| CVE-2026-13697 | HIGH | undici | 7.28.0 | 7.29.0, 8.9.0 | undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives |
| CVE-2026-18446 | HIGH | fast-uri | 3.1.4 | 2.4.4, 3.1.5, 4.1.2 | fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority |
| CVE-2026-58043 | HIGH | nodejs-22 | 22.23.1-r1 | 22.23.2-r0 | nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw |
| CVE-2026-67213 | HIGH | nanoid | 3.3.16 | 3.3.18, 5.1.6 | nanoid: nanoid: Denial of Service via infinite loop in random ID generation |
| CVE-2026-69152 | HIGH | brace-expansion | 5.0.8 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| CVE-2026-69192 | HIGH | ip-address | 10.2.0 | 10.3.1 | ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass |
| GHSA-5p4m-2wfm-xmqj | HIGH | js-yaml | 4.3.0 | 4.3.1, 3.15.1 | JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported |
| CVE-2020-8203 | HIGH | lodash.pick | 4.4.0 | — not fixable | nodejs-lodash: prototype pollution in zipObjectDeep function |
| CVE-2022-37620 | HIGH | html-minifier | 4.0.0 | — not fixable | kangax html-minifier REDoS vulnerability |
| CVE-2025-71329 | HIGH | image-size | 1.2.1 | — not fixable | image-size: image-size: Denial of Service via crafted image buffer with zero-valued size field |
| CVE-2025-71330 | HIGH | image-size | 1.2.1 | — not fixable | image-size: image-size: Denial of Service via crafted ICNS image buffer |
| CVE-2026-56876 | HIGH | extract-zip | 2.0.1 | — not fixable | extract-zip: github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass |
| CVE-2026-14643 | MEDIUM | undici | 7.28.0 | 7.29.0, 8.9.0 | undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing |
| CVE-2026-15157 | MEDIUM | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property |
| CVE-2026-15157 | MEDIUM | undici | 7.28.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property |
| CVE-2026-16728 | MEDIUM | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length |
| CVE-2026-16728 | MEDIUM | undici | 7.28.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length |
| CVE-2026-16729 | MEDIUM | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections |
| CVE-2026-16729 | MEDIUM | undici | 7.28.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections |
| CVE-2026-54272 | MEDIUM | ip-address | 10.2.0 | 10.2.1 | ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification |
| CVE-2026-56850 | MEDIUM | nodejs-22 | 22.23.1-r1 | 22.23.2-r0 | nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw |
| CVE-2026-69198 | MEDIUM | ip-address | 10.2.0 | 10.2.2 | ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass |
| CVE-2026-71498 | MEDIUM | re2 | 1.25.2 | 1.26.1 | re2: node-re2: Information disclosure via out-of-bounds read with malformed UTF-8 input |
| GHSA-55q2-fjhq-7xh7 | MEDIUM | dompurify | 3.4.12 | 3.4.13 | DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS |
| GHSA-984p-xq9m-4rjw | MEDIUM | express-brute | 1.0.1 | — not fixable | Rate Limiting Bypass in express-brute |
| CVE-2026-56847 | LOW | nodejs-22 | 22.23.1-r1 | 22.23.2-r0 | nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions |