VYPR

apk package

wolfi/jitsucom-jitsu-console

pkg:apk/wolfi/jitsucom-jitsu-console

Vulnerabilities (109)

  • CVE-2026-71429MedSep 3, 2026
    affected < 2.11.0-r34fixed 2.11.0-r34

    stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.5.0, the path filters pick, ignore, filter, and replace in src/core/filters/filter-base.js recompute the full path string from the nesting stack for every

  • CVE-2026-82659HigAug 31, 2026
    affected < 2.11.0-r28fixed 2.11.0-r28

    nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by cra

  • CVE-2026-73646HigAug 17, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and load

  • CVE-2026-73569HigAug 13, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through ad

  • CVE-2026-73419MedAug 12, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callba

  • CVE-2026-73418HigAug 12, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a malformed Authorization: Bearer head

  • CVE-2026-67320HigAug 1, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immutable interceptor pattern such

  • CVE-2026-67319LowAug 1, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another component. While the top-level merged config uses a null prototype, nested plain obj

  • CVE-2026-67318MedAug 1, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node's HTTP/2 request API does not honor the maxBodyLength option and axios's byte-counting stream wrap

  • CVE-2026-67317HigAug 1, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egr

  • CVE-2026-67316HigAug 1, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()),

  • CVE-2026-67315HigAug 1, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially

  • CVE-2026-67314MedAug 1, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-pollution primitive and makes an axios reques

  • CVE-2026-67313HigAug 1, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack a

  • CVE-2026-67312HigAug 1, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json). When an application passes attacker-controlled

  • CVE-2026-67214MedJul 29, 2026
    affected < 2.11.0-r32fixed 2.11.0-r32

    nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its

  • CVE-2026-67213MedJul 29, 2026
    affected < 2.11.0-r32fixed 2.11.0-r32

    nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An a

  • CVE-2026-64649MedJul 27, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-S

  • CVE-2026-64648MedJul 27, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidenti

  • CVE-2026-64647MedJul 27, 2026
    affected < 2.11.0-r30fixed 2.11.0-r30

    Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidentia

Page 1 of 6