VYPR

Redoc

by Redocly

Source repositories

CVEs (2)

  • CVE-2024-57083HigMar 28, 2025
    risk 0.42cvss 7.5epss 0.01

    A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

  • CVE-2026-63225MedSep 16, 2026
    risk 0.22cvss 4.4epss 0.00

    Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSamples lang values without verifying that the…