VYPR

rpm package

opensuse/agama-web-ui&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/agama-web-ui&distro=openSUSE%20Tumbleweed

Vulnerabilities (25)

  • CVE-2026-73650HigAug 13, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optim

  • CVE-2026-73089HigAug 11, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, al

  • CVE-2026-73088HigAug 11, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-sta

  • CVE-2026-73086HigAug 11, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2

  • CVE-2026-69153MedAug 3, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or d

  • CVE-2026-67321HigAug 1, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization

  • CVE-2026-67319LowAug 1, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another component. While the top-level merged config uses a null prototype, nested plain obj

  • CVE-2026-67317HigAug 1, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egr

  • CVE-2026-67315HigAug 1, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured proxies, potentially

  • CVE-2026-67313HigAug 1, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack a

  • CVE-2026-54466HigJul 17, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sendi

  • CVE-2026-13149HigJun 30, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause sign

  • CVE-2026-13676HigJun 29, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() an

  • CVE-2026-13311HigJun 25, 2026
    affected < 23+75.1a877fb50-50.1fixed 23+75.1a877fb50-50.1

    shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacke

  • CVE-2026-53663LowJun 22, 2026
    affected < 23+0.f26ed5eab-49.1fixed 23+0.f26ed5eab-49.1

    React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerability because modern browser protections

  • CVE-2026-55602HigJun 22, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-co

  • CVE-2026-53632MedJun 22, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host

  • CVE-2026-49356LowJun 22, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the s

  • CVE-2026-53550MedJun 22, 2026
    affected < 24+0.a836cced5-52.1fixed 24+0.a836cced5-52.1

    js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior rel

  • CVE-2026-34077HigJun 2, 2026
    affected < 22+143.ee15dea20-46.1fixed 22+143.ee15dea20-46.1

    React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sou

Page 1 of 2