| @grpc/grpc-js |
forms-acceptance-tests |
High
|
@grpc/grpc-js: A malformed request can cause a server crash
|
GHSA-5375-pq7m-f5r2
/ CVE-2026-48068
|
1.13.5 |
| @grpc/grpc-js |
forms-acceptance-tests |
High
|
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
|
GHSA-99f4-grh7-6pcq
/ CVE-2026-48069
|
1.13.5 |
| brace-expansion |
forms-acceptance-tests |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
5.0.7 |
| serialize-javascript |
forms-acceptance-tests |
High
|
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
|
GHSA-5c6j-r48x-rmvq
|
7.0.3 |
| undici |
forms-acceptance-tests |
High
|
undici WebSocket client vulnerable to denial of service via fragment count bypass
|
GHSA-vxpw-j846-p89q
/ CVE-2026-12151
|
8.5.0 |
| undici |
forms-acceptance-tests |
High
|
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
|
GHSA-vmh5-mc38-953g
/ CVE-2026-9697
|
8.5.0 |
| undici |
forms-acceptance-tests |
High
|
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
|
GHSA-38rv-x7px-6hhq
/ CVE-2026-9675
|
8.5.0 |
| basic-ftp |
forms-adaptor-template |
High
|
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
|
GHSA-rpmf-866q-6p89
/ CVE-2026-44240
|
5.3.1 |
| basic-ftp |
forms-adaptor-template |
High
|
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
|
GHSA-rp42-5vxx-qpwr
/ CVE-2026-41324
|
5.3.0 |
| basic-ftp |
forms-adaptor-template |
High
|
basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands
|
GHSA-6v7q-wjvx-w8wg
|
5.2.2 |
| brace-expansion |
forms-adaptor-template |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
5.0.7 |
| flatted |
forms-adaptor-template |
High
|
Prototype Pollution via parse() in NodeJS flatted
|
GHSA-rf6f-7fwh-wjgh
/ CVE-2026-33228
|
3.4.2 |
| liquidjs |
forms-adaptor-template |
High
|
LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
|
GHSA-r7g9-xpmj-5fcq
/ CVE-2026-45617
|
10.26.0 |
| liquidjs |
forms-adaptor-template |
High
|
LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)
|
GHSA-hh27-hf48-9f5q
/ CVE-2026-45357
|
— |
| liquidjs |
forms-adaptor-template |
High
|
liquidjs has a Denial of Service via circular block reference in layout
|
GHSA-4rc3-7j7w-m548
/ CVE-2026-41311
|
10.25.7 |
| picomatch |
forms-adaptor-template |
High
|
Picomatch has a ReDoS vulnerability via extglob quantifiers
|
GHSA-c2c7-rcm5-vvqj
/ CVE-2026-33671
|
2.3.2 |
| serialize-javascript |
forms-adaptor-template |
High
|
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
|
GHSA-5c6j-r48x-rmvq
|
7.0.3 |
| svgo |
forms-adaptor-template |
High
|
SVGO removeScripts plugin leaves some executable scripts intact
|
GHSA-2p49-hgcm-8545
|
3.3.4 |
| undici |
forms-adaptor-template |
High
|
undici WebSocket client vulnerable to denial of service via fragment count bypass
|
GHSA-vxpw-j846-p89q
/ CVE-2026-12151
|
7.28.0 |
| undici |
forms-adaptor-template |
High
|
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
|
GHSA-hm92-r4w5-c3mj
/ CVE-2026-6734
|
7.28.0 |
| undici |
forms-adaptor-template |
High
|
undici WebSocket client vulnerable to denial of service via fragment count bypass
|
GHSA-vxpw-j846-p89q
/ CVE-2026-12151
|
8.5.0 |
| undici |
forms-adaptor-template |
High
|
undici WebSocket client vulnerable to denial of service via fragment count bypass
|
GHSA-vxpw-j846-p89q
/ CVE-2026-12151
|
8.5.0 |
| undici |
forms-adaptor-template |
High
|
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
|
GHSA-vmh5-mc38-953g
/ CVE-2026-9697
|
7.28.0 |
| undici |
forms-adaptor-template |
High
|
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
|
GHSA-vmh5-mc38-953g
/ CVE-2026-9697
|
8.5.0 |
| undici |
forms-adaptor-template |
High
|
