VYPR

apk package

wolfi/langfuse-3-worker

pkg:apk/wolfi/langfuse-3-worker

Vulnerabilities (189)

  • CVE-2026-82659HigAug 31, 2026
    affected < 3.216.0-r0fixed 3.216.0-r0

    nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by cra

  • CVE-2026-40345HigAug 20, 2026
    affected < 3.225.5-r0fixed 3.225.5-r0

    deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs do not track visited objects or object pairs when recursively merging records. When two

  • CVE-2026-73646HigAug 17, 2026
    affected < 3.224.3-r0fixed 3.224.3-r0

    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and load

  • CVE-2026-73419MedAug 12, 2026
    affected < 3.224.3-r0fixed 3.224.3-r0

    NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callba

  • CVE-2026-73418HigAug 12, 2026
    affected < 3.224.3-r0fixed 3.224.3-r0

    NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a malformed Authorization: Bearer head

  • CVE-2026-69207MedAug 7, 2026
    affected < 3.225.1-r2fixed 3.225.1-r2

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS request, the middleware parses the attacker

  • CVE-2026-71850MedAug 7, 2026
    affected < 3.225.1-r2fixed 3.225.1-r2

    Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later renders with comparator equal props, and request scoped values read inside the comp

  • CVE-2026-71849LowAug 7, 2026
    affected < 3.225.1-r2fixed 3.225.1-r2

    Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by the origin's Connection header. Per RFC 9110 Section 7.6.1, an intermediary must

  • CVE-2026-71848MedAug 7, 2026
    affected < 3.225.1-r2fixed 3.225.1-r2

    Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen separ

  • CVE-2026-71439MedAug 6, 2026
    affected < 3.225.1-r2fixed 3.225.1-r2

    Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high CPU usage and freeze the rendering webpage

  • CVE-2026-71438LowAug 6, 2026
    affected < 3.225.1-r2fixed 3.225.1-r2

    Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid's configuration setters (mermaid.initialize, mermaidAPI.setConfig, and mermaidAPI.updateSiteConfig) merge caller-supplied configuration int

  • CVE-2026-71437MedAug 6, 2026
    affected < 3.225.1-r2fixed 3.225.1-r2

    Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Architecture Diagrams are vulnerable to prototype pollution when a diagram defines a group with an id of __proto__. Because the group

  • CVE-2026-71436MedAug 6, 2026
    affected < 3.225.1-r2fixed 3.225.1-r2

    Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisRangeData function when configuring an X-Axi

  • CVE-2026-50159MedAug 6, 2026
    affected < 3.225.1-r2fixed 3.225.1-r2

    Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied class or id names. An attacker who can supp

  • CVE-2026-69198MedAug 3, 2026
    affected < 3.225.1-r2fixed 3.225.1-r2

    ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the reference

  • CVE-2026-69192HigAug 3, 2026
    affected < 3.225.1-r2fixed 3.225.1-r2

    ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as

  • CVE-2026-69153MedAug 3, 2026
    affected < 3.225.1-r2fixed 3.225.1-r2

    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or d

  • CVE-2026-69152HigAug 3, 2026
    affected < 3.225.0-r2fixed 3.225.0-r2

    The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled in

  • CVE-2026-67320HigAug 1, 2026
    affected < 3.223.0-r0fixed 3.223.0-r0

    axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immutable interceptor pattern such

  • CVE-2026-67319LowAug 1, 2026
    affected < 3.223.0-r0fixed 3.223.0-r0

    axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another component. While the top-level merged config uses a null prototype, nested plain obj

Page 1 of 10