| CVE-2026-13697 | HIGH | undici | 7.28.0 | 7.29.0, 8.9.0 | undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives |
| CVE-2026-18446 | HIGH | fast-uri | 3.1.4 | 2.4.4, 3.1.5, 4.1.2 | fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority |
| CVE-2026-58043 | HIGH | nodejs-22 | 22.23.1-r1 | 22.23.2-r0 | nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw |
| CVE-2026-67213 | HIGH | nanoid | 3.3.16 | 3.3.17, 5.1.6 | nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ... |
| CVE-2026-69152 | HIGH | brace-expansion | 5.0.8 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays |
| CVE-2026-69192 | HIGH | ip-address | 10.2.0 | 10.3.1 | ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass |
| GHSA-5p4m-2wfm-xmqj | HIGH | js-yaml | 4.3.0 | 4.3.1, 3.15.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported |
| CVE-2020-8203 | HIGH | lodash.pick | 4.4.0 | — not fixable | nodejs-lodash: prototype pollution in zipObjectDeep function |
| CVE-2022-37620 | HIGH | html-minifier | 4.0.0 | — not fixable | kangax html-minifier REDoS vulnerability |
| CVE-2025-71329 | HIGH | image-size | 1.2.1 | — not fixable | image-size: image-size: Denial of Service via crafted image buffer with zero-valued size field |
| CVE-2025-71330 | HIGH | image-size | 1.2.1 | — not fixable | image-size: image-size: Denial of Service via crafted ICNS image buffer |
| CVE-2026-14643 | MEDIUM | undici | 7.28.0 | 7.29.0, 8.9.0 | undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing |
| CVE-2026-15157 | MEDIUM | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property |
| CVE-2026-15157 | MEDIUM | undici | 7.28.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property |
| CVE-2026-16728 | MEDIUM | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length |
| CVE-2026-16728 | MEDIUM | undici | 7.28.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length |
| CVE-2026-16729 | MEDIUM | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections |
| CVE-2026-16729 | MEDIUM | undici | 7.28.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections |
| CVE-2026-54272 | MEDIUM | ip-address | 10.2.0 | 10.2.1 | ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification |
| CVE-2026-56850 | MEDIUM | nodejs-22 | 22.23.1-r1 | 22.23.2-r0 | nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw |
| CVE-2026-69198 | MEDIUM | ip-address | 10.2.0 | 10.2.2 | ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass |
| CVE-2026-71498 | MEDIUM | re2 | 1.25.2 | 1.26.1 | node-re2 provides RE2 regular expression bindings for Node.js. Prior t ... |
| GHSA-55q2-fjhq-7xh7 | MEDIUM | dompurify | 3.4.12 | 3.4.13 | DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS |
| GHSA-984p-xq9m-4rjw | MEDIUM | express-brute | 1.0.1 | — not fixable | Rate Limiting Bypass in express-brute |
| CVE-2026-56847 | LOW | nodejs-22 | 22.23.1-r1 | 22.23.2-r0 | A flaw in Node.js Permission Model enforcement allows `trace_events.cr ... |