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
|
GHSA-vmh5-mc38-953g
/ CVE-2026-9697
|
8.5.0 |
| undici |
forms-adaptor-template |
High
|
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
|
GHSA-38rv-x7px-6hhq
/ CVE-2026-9675
|
8.5.0 |
| undici |
forms-adaptor-template |
High
|
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
|
GHSA-38rv-x7px-6hhq
/ CVE-2026-9675
|
8.5.0 |
| validator |
forms-adaptor-template |
High
|
Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements
|
GHSA-vghf-hv5q-vc2g
/ CVE-2025-12758
|
13.15.22 |
| brace-expansion |
forms-audit-api |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
5.0.7 |
| brace-expansion |
forms-designer |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
2.1.2 |
| brace-expansion |
forms-designer |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
1.1.16 |
| brace-expansion |
forms-designer |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
5.0.7 |
| fast-uri |
forms-designer |
High
|
fast-uri vulnerable to host confusion via literal backslash authority delimiter
|
GHSA-v2hh-gcrm-f6hx
/ CVE-2026-16221
|
3.1.4 |
| fast-uri |
forms-designer |
High
|
fast-uri vulnerable to host confusion via failed IDN canonicalization
|
GHSA-4c8g-83qw-93j6
/ CVE-2026-13676
|
3.1.3 |
| form-data |
forms-designer |
High
|
form-data: CRLF injection in form-data via unescaped multipart field names and filenames
|
GHSA-hmw2-7cc7-3qxx
/ CVE-2026-12143
|
4.0.6 |
| immutable |
forms-designer |
High
|
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
|
GHSA-xvcm-6775-5m9r
/ CVE-2026-59880
|
5.1.8 |
| immutable |
forms-designer |
High
|
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
|
GHSA-v56q-mh7h-f735
/ CVE-2026-59879
|
5.1.8 |
| js-yaml |
forms-designer |
High
|
js-yaml: YAML merge-key chains can force quadratic CPU consumption
|
GHSA-52cp-r559-cp3m
/ CVE-2026-59869
|
4.3.0 |
| js-yaml |
forms-designer |
High
|
js-yaml: YAML merge-key chains can force quadratic CPU consumption
|
GHSA-52cp-r559-cp3m
/ CVE-2026-59869
|
3.15.0 |
| shell-quote |
forms-designer |
High
|
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
|
GHSA-395f-4hp3-45gv
/ CVE-2026-13311
|
1.9.0 |
| svgo |
forms-designer |
High
|
SVGO removeScripts plugin leaves some executable scripts intact
|
GHSA-2p49-hgcm-8545
|
3.3.4 |
| serialize-javascript |
forms-development-tools |
High
|
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
|
GHSA-5c6j-r48x-rmvq
|
7.0.3 |
| @babel/plugin-transform-modules-systemjs |
forms-e2e-smoke-test |
High
|
@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input
|
GHSA-fv7c-fp4j-7gwp
/ CVE-2026-44728
|
7.29.4 |
| basic-ftp |
forms-e2e-smoke-test |
High
|
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
|
GHSA-rpmf-866q-6p89
/ CVE-2026-44240
|
5.3.1 |
| basic-ftp |
forms-e2e-smoke-test |
High
|
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
|
GHSA-rp42-5vxx-qpwr
/ CVE-2026-41324
|
5.3.0 |
| basic-ftp |
forms-e2e-smoke-test |
High
|
basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands
|
GHSA-6v7q-wjvx-w8wg
|
5.2.2 |
| braces |
forms-e2e-smoke-test |
High
|
Uncontrolled resource consumption in braces
|
GHSA-grv7-fg5c-xmjg
/ CVE-2024-4068
|
3.0.3 |
| flatted |
forms-e2e-smoke-test |
High
|
Prototype Pollution via parse() in NodeJS flatted
|
GHSA-rf6f-7fwh-wjgh
/ CVE-2026-33228
|
3.4.2 |
| glob |
forms-e2e-smoke-test |
High
|
glob CLI: Command injection via -c/--cmd executes matches with shell:true
|
GHSA-5j98-mcp5-4vw2
/ CVE-2025-64756
|
10.5.0 |
| lodash |
forms-e2e-smoke-test |
High
|
lodash vulnerable to Code Injection via `_.template` imports key names
|
GHSA-r5fr-rjxr-66jc
/ CVE-2026-4800
|
4.18.0 |
| minimatch |
forms-e2e-smoke-test |
High
|
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
|
GHSA-7r86-cg39-jmmj
/ CVE-2026-27903
|
3.1.3 |
| minimatch |
forms-e2e-smoke-test |
High
|
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
|
GHSA-23c5-xmqv-rm74
/ CVE-2026-27904
|
3.1.4 |
| minimatch |
forms-e2e-smoke-test |
High
|
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
|
GHSA-7r86-cg39-jmmj
/ CVE-2026-27903
|
5.1.8 |
| minimatch |
forms-e2e-smoke-test |
High
|
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
|
GHSA-23c5-xmqv-rm74
/ CVE-2026-27904
|
5.1.8 |
| minimatch |
forms-e2e-smoke-test |
High
|
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
|
GHSA-7r86-cg39-jmmj
/ CVE-2026-27903
|
9.0.7 |
| minimatch |
forms-e2e-smoke-test |
High
|
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
|
GHSA-23c5-xmqv-rm74
/ CVE-2026-27904
|
9.0.7 |
| minimatch |
forms-e2e-smoke-test |
High
|
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
|
GHSA-3ppc-4f35-3m26
/ CVE-2026-26996
|
3.1.3 |
| minimatch |
forms-e2e-smoke-test |
High
|
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
|
GHSA-3ppc-4f35-3m26
/ CVE-2026-26996
|
5.1.7 |
| minimatch |
forms-e2e-smoke-test |
High
|
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
|
GHSA-3ppc-4f35-3m26
/ CVE-2026-26996
|
9.0.6 |
| picomatch |
forms-e2e-smoke-test |
High
|
Picomatch has a ReDoS vulnerability via extglob quantifiers
|
GHSA-c2c7-rcm5-vvqj
/ CVE-2026-33671
|
2.3.2 |
| serialize-javascript |
forms-e2e-smoke-test |
High
|
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
|
GHSA-5c6j-r48x-rmvq
|
7.0.3 |
| tar-fs |
forms-e2e-smoke-test |
High
|
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
|
GHSA-vj76-c3g6-qr5v
/ CVE-2025-59343
|
3.1.1 |
| tar-fs |
forms-e2e-smoke-test |
High
|
tar-fs can extract outside the specified dir with a specific tarball
|
GHSA-8cj5-5rvv-wf4v
/ CVE-2025-48387
|
3.0.9 |
| tar-fs |
forms-e2e-smoke-test |
High
|
tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File
|
GHSA-pq67-2wwv-3xjx
/ CVE-2024-12905
|
3.0.7 |
| tmp |
forms-e2e-smoke-test |
High
|
tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
|
GHSA-ph9p-34f9-6g65
/ CVE-2026-44705
|
0.2.6 |
| ws |
forms-e2e-smoke-test |
High
|
ws: Memory exhaustion DoS from tiny fragments and data chunks
|
GHSA-96hv-2xvq-fx4p
/ CVE-2026-48779
|
8.21.0 |
| ws |
forms-e2e-smoke-test |
High
|
ws affected by a DoS when handling a request with many HTTP headers
|
GHSA-3h5v-q93c-6h6q
/ CVE-2024-37890
|
8.17.1 |
| basic-ftp |
forms-engine-plugin-example-ui |
High
|
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
|
GHSA-rpmf-866q-6p89
/ CVE-2026-44240
|
5.3.1 |
| basic-ftp |
forms-engine-plugin-example-ui |
High
|
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
|
GHSA-rp42-5vxx-qpwr
/ CVE-2026-41324
|
5.3.0 |
| basic-ftp |
forms-engine-plugin-example-ui |
High
|
basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands
|
GHSA-6v7q-wjvx-w8wg
|
5.2.2 |
| basic-ftp |
forms-engine-plugin-example-ui |
High
|
basic-ftp has FTP Command Injection via CRLF
|
GHSA-chqc-8p9q-pq6q
/ CVE-2026-39983
|
5.2.1 |
| brace-expansion |
forms-engine-plugin-example-ui |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
5.0.7 |
| fast-uri |
forms-engine-plugin-example-ui |
High
|
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
|
GHSA-v39h-62p7-jpjc
/ CVE-2026-6322
|
3.1.2 |
| fast-uri |
forms-engine-plugin-example-ui |
High
|
fast-uri vulnerable to path traversal via percent-encoded dot segments
|
GHSA-q3j6-qgpj-74h6
/ CVE-2026-6321
|
3.1.1 |
| flatted |
forms-engine-plugin-example-ui |
High
|
Prototype Pollution via parse() in NodeJS flatted
