VYPR

rpm package

opensuse/heroic-games-launcher&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/heroic-games-launcher&distro=openSUSE%20Tumbleweed

Vulnerabilities (13)

  • CVE-2026-54673HigJun 30, 2026
    affected < 2.22.0-4.1fixed 2.22.0-4.1

    electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) only stripped a credential header whose key string matched exactly lowercase "authorization", exposing credentials. Other credential

  • CVE-2026-54672HigJun 30, 2026
    affected < 2.22.0-4.1fixed 2.22.0-4.1

    electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added t

  • CVE-2026-56876HigJun 26, 2026
    affected < 2.22.0-4.1fixed 2.22.0-4.1

    extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extr

  • CVE-2026-13311HigJun 25, 2026
    affected < 2.22.0-3.1fixed 2.22.0-3.1

    shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacke

  • CVE-2026-48779HigJun 17, 2026
    affected < 2.22.0-3.1fixed 2.22.0-3.1

    ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume

  • CVE-2026-34601HigApr 2, 2026
    affected < 2.20.1-5.1fixed 2.20.1-5.1

    xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom versions 0.6.0 and prior and @xmldom/xmldom prior to versions 0.8.12 and 0.9.9, xmldom/xmldom allows attacker-controlled strings containing the CDATA terminator

  • CVE-2026-33036HigMar 20, 2026
    affected < 2.20.1-4.1fixed 2.20.1-4.1

    fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and standard XML entities completely evade the entity expa

  • CVE-2026-28292CriMar 10, 2026
    affected < 2.20.1-3.1fixed 2.20.1-3.1

    `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code execution on the host machine. Ver

  • CVE-2026-3449LowMar 3, 2026
    affected < 2.20.1-2.1fixed 2.20.1-2.1

    Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang

  • CVE-2026-27606CriFeb 25, 2026
    affected < 2.20.0-2.1fixed 2.20.0-2.1

    Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine a

  • CVE-2026-26278HigFeb 19, 2026
    affected < 2.20.0-1.1fixed 2.20.0-1.1

    fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML inpu

  • CVE-2026-25547CriFeb 4, 2026
    affected < 2.20.0-1.1fixed 2.20.0-1.1

    @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated nume

  • CVE-2026-22029HigJan 10, 2026
    affected < 2.18.1-2.1fixed 2.18.1-2.1

    React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can res