| CVE-2026-63376 | HIGH | toml | 3.0.0 | 4.1.2 | toml-node: toml-node: Arbitrary Code Execution via Prototype Pollution in TOML Parsing |
| CVE-2026-77037 | HIGH | multer | 2.2.0 | 2.3.0 | multer vulnerable to Denial of Service via file descriptor leak on aborted uploads |
| CVE-2026-77078 | HIGH | multer | 2.2.0 | 2.3.0 | multer vulnerable to Denial of Service via crafted multipart field names |
| CVE-2026-77465 | HIGH | toml | 3.0.0 | 4.2.0 | toml-node: toml-node: Denial of Service via uncontrolled recursion in TOML parsing |
| CVE-2026-82333 | HIGH | multer | 2.2.0 | 2.3.0 | multer vulnerable to Denial of Service via oversized array index in field names |
| CVE-2026-84375 | HIGH | js-yaml | 4.3.1 | 4.3.2, 3.15.2 | js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing |
| CVE-2026-86075 | HIGH | n8n | 2.32.7 | 2.38.2, 2.37.7 | n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint |
| CVE-2026-86076 | HIGH | n8n | 2.32.7 | 1.123.76, 2.38.2, 2.37.7 | n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution |
| CVE-2026-86081 | HIGH | n8n | 2.32.7 | 1.123.76, 2.38.2, 2.37.7 | n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path |
| CVE-2026-86082 | HIGH | n8n | 2.32.7 | 1.123.76, 2.38.2, 2.37.7 | n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node |
| CVE-2026-86083 | HIGH | n8n | 2.32.7 | 1.123.76, 2.38.2, 2.37.7 | n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution |
| GHSA-2x7j-588g-ccc2 | HIGH | nodemailer | 9.0.1 | 9.1.0 | Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list |
| GHSA-3f6p-5ww8-9rcr | HIGH | mysql2 | 3.17.0 | 3.22.0 | MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials |
| CVE-2026-18374 | MEDIUM | glibc-2.44 | 2.44-r1 | 2.44-r6 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string |
| CVE-2026-18374 | MEDIUM | glibc-2.44-locale-posix | 2.44-r1 | 2.44-r6 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string |
| CVE-2026-18374 | MEDIUM | ld-linux-2.44 | 2.44-r1 | 2.44-r6 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string |
| CVE-2026-63670 | MEDIUM | sanitize-html | 2.17.5 | 2.17.6 | ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close |
| CVE-2026-71429 | MEDIUM | stream-json | 1.9.1 | 3.5.0 | stream-json: stream-json: Denial of Service due to inefficient processing of deeply nested JSON |
| CVE-2026-82417 | MEDIUM | qs | 6.15.2 | 6.16.0 | qs: qs: Denial of Service via improper validation in stringify function |
| CVE-2026-82562 | MEDIUM | qs | 6.15.2 | 6.16.0 | qs: qs: Denial of Service via array limit bypass in query string parsing |
| CVE-2026-84371 | MEDIUM | sanitize-html | 2.17.5 | 2.17.7 | sanitize-html: stored XSS via SVG SMIL URI-list scheme-policy bypass |
| CVE-2026-85063 | MEDIUM | csv-parse | 6.2.1 | 7.0.2 | csv-parse: node-csv: Prototype pollution via malicious CSV header |
| CVE-2026-85091 | MEDIUM | zlib | 1.3.2-r4 | 1.3.3-r0 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... |
| CVE-2026-86073 | MEDIUM | n8n | 2.32.7 | 2.38.1, 2.37.7 | n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution |
| CVE-2026-86074 | MEDIUM | n8n | 2.32.7 | 2.38.2, 2.37.7 | n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content |
| CVE-2026-86077 | MEDIUM | n8n | 2.32.7 | 2.38.2, 2.37.7 | n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket |
| CVE-2026-86078 | MEDIUM | n8n | 2.32.7 | 2.38.2, 2.37.7 | n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service |
| CVE-2026-86079 | MEDIUM | n8n | 2.32.7 | 1.123.76, 2.38.2, 2.37.7 | n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers |
| CVE-2026-86080 | MEDIUM | n8n | 2.32.7 | 1.123.76, 2.38.2, 2.37.7 | n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open |
| CVE-2026-86084 | MEDIUM | n8n | 2.32.7 | 1.123.76, 2.38.2, 2.37.7 | n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions |
| CVE-2026-86085 | MEDIUM | n8n | 2.32.7 | 2.38.2, 2.37.7 | n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints |
| CVE-2026-86993 | MEDIUM | n8n | 2.32.7 | 1.123.76, 2.38.2, 2.37.7 | n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check |
| CVE-2026-86994 | MEDIUM | n8n | 2.32.7 | 1.123.76, 2.38.2, 2.37.7 | n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter |
| CVE-2026-86995 | MEDIUM | n8n | 2.32.7 | 1.123.76, 2.38.2, 2.37.7 | n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read |
| CVE-2026-86996 | MEDIUM | n8n | 2.32.7 | 2.38.2, 2.37.7 | n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy |
| GHSA-8m3c-c648-2xjj | MEDIUM | nodemailer | 9.0.1 | 9.1.1 | Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature |
| GHSA-cc9r-2j5m-2m83 | MEDIUM | nodemailer | 9.0.1 | 9.1.0 | Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain |
| GHSA-rgwj-5xj2-c3m3 | MEDIUM | mysql2 | 3.17.0 | 3.23.1 | MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS |
| GHSA-wmmp-3585-3rmp | MEDIUM | nodemailer | 9.0.1 | 9.1.0 | Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain |
| CVE-2024-1899 | MEDIUM | showdown | 2.1.0 | — sin corrección | Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing |
| CVE-2026-59710 | MEDIUM | showdown | 2.1.0 | — sin corrección | showdown: Showdown: Stored Cross-Site Scripting via unescaped table header ID attributes in markdown |
| CVE-2026-59711 | MEDIUM | showdown | 2.1.0 | — sin corrección | showdown: Showdown: Cross-site scripting via unescaped metadata title allows arbitrary code execution |
| CVE-2026-76845 | MEDIUM | adm-zip | 0.6.0 | — sin corrección | adm-zip: adm-zip: Arbitrary File Overwrite via Symlink Following |
| CVE-2026-77063 | LOW | multer | 2.2.0 | 2.3.0 | multer vulnerable to file size limit bypass via async fileFilter race condition |