| CVE-2026-59873 | CRITICAL | tar | 6.2.1 | 7.5.19 | tar: node-tar: Denial of Service via crafted gzip bomb |
| CVE-2026-59873 | CRITICAL | tar | 7.5.16 | 7.5.19 | tar: node-tar: Denial of Service via crafted gzip bomb |
| CVE-2025-64756 | HIGH | glob | 10.4.5 | 11.1.0, 10.5.0 | glob: glob: Command Injection Vulnerability via Malicious Filenames |
| CVE-2025-69262 | HIGH | pnpm | 9.15.9 | 10.27.0 | pnpm: pnpm: Remote code execution via command injection in tokenHelper environment variable substitution |
| CVE-2025-69263 | HIGH | pnpm | 9.15.9 | 10.26.0 | pnpm: pnpm Lockfile Integrity Bypass |
| CVE-2026-13149 | HIGH | brace-expansion | 2.0.1 | 5.0.7, 1.1.16, 2.1.2 | brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity |
| CVE-2026-13149 | HIGH | brace-expansion | 5.0.6 | 5.0.7, 1.1.16, 2.1.2 | brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity |
| CVE-2026-14257 | HIGH | npm | 11.17.0-r2 | 12.0.1-r2 | brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function |
| CVE-2026-14257 | HIGH | brace-expansion | 2.0.1 | 5.0.8, 3.0.3, 2.1.3, 1.1.17 | brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function |
| CVE-2026-14257 | HIGH | brace-expansion | 5.0.6 | 5.0.8, 3.0.3, 2.1.3, 1.1.17 | brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function |
| CVE-2026-14456 | HIGH | libcrypto3 | 3.6.3-r3 | 3.6.3-r5 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-14456 | HIGH | libssl3 | 3.6.3-r3 | 3.6.3-r5 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server |
| CVE-2026-23745 | HIGH | tar | 6.2.1 | 7.5.3 | node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives |
| CVE-2026-23950 | HIGH | tar | 6.2.1 | 7.5.4 | node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition |
| CVE-2026-24842 | HIGH | tar | 6.2.1 | 7.5.7 | node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check |
| CVE-2026-26960 | HIGH | tar | 6.2.1 | 7.5.8 | node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation |
| CVE-2026-26996 | HIGH | minimatch | 9.0.5 | 10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3 | minimatch: minimatch: Denial of Service via specially crafted glob patterns |
| CVE-2026-27903 | HIGH | minimatch | 9.0.5 | 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3 | minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns |
| CVE-2026-27904 | HIGH | minimatch | 9.0.5 | 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4 | minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions |
| CVE-2026-29786 | HIGH | tar | 6.2.1 | 7.5.10 | node-tar: hardlink path traversal via drive-relative linkpath |
| CVE-2026-31802 | HIGH | tar | 6.2.1 | 7.5.11 | tar: tar: File overwrite via drive-relative symlink traversal |
| CVE-2026-50015 | HIGH | pnpm | 9.15.9 | 10.34.0, 11.4.0 | pnpm: pnpm: Arbitrary file write/delete due to lack of path validation in patch files |
| CVE-2026-50016 | HIGH | pnpm | 9.15.9 | 10.34.0, 11.4.0 | pnpm: pnpm: Arbitrary code execution due to path traversal in dependency aliases |
| CVE-2026-55487 | HIGH | pnpm | 9.15.9 | 10.34.2, 11.5.3 | pnpm: pnpm: Supply chain compromise via manipulated package source strings |
| CVE-2026-55697 | HIGH | pnpm | 9.15.9 | 10.34.2, 11.5.3 | pnpm: pnpm: Arbitrary code execution via improper handling of config dependencies |
| CVE-2026-55698 | HIGH | pnpm | 9.15.9 | 10.34.2, 11.5.3 | pnpm: pnpm: Arbitrary code execution via malicious package-manager lockfile |
| CVE-2026-58043 | HIGH | nodejs-22 | 22.23.1-r0 | 22.23.2-r0 | nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw |
| CVE-2026-59871 | HIGH | npm | 11.17.0-r2 | 12.0.0-r1 | node-tar: node-tar: Denial of Service due to incorrect PAX path handling |
| CVE-2026-59873 | HIGH | npm | 11.17.0-r2 | 12.0.0-r1 | tar: node-tar: Denial of Service via crafted gzip bomb |
| CVE-2026-59874 | HIGH | npm | 11.17.0-r2 | 12.0.0-r1 | tar: Node-tar: Denial of Service via malformed tar archive header |
| CVE-2026-59874 | HIGH | tar | 6.2.1 | 7.5.18 | tar: Node-tar: Denial of Service via malformed tar archive header |
| CVE-2026-59874 | HIGH | tar | 7.5.16 | 7.5.18 | tar: Node-tar: Denial of Service via malformed tar archive header |
| CVE-2026-69152 | HIGH | brace-expansion | 2.0.1 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| CVE-2026-69152 | HIGH | brace-expansion | 5.0.6 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| CVE-2026-69192 | HIGH | ip-address | 10.2.0 | 10.3.1 | ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass |
| CVE-2026-69192 | HIGH | ip-address | 9.0.5 | 10.3.1 | ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass |
| CVE-2026-73566 | HIGH | node-gyp | 13.0.0-r1 | 13.0.1-r1 | tar: node-tar: Denial of Service via crafted long-path tar archive |
| CVE-2026-73566 | HIGH | npm | 11.17.0-r2 | 12.0.1-r2 | tar: node-tar: Denial of Service via crafted long-path tar archive |
| CVE-2026-73566 | HIGH | tar | 6.2.1 | 7.5.21 | tar: node-tar: Denial of Service via crafted long-path tar archive |
| CVE-2026-73566 | HIGH | tar | 7.5.16 | 7.5.21 | tar: node-tar: Denial of Service via crafted long-path tar archive |
| CVE-2026-82392 | HIGH | pnpm | 9.15.9 | 10.34.5, 11.11.0 | pnpm: pnpm: Arbitrary Code Execution via Path Traversal |
| CVE-2026-82393 | HIGH | pnpm | 9.15.9 | 10.34.5, 11.11.0 | pnpm: pnpm: Arbitrary file write and code execution via path traversal in tarball dependency manifest |
| GHSA-72r4-9c5j-mj57 | HIGH | pnpm | 9.15.9 | 10.34.4, 11.7.0 | pnpm: `patch-remove` could delete project-selected files outside the patches directory |
| GHSA-fr4h-3cph-29xv | HIGH | pnpm | 9.15.9 | 10.34.4, 11.7.0 | pnpm: Hoisted install imports lockfile alias outside node_modules |
| GHSA-qrv3-253h-g69c | HIGH | pnpm | 9.15.9 | 10.34.4, 11.8.0 | pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config |
| CVE-2024-47829 | MEDIUM | pnpm | 9.15.9 | 10.0.0 | pnpm: pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting |
| CVE-2026-15157 | MEDIUM | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property |
| CVE-2026-16728 | MEDIUM | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length |
| CVE-2026-16729 | MEDIUM | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections |
| CVE-2026-23888 | MEDIUM | pnpm | 9.15.9 | 10.28.1 | pnpm: pnpm: Arbitrary file write via path traversal in binary fetcher leading to remote code execution |
| CVE-2026-23889 | MEDIUM | pnpm | 9.15.9 | 10.28.1 | pnpm: pnpm: Arbitrary file write via path traversal on Windows |
| CVE-2026-23890 | MEDIUM | pnpm | 9.15.9 | 10.28.1 | pnpm: pnpm: Arbitrary code execution via path traversal in bin linking |
| CVE-2026-24056 | MEDIUM | pnpm | 9.15.9 | 10.28.2 | pnpm: pnpm symlink traversal in file:/git dependencies |
| CVE-2026-24131 | MEDIUM | pnpm | 9.15.9 | 10.28.2 | pnpm: pnpm: Arbitrary file permission modification via directory traversal |
| CVE-2026-33750 | MEDIUM | brace-expansion | 2.0.1 | 5.0.5, 3.0.2, 2.0.3, 1.1.13 | brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern |
| CVE-2026-42338 | MEDIUM | ip-address | 9.0.5 | 10.1.1 | ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input |
| CVE-2026-48995 | MEDIUM | pnpm | 9.15.9 | 10.33.4, 11.0.7 | pnpm: pnpm: Supply chain compromise from unverified dependencies |
| CVE-2026-50014 | MEDIUM | pnpm | 9.15.9 | 10.34.0, 11.4.0 | pnpm: pnpm: Arbitrary Code Execution via Malicious Lockfile |
| CVE-2026-50017 | MEDIUM | pnpm | 9.15.9 | 10.34.0, 11.4.0 | pnpm: pnpm: Information disclosure of authentication credentials via malicious .npmrc file |
| CVE-2026-50021 | MEDIUM | pnpm | 9.15.9 | 11.4.0, 10.34.1 | pnpm: pnpm: Integrity bypass allows installation of altered packages via modified lockfile |
| CVE-2026-50573 | MEDIUM | pnpm | 9.15.9 | 10.34.0, 11.4.0 | pnpm: pnpm: Package integrity check bypass allows installation of malicious content |
| CVE-2026-53655 | MEDIUM | tar | 6.2.1 | 7.5.16 | node-tar: node-tar: File smuggling due to inconsistent tar archive parsing |
| CVE-2026-54272 | MEDIUM | ip-address | 10.2.0 | 10.2.1 | ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification |
| CVE-2026-55180 | MEDIUM | pnpm | 9.15.9 | 10.34.2, 11.5.3 | pnpm: pacquet: pnpm and pacquet: Information disclosure of environment secrets via improper environment variable expansion |
| CVE-2026-55699 | MEDIUM | pnpm | 9.15.9 | 10.34.2, 11.5.3 | pnpm: pnpm: Denial of Service due to improper handling of malicious package manifest bin keys |
| CVE-2026-56847 | MEDIUM | nodejs-22 | 22.23.1-r0 | 22.23.2-r0 | nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions |
| CVE-2026-56850 | MEDIUM | nodejs-22 | 22.23.1-r0 | 22.23.2-r0 | nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw |
| CVE-2026-58055 | MEDIUM | libnghttp2-14 | 1.69.0-r0 | 1.70.0-r0 | nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests |
| CVE-2026-59871 | MEDIUM | tar | 6.2.1 | 7.5.18 | node-tar: node-tar: Denial of Service due to incorrect PAX path handling |
| CVE-2026-59871 | MEDIUM | tar | 7.5.16 | 7.5.18 | node-tar: node-tar: Denial of Service due to incorrect PAX path handling |
| CVE-2026-59875 | MEDIUM | npm | 11.17.0-r2 | 12.0.0-r1 | node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata |
| CVE-2026-59875 | MEDIUM | tar | 6.2.1 | 7.5.17 | node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata |
| CVE-2026-59875 | MEDIUM | tar | 7.5.16 | 7.5.17 | node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata |
| CVE-2026-6791 | MEDIUM | glibc | 2.43-r9 | 2.43-r10 | glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion |
| CVE-2026-6791 | MEDIUM | glibc-locale-posix | 2.43-r9 | 2.43-r10 | glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion |
| CVE-2026-6791 | MEDIUM | ld-linux | 2.43-r9 | 2.43-r10 | glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion |
| CVE-2026-69198 | MEDIUM | ip-address | 10.2.0 | 10.2.2 | ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass |
| CVE-2026-85091 | MEDIUM | zlib | 1.3.2-r3 | 1.3.3-r0 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... |
| CVE-2025-5889 | LOW | brace-expansion | 2.0.1 | 2.0.2, 1.1.12, 3.0.1, 4.0.1 | brace-expansion: juliangruber brace-expansion index.js expand redos |
| CVE-2026-54876 | LOW | libcrypto3 | 3.6.3-r3 | 3.6.3-r4 | openssl: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking |
| CVE-2026-54876 | LOW | libssl3 | 3.6.3-r3 | 3.6.3-r4 | openssl: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking |