| CVE-2026-13697 | HIGH | undici | 7.28.0 | 7.29.0, 8.9.0 | undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives |
| CVE-2026-14456 | HIGH | libcrypto3 | 3.6.3-r3 | 3.6.3-r5 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-14456 | HIGH | libssl3 | 3.6.3-r3 | 3.6.3-r5 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-18446 | HIGH | fast-uri | 3.1.4 | 2.4.4, 3.1.5, 4.1.2 | fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority |
| CVE-2026-58043 | HIGH | nodejs-22 | 22.23.1-r1 | 22.23.2-r0 | nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw |
| CVE-2026-67213 | HIGH | nanoid | 3.3.16 | 3.3.18, 5.1.6 | nanoid: nanoid: Denial of Service via infinite loop in random ID generation |
| CVE-2026-69152 | HIGH | brace-expansion | 5.0.8 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| CVE-2026-69192 | HIGH | ip-address | 10.2.0 | 10.3.1 | ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass |
| CVE-2026-75899 | HIGH | fast-uri | 3.1.4 | 2.4.5, 3.1.6, 4.1.3 | fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding |
| CVE-2026-75931 | HIGH | fast-uri | 3.1.4 | 2.4.5, 3.1.6, 4.1.3 | fast-uri: fast-uri: Host confusion via skipped IDN canonicalization |
| CVE-2026-75975 | HIGH | fast-uri | 3.1.4 | 2.4.5, 3.1.6, 4.1.3 | fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization |
| CVE-2026-76172 | HIGH | fast-uri | 3.1.4 | 2.4.5, 3.1.6, 4.1.3 | fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects |
| CVE-2026-77037 | HIGH | multer | 2.2.0 | 2.3.0 | multer vulnerable to Denial of Service via file descriptor leak on aborted uploads |
| CVE-2026-77078 | HIGH | multer | 2.2.0 | 2.3.0 | multer vulnerable to Denial of Service via crafted multipart field names |
| CVE-2026-82333 | HIGH | multer | 2.2.0 | 2.3.0 | multer vulnerable to Denial of Service via oversized array index in field names |
| CVE-2026-84375 | HIGH | js-yaml | 4.3.0 | 4.3.2, 3.15.2 | js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing |
| GHSA-2x7j-588g-ccc2 | HIGH | nodemailer | 9.0.1 | 9.1.0 | Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list |
| GHSA-5p4m-2wfm-xmqj | HIGH | js-yaml | 4.3.0 | 4.3.1, 3.15.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported |
| GHSA-rgj7-g3m4-5g8c | HIGH | sharp | 0.35.3 | 0.35.4 | sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545 |
| CVE-2020-8203 | HIGH | lodash.pick | 4.4.0 | — غير قابلة للإصلاح | nodejs-lodash: prototype pollution in zipObjectDeep function |
| CVE-2022-37620 | HIGH | html-minifier | 4.0.0 | — غير قابلة للإصلاح | kangax html-minifier REDoS vulnerability |
| CVE-2025-71329 | HIGH | image-size | 1.2.1 | — غير قابلة للإصلاح | image-size: image-size: Denial of Service via crafted image buffer with zero-valued size field |
| CVE-2025-71330 | HIGH | image-size | 1.2.1 | — غير قابلة للإصلاح | image-size: image-size: Denial of Service via crafted ICNS image buffer |
| CVE-2026-19693 | HIGH | extract-zip | 2.0.1 | — غير قابلة للإصلاح | extract-zip: extract-zip: Arbitrary file write via symlink in archive |
| CVE-2026-56876 | HIGH | extract-zip | 2.0.1 | — غير قابلة للإصلاح | extract-zip: github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass |
| CVE-2026-14643 | MEDIUM | undici | 7.28.0 | 7.29.0, 8.9.0 | undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing |
| CVE-2026-15157 | MEDIUM | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property |
| CVE-2026-15157 | MEDIUM | undici | 7.28.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property |
| CVE-2026-16728 | MEDIUM | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length |
| CVE-2026-16728 | MEDIUM | undici | 7.28.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length |
| CVE-2026-16729 | MEDIUM | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections |
| CVE-2026-16729 | MEDIUM | undici | 7.28.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections |
| CVE-2026-54272 | MEDIUM | ip-address | 10.2.0 | 10.2.1 | ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification |
| CVE-2026-56847 | MEDIUM | nodejs-22 | 22.23.1-r1 | 22.23.2-r0 | nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions |
| CVE-2026-56850 | MEDIUM | nodejs-22 | 22.23.1-r1 | 22.23.2-r0 | nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw |
| CVE-2026-58055 | MEDIUM | libnghttp2-14 | 1.69.0-r0 | 1.70.0-r0 | nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests |
| CVE-2026-63670 | MEDIUM | sanitize-html | 2.17.5 | 2.17.6 | ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close |
| CVE-2026-67550 | MEDIUM | re2 | 1.25.0 | 1.25.2 | re2: Denial of Service via out-of-bounds read |
| CVE-2026-68499 | MEDIUM | re2 | 1.25.0 | 1.25.2 | re2 provides Node.js bindings for Google's RE2 regular expression engi ... |
| CVE-2026-69198 | MEDIUM | ip-address | 10.2.0 | 10.2.2 | ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass |
| CVE-2026-70588 | MEDIUM | ghost | 6.54.0 | 6.54.1 | Ghost: Cross-Site Scripting in Universal Import |
| CVE-2026-70589 | MEDIUM | ghost | 6.54.0 | 6.54.1 | Ghost: Archived Offers can be Redeemed |
| CVE-2026-70590 | MEDIUM | ghost | 6.54.0 | 6.54.1 | Ghost: Blind Password Hash Disclosure in Ghost Admin API |
| CVE-2026-70591 | MEDIUM | ghost | 6.54.0 | 6.54.1 | Ghost: Server-Side Request Forgery in Image Fetching |
| CVE-2026-70592 | MEDIUM | ghost | 6.54.0 | 6.54.1 | Ghost: Database Backup Path Traversal |
| CVE-2026-70593 | MEDIUM | ghost | 6.54.0 | 6.54.1 | Ghost: Theme Upload Path Traversal |
| CVE-2026-70594 | MEDIUM | ghost | 6.54.0 | 6.54.1 | Ghost: Session Fixation in Ghost Admin |
| CVE-2026-70595 | MEDIUM | ghost | 6.54.0 | 6.54.1 | Ghost: Server-Side Request Forgery Mitigation Issue |
| CVE-2026-70596 | MEDIUM | ghost | 6.54.0 | 6.54.1 | Ghost: Cross-Site Scripting in Feature Image Captions |
| CVE-2026-71430 | MEDIUM | re2 | 1.25.0 | 1.25.1 | node-re2: node-re2: Denial of Service due to excessive string length in replacements |
| CVE-2026-71498 | MEDIUM | re2 | 1.25.0 | 1.26.1 | node-re2: node-re2: Information disclosure via out-of-bounds read with malformed UTF-8 input |
| CVE-2026-82417 | MEDIUM | qs | 6.15.3 | 6.16.0 | qs: qs: Denial of Service via improper validation in stringify function |
| CVE-2026-82562 | MEDIUM | qs | 6.15.3 | 6.16.0 | qs: qs: Denial of Service via array limit bypass in query string parsing |
| CVE-2026-84371 | MEDIUM | sanitize-html | 2.17.5 | 2.17.7 | sanitize-html: stored XSS via SVG SMIL URI-list scheme-policy bypass |
| CVE-2026-85091 | MEDIUM | zlib | 1.3.2-r3 | 1.3.3-r0 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... |
| GHSA-55q2-fjhq-7xh7 | MEDIUM | dompurify | 3.4.12 | 3.4.13 | DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS |
| GHSA-8m3c-c648-2xjj | MEDIUM | nodemailer | 9.0.1 | 9.1.1 | Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature |
| GHSA-cc9r-2j5m-2m83 | MEDIUM | nodemailer | 9.0.1 | 9.1.0 | Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain |
| GHSA-rgwj-5xj2-c3m3 | MEDIUM | mysql2 | 3.22.5 | 3.23.1 | MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS |
| GHSA-wmmp-3585-3rmp | MEDIUM | nodemailer | 9.0.1 | 9.1.0 | Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain |
| GHSA-984p-xq9m-4rjw | MEDIUM | express-brute | 1.0.1 | — غير قابلة للإصلاح | Rate Limiting Bypass in express-brute |
| CVE-2026-54876 | LOW | libcrypto3 | 3.6.3-r3 | 3.6.3-r4 | openssl: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking |
| CVE-2026-54876 | LOW | libssl3 | 3.6.3-r3 | 3.6.3-r4 | openssl: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking |
| CVE-2026-77063 | LOW | multer | 2.2.0 | 2.3.0 | multer vulnerable to file size limit bypass via async fileFilter race condition |