VYPR

apk package

chainguard/node-gyp

pkg:apk/chainguard/node-gyp

Vulnerabilities (22)

  • CVE-2024-21538HigNov 8, 2024
    affected < 10.3.1-r0fixed 10.3.1-r0

    Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted

  • CVE-2023-42282CriFeb 8, 2024
    affected < 10.1.0-r0fixed 10.1.0-r0

    The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

Page 2 of 2