VYPR
Vendor

Pillarjs

Products
5
CVEs
13
Across products
13
Status
Private

Products

5

Recent CVEs

13
  • CVE-2026-8162HigMay 12, 2026
    risk 0.49cvss 7.5epss 0.01

    [email protected] and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a Content-Disposition header whose filename* parameter contains a malformed percent-encoding, the parser invokes decodeURI on the value…

  • CVE-2026-4867HigMar 26, 2026
    risk 0.49cvss 7.5epss 0.01

    Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in [email protected] only prevents…

  • CVE-2026-16231HigAug 25, 2026
    risk 0.46cvss 8.1epss 0.00

    hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after…

  • CVE-2024-52798HigDec 5, 2024
    risk 0.43cvss —epss 0.01

    path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of…

  • CVE-2026-87908HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.01

    multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An unauthenticated attacker can…

  • CVE-2026-8161HigMay 12, 2026
    risk 0.42cvss 7.5epss 0.01

    [email protected] and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a field name that collides with an inherited Object.prototype property such as __proto__, constructor, or toString, the parser invokes…

  • CVE-2026-8159HigMay 12, 2026
    risk 0.42cvss 7.5epss 0.01

    [email protected] and lower versions are vulnerable to denial of service via regular expression backtracking in the Content-Disposition filename parameter parser. A crafted multipart upload with a long header value can cause regex matching to take seconds, blocking the event…

  • CVE-2026-4926HigMar 26, 2026
    risk 0.42cvss 7.5epss 0.01

    Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service. Patches: Fixed in version 8.4.0. …

  • CVE-2024-45296HigSep 9, 2024
    risk 0.42cvss 7.5epss 0.01

    path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance…

  • CVE-2026-87123MedSep 11, 2026
    risk 0.31cvss 5.9epss 0.00

    hbs is an Express view engine wrapper for Handlebars. Version 4.3.0 can crash the Node.js process during output escaping when an async helper, registered with registerAsyncHelper, resolves to an object whose toHTML property is truthy but not callable. Handlebars escapeExpression…

  • CVE-2026-4923MedMar 26, 2026
    risk 0.31cvss 5.9epss 0.00

    Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path. Unsafe examples: …

  • CVE-2021-32822MedAug 16, 2021
    risk 0.26cvss 4.0epss 0.01

    The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnerability. There is currently no patch for this vulnerability. hbs mixes pure template data with engine configuration options through…

  • CVE-2026-88038MedSep 10, 2026
    risk 0.24cvss 4.8epss 0.00

    cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator, but the domain and path options are checked only…