| CVE-2026-75899 | HIGH | fast-uri | 3.1.5 | 2.4.5, 3.1.6, 4.1.3 | fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding |
| CVE-2026-75931 | HIGH | fast-uri | 3.1.5 | 2.4.5, 3.1.6, 4.1.3 | fast-uri: fast-uri: Host confusion via skipped IDN canonicalization |
| CVE-2026-75975 | HIGH | fast-uri | 3.1.5 | 2.4.5, 3.1.6, 4.1.3 | fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization |
| CVE-2026-76172 | HIGH | fast-uri | 3.1.5 | 2.4.5, 3.1.6, 4.1.3 | fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects |
| CVE-2026-77037 | HIGH | multer | 2.2.0 | 2.3.0 | multer vulnerable to Denial of Service via file descriptor leak on aborted uploads |
| CVE-2026-77078 | HIGH | multer | 2.2.0 | 2.3.0 | multer vulnerable to Denial of Service via crafted multipart field names |
| CVE-2026-82333 | HIGH | multer | 2.2.0 | 2.3.0 | multer vulnerable to Denial of Service via oversized array index in field names |
| CVE-2026-84375 | HIGH | js-yaml | 4.3.1 | 4.3.2, 3.15.2 | js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing |
| GHSA-2x7j-588g-ccc2 | HIGH | nodemailer | 9.0.1 | 9.1.0 | Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list |
| GHSA-rgj7-g3m4-5g8c | HIGH | sharp | 0.35.3 | 0.35.4 | sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545 |
| CVE-2020-8203 | HIGH | lodash.pick | 4.4.0 | — not fixable | nodejs-lodash: prototype pollution in zipObjectDeep function |
| CVE-2022-37620 | HIGH | html-minifier | 4.0.0 | — not fixable | kangax html-minifier REDoS vulnerability |
| CVE-2025-71329 | HIGH | image-size | 1.2.1 | — not fixable | image-size: image-size: Denial of Service via crafted image buffer with zero-valued size field |
| CVE-2025-71330 | HIGH | image-size | 1.2.1 | — not fixable | image-size: image-size: Denial of Service via crafted ICNS image buffer |
| CVE-2026-19693 | HIGH | extract-zip | 2.0.1 | — not fixable | extract-zip: extract-zip: Arbitrary file write via symlink in archive |
| CVE-2026-56876 | HIGH | extract-zip | 2.0.1 | — not fixable | extract-zip: github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass |
| CVE-2026-18374 | MEDIUM | glibc-2.44 | 2.44-r1 | 2.44-r6 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string |
| CVE-2026-18374 | MEDIUM | glibc-2.44-locale-posix | 2.44-r1 | 2.44-r6 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string |
| CVE-2026-18374 | MEDIUM | ld-linux-2.44 | 2.44-r1 | 2.44-r6 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string |
| CVE-2026-63670 | MEDIUM | sanitize-html | 2.17.5 | 2.17.6 | ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close |
| CVE-2026-82417 | MEDIUM | qs | 6.15.3 | 6.16.0 | qs: qs: Denial of Service via improper validation in stringify function |
| CVE-2026-82562 | MEDIUM | qs | 6.15.3 | 6.16.0 | qs: qs: Denial of Service via array limit bypass in query string parsing |
| CVE-2026-84371 | MEDIUM | sanitize-html | 2.17.5 | 2.17.7 | sanitize-html: stored XSS via SVG SMIL URI-list scheme-policy bypass |
| CVE-2026-85091 | MEDIUM | zlib | 1.3.2-r4 | 1.3.3-r0 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... |
| GHSA-8m3c-c648-2xjj | MEDIUM | nodemailer | 9.0.1 | 9.1.1 | Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature |
| GHSA-cc9r-2j5m-2m83 | MEDIUM | nodemailer | 9.0.1 | 9.1.0 | Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain |
| GHSA-rgwj-5xj2-c3m3 | MEDIUM | mysql2 | 3.22.5 | 3.23.1 | MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS |
| GHSA-wmmp-3585-3rmp | MEDIUM | nodemailer | 9.0.1 | 9.1.0 | Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain |
| GHSA-984p-xq9m-4rjw | MEDIUM | express-brute | 1.0.1 | — not fixable | Rate Limiting Bypass in express-brute |
| CVE-2026-77063 | LOW | multer | 2.2.0 | 2.3.0 | multer vulnerable to file size limit bypass via async fileFilter race condition |