tag/v4.1.2
https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7
https://nvd.nist.gov/vuln/detail/CVE-2026-18446
https://www.cve.org/CVERecord?id=CVE-2026-18446
|
| hono |
CVE-2026-69207 |
MEDIUM |
4.12.28 |
4.12.34 |
https://github.com/honojs/hono
https://github.com/honojs/hono/commit/93fc250d8b4df58ea542cb945171de8013d5e6d5
https://github.com/honojs/hono/releases/tag/v4.12.34
https://github.com/honojs/hono/security/advisories/GHSA-8j4g-w8fx-2239
|
| hono |
CVE-2026-71848 |
MEDIUM |
4.12.28 |
4.12.34 |
https://github.com/honojs/hono
https://github.com/honojs/hono/commit/f70e2c31684387b3231cc38512a31df6ca76a1c7
https://github.com/honojs/hono/releases/tag/v4.12.34
https://github.com/honojs/hono/security/advisories/GHSA-54fx-42gc-7vw4
|
| hono |
CVE-2026-71850 |
MEDIUM |
4.12.28 |
4.12.34 |
https://github.com/honojs/hono
https://github.com/honojs/hono/commit/0c45036d6b0ddf42ab2fa44639dc8710825d5c0f
https://github.com/honojs/hono/releases/tag/v4.12.34
https://github.com/honojs/hono/security/advisories/GHSA-f23p-vx2j-j53r
|
| hono |
CVE-2026-71849 |
LOW |
4.12.28 |
4.12.34 |
https://github.com/honojs/hono
https://github.com/honojs/hono/commit/720b566290793d4358bf39843adcb7cf4da4548f
https://github.com/honojs/hono/releases/tag/v4.12.34
https://github.com/honojs/hono/security/advisories/GHSA-79qm-7rj5-m7r9
|
| ip-address |
CVE-2026-69192 |
HIGH |
10.2.0 |
10.3.1 |
https://access.redhat.com/security/cve/CVE-2026-69192
https://github.com/beaugunderson/ip-address
https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e
https://github.com/beaugunderson/ip-address/releases/tag/v10.3.1
https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr
https://nvd.nist.gov/vuln/detail/CVE-2026-69192
https://www.cve.org/CVERecord?id=CVE-2026-69192
|
| ip-address |
CVE-2026-54272 |
MEDIUM |
10.2.0 |
10.2.1 |
https://access.redhat.com/security/cve/CVE-2026-54272
https://github.com/beaugunderson/ip-address
https://github.com/beaugunderson/ip-address/commit/4a1f613f4c1bec915677dea923c10aaa09361ef9
https://github.com/beaugunderson/ip-address/releases/tag/v10.2.1
https://github.com/beaugunderson/ip-address/security/advisories/GHSA-22jq-vg5j-6vgg
https://nvd.nist.gov/vuln/detail/CVE-2026-54272
https://www.cve.org/CVERecord?id=CVE-2026-54272
|
| ip-address |
CVE-2026-69198 |
MEDIUM |
10.2.0 |
10.2.2 |
https://access.redhat.com/security/cve/CVE-2026-69198
https://github.com/beaugunderson/ip-address
https://github.com/beaugunderson/ip-address/commit/488fe9bc7c35363b4b090494fc38c266d217740d
https://github.com/beaugunderson/ip-address/releases/tag/v10.2.2
https://github.com/beaugunderson/ip-address/security/advisories/GHSA-4xrf-jv44-h6hh
https://nvd.nist.gov/vuln/detail/CVE-2026-69198
https://www.cve.org/CVERecord?id=CVE-2026-69198
|
| js-yaml |
GHSA-5p4m-2wfm-xmqj |
HIGH |
4.3.0 |
4.3.1, 3.15.1 |
https://github.com/nodeca/js-yaml
https://github.com/nodeca/js-yaml/security/advisories/GHSA-5p4m-2wfm-xmqj
|
| nanoid |
CVE-2026-67213 |
HIGH |
3.3.15 |
3.3.17, 5.1.6 |
https://github.com/ai/nanoid
https://github.com/ai/nanoid/commit/cb3626d0f3342fdf179cd425fd9c4fbb92c7d0e7
https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b
https://github.com/ai/nanoid/releases/tag/3.3.17
https://github.com/ai/nanoid/releases/tag/5.1.6
https://nvd.nist.gov/vuln/detail/CVE-2026-67213
https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-zero-size-in-customalphabet-and-customrandom
|
| nanoid |
CVE-2026-67214 |
HIGH |
3.3.15 |
3.3.16, 5.1.16 |
https://github.com/ai/nanoid
https://github.com/ai/nanoid/commit/6ccc67bbaba71d3d77a21d9b636f4171a268ce49
https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d
https://github.com/ai/nanoid/pull/600
https://github.com/ai/nanoid/pull/601
https://github.com/ai/nanoid/releases/tag/5.1.16
https://nvd.nist.gov/vuln/detail/CVE-2026-67214
https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-negative-size-in-non-secure-module
|
| postcss |
CVE-2026-69153 |
MEDIUM |
8.5.18 |
8.5.23 |
https://access.redhat.com/security/cve/CVE-2026-69153
https://github.com/postcss/postcss
https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8
https://github.com/postcss/postcss/releases/tag/8.5.19
https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp
https://nvd.nist.gov/vuln/detail/CVE-2026-69153
https://www.cve.org/CVERecord?id=CVE-2026-69153
|
| undici |
CVE-2026-15157 |
MEDIUM |
6.27.0 |
6.28.0, 7.29.0, 8.9.0 |
https://access.redhat.com/security/cve/CVE-2026-15157
https://cna.openjsf.org/security-advisories.html
https://github.com/nodejs/undici
https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d
https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400
https://github.com/nodejs/undici/commit/7d3cf924c262c486bc77f951348f4e5c847b7b42
https://github.com/nodejs/undici/releases/tag/v6.28.0
https://github.com/nodejs/undici/releases/tag/v7.29.0
https://github.com/nodejs/undici/releases/tag/v8.9.0
https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5
https://nvd.nist.gov/vuln/detail/CVE-2026-15157
https://www.cve.org/CVERecord?id=CVE-2026-15157
|
| undici |
CVE-2026-16728 |
MEDIUM |
6.27.0 |
6.28.0, 7.29.0, 8.9.0 |
https://access.redhat.com/security/cve/CVE-2026-16728
https://cna.openjsf.org/security-advisories.html
https://github.com/nodejs/undici
https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c
https://github.com/nodejs/undici/commit/2b3f749336d356bbbc50192f87f6cf7bc714721a
https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7
https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420
https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e
https://github.com/nodejs/undici/commit/e11a68ed4ff345c79402476f7a00d473443e318d
https://github.com/nodejs/undici/releases/tag/v6.28.0
https://github.com/nodejs/undici/releases/tag/v7.29.0
https://github.com/nodejs/undici/releases/tag/v8.9.0
https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524
https://hackerone.com/reports/3828685
https://nvd.nist.gov/vuln/detail/CVE-2026-16728
https://www.cve.org/CVERecord?id=CVE-2026-16728
|
| undici |
CVE-2026-16729 |
MEDIUM |
6.27.0 |
6.28.0, 7.29.0, 8.9.0 |
https://access.redhat.com/security/cve/CVE-2026-16729
https://cna.openjsf.org/security-advisories.html
https://github.com/nodejs/undici
https://github.com/nodejs/undici/commit/10d93fc332f2c8c161982dec3833201de29891b5
https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef
https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235
https://github.com/nodejs/undici/releases/tag/v6.28.0
https://github.com/nodejs/undici/releases/tag/v7.29.0
https://github.com/nodejs/undici/releases/tag/v8.9.0
https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm
https://nvd.nist.gov/vuln/detail/CVE-2026-16729
https://www.cve.org/CVERecord?id=CVE-2026-16729
|
| undici |
CVE-2026-13697 |
HIGH |
7.28.0 |
7.29.0, 8.9.0 |
https://access.redhat.com/security/cve/CVE-2026-13697
https://cna.openjsf.org/security-advisories.html
https://github.com/nodejs/undici
https://github.com/nodejs/undici/commit/4fe5bc5fefe5ac81a200fc8e1cf84b8bf8464451
https://github.com/nodejs/undici/releases/tag/v7.29.0
https://github.com/nodejs/undici/releases/tag/v8.9.0
https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272
https://nvd.nist.gov/vuln/detail/CVE-2026-13697
https://www.cve.org/CVERecord?id=CVE-2026-13697
|
| undici |
CVE-2026-14643 |
MEDIUM |
7.28.0 |
7.29.0, 8.9.0 |
https://access.redhat.com/security/cve/CVE-2026-14643
https://cna.openjsf.org/security-advisories.html
https://github.com/nodejs/undici
https://github.com/nodejs/undici/commit/85a240551c9feb8b8a0ecc56c84b2b3015add8a9
https://github.com/nodejs/undici/commit/cb105d7c79069150982fa11acada0dd94a60dbbc
https://github.com/nodejs/undici/releases/tag/v7.29.0
https://github.com/nodejs/undici/releases/tag/v8.9.0
https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54
https://nvd.nist.gov/vuln/detail/CVE-2026-14643
https://www.cve.org/CVERecord?id=CVE-2026-14643
|
| undici |
CVE-2026-15157 |
MEDIUM |
7.28.0 |
6.28.0, 7.29.0, 8.9.0 |
https://access.redhat.com/security/cve/CVE-2026-15157
https://cna.openjsf.org/security-advisories.html
https://github.com/nodejs/undici
https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d
https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400
https://github.com/nodejs/undici/commit/7d3cf924c262c486bc77f951348f4e5c847b7b42
https://github.com/nodejs/undici/releases/tag/v6.28.0
https://github.com/nodejs/undici/releases/tag/v7.29.0
https://github.com/nodejs/undici/releases/tag/v8.9.0
https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5
https://nvd.nist.gov/vuln/detail/CVE-2026-15157
https://www.cve.org/CVERecord?id=CVE-2026-15157
|
| undici |
CVE-2026-16728 |
MEDIUM |
7.28.0 |
6.28.0, 7.29.0, 8.9.0 |
https://access.redhat.com/security/cve/CVE-2026-16728
https://cna.openjsf.org/security-advisories.html
https://github.com/nodejs/undici
https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c
https://github.com/nodejs/undici/commit/2b3f749336d356bbbc50192f87f6cf7bc714721a
https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7
https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420
https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e
https://github.com/nodejs/undici/commit/e11a68ed4ff345c79402476f7a00d473443e318d
https://github.com/nodejs/undici/releases/tag/v6.28.0
https://github.com/nodejs/undici/releases/tag/v7.29.0
https://github.com/nodejs/undici/releases/tag/v8.9.0
https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524
https://hackerone.com/reports/3828685
https://nvd.nist.gov/vuln/detail/CVE-2026-16728
https://www.cve.org/CVERecord?id=CVE-2026-16728
|
| undici |
CVE-2026-16729 |
MEDIUM |
7.28.0 |
6.28.0, 7.29.0, 8.9.0 |
https://access.redhat.com/security/cve/CVE-2026-16729
https://cna.openjsf.org/security-advisories.html
https://github.com/nodejs/undici
https://github.com/nodejs/undici/commit/10d93fc332f2c8c161982dec3833201de29891b5
https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef
https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235
https://github.com/nodejs/undici/releases/tag/v6.28.0
https://github.com/nodejs/undici/releases/tag/v7.29.0
https://github.com/nodejs/undici/releases/tag/v8.9.0
https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm
https://nvd.nist.gov/vuln/detail/CVE-2026-16729
https://www.cve.org/CVERecord?id=CVE-2026-16729
|
| No Misconfigurations found |
| No Vulnerabilities found |
| Dockerfile Security Check |
DS026 |
No HEALTHCHECK defined |
LOW |
Add HEALTHCHECK instruction in your Dockerfile
https://avd.aquasec.com/misconfig/ds026
|
| No Vulnerabilities found |
| No Misconfigurations found |
| No Vulnerabilities found |
| No Misconfigurations found |