| 24 |
Medium |
- |
GHSA-7gcf-g7xr-8hxj |
serde_with |
Rust |
KeyValueMap serialisation triggers panic on empty sequence or empty Map entry |
< 3.21.0 |
3.21.0 |
2026-08-24 |
2026-08-24 |
#24 |
| 23 |
Medium |
CVE-2026-42184 |
GHSA-7gmj-67g7-phm9 |
tauri |
Rust |
Origin confusion vulnerability allowing remote pages to invoke local-only IPC commands |
>= 2.0.0, <= 2.11.0 |
2.11.1 |
2026-08-24 |
2026-08-24 |
#23 |
| 22 |
Low |
- |
GHSA-cq8v-f236-94qc |
rand |
Rust |
Unsoundness issue when using a custom logger with rand::rng() |
>= 0.7.0, < 0.8.6 |
0.8.6 |
2026-08-24 |
2026-08-24 |
#22 |
| 20 |
Medium |
CVE-2020-35910 |
GHSA-ppj3-7jw3-8vc4 |
lock_api |
Rust |
Data race in lock_api |
< 0.4.2 |
0.4.2 |
2026-08-24 |
2026-08-24 |
#20 |
| 19 |
Medium |
CVE-2020-35914 |
GHSA-gmv4-vmx3-x9f3 |
lock_api |
Rust |
Data race in lock_api |
< 0.4.2 |
0.4.2 |
2026-08-24 |
2026-08-24 |
#19 |
| 18 |
Medium |
CVE-2020-35911 |
GHSA-vh4p-6j7g-f4j9 |
lock_api |
Rust |
Data race in lock_api |
< 0.4.2 |
0.4.2 |
2026-08-24 |
2026-08-24 |
#18 |
| 17 |
Medium |
CVE-2020-35912 |
GHSA-5wg8-7c9q-794v |
lock_api |
Rust |
Data race in lock_api |
< 0.4.2 |
0.4.2 |
2026-08-24 |
2026-08-24 |
#17 |
| 16 |
Medium |
CVE-2020-35913 |
GHSA-hj9h-wrgg-hgmx |
lock_api |
Rust |
Data race in lock_api |
< 0.4.2 |
0.4.2 |
2026-08-24 |
2026-08-24 |
#16 |
| 15 |
High |
CVE-2026-67213 |
GHSA-2v37-7h3g-55p8 |
nanoid |
npm |
Custom generator may loop infinitely when size is zero |
< 3.3.18 |
3.3.18 |
2026-08-17 |
2026-08-24 |
#15 |
| 14 |
High |
CVE-2026-67214 |
GHSA-28wg-ghj8-5hjv |
nanoid |
npm |
Non-secure generator may loop infinitely when size is negative |
< 3.3.16 |
3.3.16 |
2026-08-11 |
2026-08-24 |
#14 |
| 12 |
Medium |
CVE-2026-69153 |
GHSA-fxqj-rqcc-2cmp |
postcss |
npm |
Incomplete fix for GHSA-6g55-p6wh-862q: attacker-controlled sourceMappingURL can read arbitrary .map files when from is not set |
<= 8.5.22 |
8.5.23 |
2026-08-05 |
2026-08-24 |
#12 |
| 11 |
High |
CVE-2026-73566 |
GHSA-r292-9mhp-454m |
tar |
npm |
mapHas/filesFilter lacks recursion limit; crafted tar with long path and member selection can cause uncaught stack overflow DoS |
<= 7.5.20 |
7.5.21 |
2026-08-05 |
2026-08-24 |
#11 |
| 10 |
High |
CVE-2026-73646 |
GHSA-r28c-9q8g-f849 |
postcss |
npm |
Path traversal in Source Map auto-loading (sourceMappingURL) leading to arbitrary .map file disclosure |
<= 8.5.17 |
8.5.18 |
2026-08-05 |
2026-08-24 |
#10 |
| 9 |
Medium |
CVE-2026-59871 |
GHSA-w8wr-v893-vjvp |
tar |
npm |
PAX numeric path type confusion causes process crash |
<= 7.5.17 |
7.5.18 |
2026-08-05 |
2026-08-24 |
#9 |
| 8 |
Critical |
CVE-2026-59873 |
GHSA-23hp-3jrh-7fpw |
tar |
npm |
Unrestricted input leads to decompression/parsing DoS |
<= 7.5.18 |
7.5.19 |
2026-08-05 |
2026-08-24 |
#8 |
| 7 |
High |
CVE-2026-59874 |
GHSA-8x88-c5mf-7j5w |
tar |
npm |
Negative tar entry size causes infinite loop during archive replacement |
<= 7.5.17 |
7.5.18 |
2026-08-05 |
2026-08-24 |
#7 |
| 6 |
Medium |
CVE-2026-59875 |
GHSA-gvwx-54wh-qm9j |
tar |
npm |
NUL byte in PAX path/linkpath record causes uncaught exception DoS |
<= 7.5.16 |
7.5.17 |
2026-08-05 |
2026-08-24 |
#6 |
| 5 |
Medium |
CVE-2026-53655 |
GHSA-vmf3-w455-68vh |
tar |
npm |
PAX size override applied to intermediate GNU long-name/long-link headers, causing tar parser interpretation discrepancy (file smuggling) |
<= 7.5.15 |
7.5.16 |
2026-08-05 |
2026-08-24 |
#5 |
| 4 |
Medium |
CVE-2026-33672 |
GHSA-3v7f-55p6-f55p |
picomatch |
npm |
Method injection in POSIX character classes causes incorrect glob matching results |
< 2.3.2 |
2.3.2 |
2026-08-05 |
2026-08-24 |
#4 |
| 3 |
High |
CVE-2026-33671 |
GHSA-c2c7-rcm5-vvqj |
picomatch |
npm |
ReDoS vulnerability caused by extglob quantifiers |
< 2.3.2 |
2.3.2 |
2026-08-05 |
2026-08-24 |
#3 |
| 2 |
Medium |
CVE-2025-53892 |
GHSA-x8qp-wqqm-57ph |
@intlify/core-base |
npm |
vue-i18n’s escapeParameterHtml fails to prevent DOM-based XSS via tag attributes |
>= 9.0.0, < 9.14.5 |
9.14.5 |
2026-08-05 |
2026-08-24 |
#2 |
| 1 |
Medium |
CVE-2025-53892 |
GHSA-x8qp-wqqm-57ph |
vue-i18n |
npm |
vue-i18n’s escapeParameterHtml fails to prevent DOM-based XSS via tag attributes |
>= 9.0.0, < 9.14.5 |
9.14.5 |
2026-08-05 |
2026-08-24 |
#1 |