|
GHSA-rf6f-7fwh-wjgh
/ CVE-2026-33228
|
3.4.2 |
| immutable |
forms-engine-plugin-example-ui |
High
|
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
|
GHSA-xvcm-6775-5m9r
/ CVE-2026-59880
|
5.1.8 |
| immutable |
forms-engine-plugin-example-ui |
High
|
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
|
GHSA-v56q-mh7h-f735
/ CVE-2026-59879
|
5.1.8 |
| liquidjs |
forms-engine-plugin-example-ui |
High
|
LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
|
GHSA-r7g9-xpmj-5fcq
/ CVE-2026-45617
|
10.26.0 |
| liquidjs |
forms-engine-plugin-example-ui |
High
|
LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)
|
GHSA-hh27-hf48-9f5q
/ CVE-2026-45357
|
— |
| liquidjs |
forms-engine-plugin-example-ui |
High
|
liquidjs has a Denial of Service via circular block reference in layout
|
GHSA-4rc3-7j7w-m548
/ CVE-2026-41311
|
10.25.7 |
| liquidjs |
forms-engine-plugin-example-ui |
High
|
LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates
|
GHSA-56p5-8mhr-2fph
/ CVE-2026-35525
|
10.25.3 |
| picomatch |
forms-engine-plugin-example-ui |
High
|
Picomatch has a ReDoS vulnerability via extglob quantifiers
|
GHSA-c2c7-rcm5-vvqj
/ CVE-2026-33671
|
2.3.2 |
| serialize-javascript |
forms-engine-plugin-example-ui |
High
|
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
|
GHSA-5c6j-r48x-rmvq
|
7.0.3 |
| svgo |
forms-engine-plugin-example-ui |
High
|
SVGO removeScripts plugin leaves some executable scripts intact
|
GHSA-2p49-hgcm-8545
|
3.3.4 |
| svgo |
forms-engine-plugin-example-ui |
High
|
SVGO removeScripts plugin leaves some executable scripts intact
|
GHSA-2p49-hgcm-8545
|
4.0.2 |
| undici |
forms-engine-plugin-example-ui |
High
|
undici WebSocket client vulnerable to denial of service via fragment count bypass
|
GHSA-vxpw-j846-p89q
/ CVE-2026-12151
|
7.28.0 |
| undici |
forms-engine-plugin-example-ui |
High
|
undici WebSocket client vulnerable to denial of service via fragment count bypass
|
GHSA-vxpw-j846-p89q
/ CVE-2026-12151
|
8.5.0 |
| undici |
forms-engine-plugin-example-ui |
High
|
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
|
GHSA-hm92-r4w5-c3mj
/ CVE-2026-6734
|
7.28.0 |
| undici |
forms-engine-plugin-example-ui |
High
|
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
|
GHSA-vmh5-mc38-953g
/ CVE-2026-9697
|
8.5.0 |
| undici |
forms-engine-plugin-example-ui |
High
|
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
|
GHSA-38rv-x7px-6hhq
/ CVE-2026-9675
|
8.5.0 |
| undici |
forms-engine-plugin-example-ui |
High
|
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
|
GHSA-vmh5-mc38-953g
/ CVE-2026-9697
|
7.28.0 |
| brace-expansion |
forms-entitlement-api |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
5.0.7 |
| fast-xml-parser |
forms-entitlement-api |
High
|
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
|
GHSA-8r6m-32jq-jx6q
|
5.10.1 |
| SonarSource/sonarqube-scan-action |
forms-entitlement-api |
High
|
Argument injection vulnerability in SonarQube Scan Action
|
GHSA-5xq9-5g24-4g6f
/ CVE-2025-59844
|
6.0.0 |
| undici |
forms-entitlement-api |
High
|
undici WebSocket client vulnerable to denial of service via fragment count bypass
|
GHSA-vxpw-j846-p89q
/ CVE-2026-12151
|
8.5.0 |
| undici |
forms-entitlement-api |
High
|
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
|
GHSA-vmh5-mc38-953g
/ CVE-2026-9697
|
8.5.0 |
| undici |
forms-entitlement-api |
High
|
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
|
GHSA-38rv-x7px-6hhq
/ CVE-2026-9675
|
8.5.0 |
| brace-expansion |
forms-manager |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
2.1.2 |
| brace-expansion |
forms-manager |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
1.1.16 |
| brace-expansion |
forms-manager |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
5.0.7 |
| fast-xml-parser |
forms-manager |
High
|
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
|
GHSA-8r6m-32jq-jx6q
|
5.10.1 |
| js-yaml |
forms-manager |
High
|
js-yaml: YAML merge-key chains can force quadratic CPU consumption
|
GHSA-52cp-r559-cp3m
/ CVE-2026-59869
|
4.3.0 |
| js-yaml |
forms-manager |
High
|
js-yaml: YAML merge-key chains can force quadratic CPU consumption
|
GHSA-52cp-r559-cp3m
/ CVE-2026-59869
|
3.15.0 |
| basic-ftp |
forms-newls-cwt-listener |
High
|
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
|
GHSA-rpmf-866q-6p89
/ CVE-2026-44240
|
5.3.1 |
| basic-ftp |
forms-newls-cwt-listener |
High
|
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
|
GHSA-rp42-5vxx-qpwr
/ CVE-2026-41324
|
5.3.0 |
| basic-ftp |
forms-newls-cwt-listener |
High
|
basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands
|
GHSA-6v7q-wjvx-w8wg
|
5.2.2 |
| brace-expansion |
forms-newls-cwt-listener |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
5.0.7 |
| flatted |
forms-newls-cwt-listener |
High
|
Prototype Pollution via parse() in NodeJS flatted
|
GHSA-rf6f-7fwh-wjgh
/ CVE-2026-33228
|
3.4.2 |
| liquidjs |
forms-newls-cwt-listener |
High
|
LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
|
GHSA-r7g9-xpmj-5fcq
/ CVE-2026-45617
|
10.26.0 |
| liquidjs |
forms-newls-cwt-listener |
High
|
LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)
|
GHSA-hh27-hf48-9f5q
/ CVE-2026-45357
|
— |
| liquidjs |
forms-newls-cwt-listener |
High
|
liquidjs has a Denial of Service via circular block reference in layout
|
GHSA-4rc3-7j7w-m548
/ CVE-2026-41311
|
10.25.7 |
| liquidjs |
forms-newls-cwt-listener |
High
|
LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates
|
GHSA-56p5-8mhr-2fph
/ CVE-2026-35525
|
10.25.3 |
| liquidjs |
forms-newls-cwt-listener |
High
|
LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern
|
GHSA-6q5m-63h6-5x4v
/ CVE-2026-33287
|
— |
| liquidjs |
forms-newls-cwt-listener |
High
|
LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash
|
GHSA-9r5m-9576-7f6x
/ CVE-2026-33285
|
— |
| liquidjs |
forms-newls-cwt-listener |
High
|
liquidjs has a path traversal fallback vulnerability
|
GHSA-wmfp-5q7x-987x
/ CVE-2026-30952
|
10.25.0 |
| minimatch |
forms-newls-cwt-listener |
High
|
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
|
GHSA-7r86-cg39-jmmj
/ CVE-2026-27903
|
9.0.7 |
| minimatch |
forms-newls-cwt-listener |
High
|
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
|
GHSA-7r86-cg39-jmmj
/ CVE-2026-27903
|
10.2.3 |
| picomatch |
forms-newls-cwt-listener |
High
|
Picomatch has a ReDoS vulnerability via extglob quantifiers
|
GHSA-c2c7-rcm5-vvqj
/ CVE-2026-33671
|
2.3.2 |
| serialize-javascript |
forms-newls-cwt-listener |
High
|
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
|
GHSA-5c6j-r48x-rmvq
|
7.0.3 |
| svgo |
forms-newls-cwt-listener |
High
|
SVGO removeScripts plugin leaves some executable scripts intact
|
GHSA-2p49-hgcm-8545
|
3.3.4 |
| undici |
forms-newls-cwt-listener |
High
|
undici WebSocket client vulnerable to denial of service via fragment count bypass
|
GHSA-vxpw-j846-p89q
/ CVE-2026-12151
|
7.28.0 |
| undici |
forms-newls-cwt-listener |
High
|
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
|
GHSA-hm92-r4w5-c3mj
/ CVE-2026-6734
|
7.28.0 |
| undici |
forms-newls-cwt-listener |
High
|
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
|
GHSA-vmh5-mc38-953g
/ CVE-2026-9697
|
7.28.0 |
| validator |
forms-newls-cwt-listener |
High
|
Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements
|
GHSA-vghf-hv5q-vc2g
/ CVE-2025-12758
|
13.15.22 |
| basic-ftp |
forms-notify-listener |
High
|
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
|
GHSA-rpmf-866q-6p89
/ CVE-2026-44240
|
5.3.1 |
| basic-ftp |
forms-notify-listener |
High
|
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
|
GHSA-rp42-5vxx-qpwr
/ CVE-2026-41324
|
5.3.0 |
| basic-ftp |
forms-notify-listener |
High
|
basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands
|
GHSA-6v7q-wjvx-w8wg
|
5.2.2 |
| basic-ftp |
forms-notify-listener |
High
|
basic-ftp has FTP Command Injection via CRLF
|
GHSA-chqc-8p9q-pq6q
/ CVE-2026-39983
|
5.2.1 |
| brace-expansion |
forms-notify-listener |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
2.1.2 |
| brace-expansion |
forms-notify-listener |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
1.1.16 |
| brace-expansion |
forms-notify-listener |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
5.0.7 |
| js-yaml |
forms-notify-listener |
High
|
js-yaml: YAML merge-key chains can force quadratic CPU consumption
|
GHSA-52cp-r559-cp3m
/ CVE-2026-59869
|
4.3.0 |
| js-yaml |
forms-notify-listener |
High
|
js-yaml: YAML merge-key chains can force quadratic CPU consumption
|
GHSA-52cp-r559-cp3m
/ CVE-2026-59869
|
3.15.0 |
| liquidjs |
forms-notify-listener |
High
|
LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
|
GHSA-r7g9-xpmj-5fcq
/ CVE-2026-45617
|
10.26.0 |
| liquidjs |
forms-notify-listener |
High
|
LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)
|
GHSA-hh27-hf48-9f5q
/ CVE-2026-45357
|
— |
| liquidjs |
forms-notify-listener |
High
|
liquidjs has a Denial of Service via circular block reference in layout
|
GHSA-4rc3-7j7w-m548
/ CVE-2026-41311
|
10.25.7 |
| liquidjs |
forms-notify-listener |
High
|
LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates
|
GHSA-56p5-8mhr-2fph
/ CVE-2026-35525
|
10.25.3 |
| shell-quote |
forms-runner |
High
|
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
|
GHSA-395f-4hp3-45gv
/ CVE-2026-13311
|
1.9.0 |
| brace-expansion |
forms-runner-acceptance-tests |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
5.0.7 |
| undici |
forms-runner-acceptance-tests |
High
|
undici WebSocket client vulnerable to denial of service via fragment count bypass
|
GHSA-vxpw-j846-p89q
/ CVE-2026-12151
|
7.28.0 |
| undici |
forms-runner-acceptance-tests |
High
|
undici WebSocket client vulnerable to denial of service via fragment count bypass
|
GHSA-vxpw-j846-p89q
/ CVE-2026-12151
|
7.28.0 |
| undici |
forms-runner-acceptance-tests |
High
|
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
|
GHSA-vrm6-8vpv-qv8q
/ CVE-2026-1526
|
7.24.0 |
| undici |
forms-runner-acceptance-tests |
High
|
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
|
GHSA-v9p9-hfj2-hcw8
/ CVE-2026-2229
|
7.24.0 |
| undici |
forms-runner-acceptance-tests |
High
|
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
|
GHSA-f269-vfmq-vjvj
/ CVE-2026-1528
|
7.24.0 |
| brace-expansion |
forms-runner-tests |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
5.0.7 |
| flatted |
forms-runner-tests |
High
|
Prototype Pollution via parse() in NodeJS flatted
|
GHSA-rf6f-7fwh-wjgh
/ CVE-2026-33228
|
3.4.2 |
| brace-expansion |
forms-sharepoint-listener |
High
|
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
|
GHSA-3jxr-9vmj-r5cp
/ CVE-2026-13149
|
5.0.7 |
| serialize-javascript |
forms-sharepoint-listener |
High
|
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
|
GHSA-5c6j-r48x-rmvq
|
7.0.3 |
| svgo |
forms-sharepoint-listener |
High
|
SVGO removeScripts plugin leaves some executable scripts intact
|
GHSA-2p49-hgcm-8545
|
3.3.4 |
| undici |
forms-sharepoint-listener |
High
|
undici WebSocket client vulnerable to denial of service via fragment count bypass
|
GHSA-vxpw-j846-p89q
/ CVE-2026-12151
|
7.28.0 |
| undici |
forms-sharepoint-listener |
High
|
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
|
GHSA-hm92-r4w5-c3mj
/ CVE-2026-6734
|
7.28.0 |
| undici |
forms-sharepoint-listener |
High
|
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
|
GHSA-vmh5-mc38-953g
/ CVE-2026-9697
|
7.28.0 |
| @babel/plugin-transform-modules-systemjs |
forms-smoke-test |
High
|
@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input
|
GHSA-fv7c-fp4j-7gwp
/ CVE-2026-44728
|
7.29.4 |
| basic-ftp |
forms-smoke-test |
High
|
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
|
GHSA-rpmf-866q-6p89
/ CVE-2026-44240
|
5.3.1 |
| basic-ftp |
forms-smoke-test |
High
|
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
|
GHSA-rp42-5vxx-qpwr
/ CVE-2026-41324
|
5.3.0 |
| basic-ftp |
forms-smoke-test |
High
|
basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands
|
GHSA-6v7q-wjvx-w8wg
|
5.2.2 |
| basic-ftp |
forms-smoke-test |
High
|
basic-ftp has FTP Command Injection via CRLF
|
GHSA-chqc-8p9q-pq6q
/ CVE-2026-39983
|
5.2.1 |
| fast-xml-parser |
forms-smoke-test |
High
|
fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)
|
GHSA-8gc5-j5rx-235r
/ CVE-2026-33036
|
4.5.5 |
| flatted |
forms-smoke-test |
High
|
Prototype Pollution via parse() in NodeJS flatted
|
GHSA-rf6f-7fwh-wjgh
/ CVE-2026-33228
|
3.4.2 |
| lodash |
forms-smoke-test |
High
|
lodash vulnerable to Code Injection via `_.template` imports key names
|
GHSA-r5fr-rjxr-66jc
/ CVE-2026-4800
|
4.18.0 |
| minimatch |
forms-smoke-test |
High
|
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
|
GHSA-7r86-cg39-jmmj
/ CVE-2026-27903
|
3.1.3 |
| minimatch |
forms-smoke-test |
High
|
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
|
GHSA-23c5-xmqv-rm74
/ CVE-2026-27904
|
3.1.4 |
| minimatch |
forms-smoke-test |
High
|
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
|
GHSA-3ppc-4f35-3m26
/ CVE-2026-26996
|
3.1.3 |
| picomatch |
forms-smoke-test |
High
|
Picomatch has a ReDoS vulnerability via extglob quantifiers
|
GHSA-c2c7-rcm5-vvqj
/ CVE-2026-33671
|
2.3.2 |
| serialize-javascript |
forms-smoke-test |
High
|
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
|
GHSA-5c6j-r48x-rmvq
|
7.0.3 |
| tmp |
forms-smoke-test |
High
|
tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
|
GHSA-ph9p-34f9-6g65
/ CVE-2026-44705
|
0.2.6 |
| undici |
forms-smoke-test |
High
|
undici WebSocket client vulnerable to denial of service via fragment count bypass
|
GHSA-vxpw-j846-p89q
/ CVE-2026-12151
|
6.27.0 |
| undici |
forms-smoke-test |
High
|
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
|
GHSA-v9p9-hfj2-hcw8
/ CVE-2026-2229
|
6.24.0 |
| undici |
forms-smoke-test |
High
|
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
|
GHSA-vrm6-8vpv-qv8q
/ CVE-2026-1526
|
6.24.0 |
| undici |
forms-smoke-test |
High
|
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
|
GHSA-f269-vfmq-vjvj
/ CVE-2026-1528
|
6.24.0 |
| ws |
forms-smoke-test |
High
|
ws: Memory exhaustion DoS from tiny fragments and data chunks
|
GHSA-96hv-2xvq-fx4p
/ CVE-2026-48779
|
8.21.0 |
| serialize-javascript |
forms-submission-api |
High
|
Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
|
GHSA-5c6j-r48x-rmvq
|
7.0.3 |
| SonarSource/sonarqube-scan-action |
forms-submission-api |
High
|
Argument injection vulnerability in SonarQube Scan Action
|
GHSA-5xq9-5g24-4g6f
/ CVE-2025-59844
|
6.0.0 |
| SonarSource/sonarqube-scan-action |
forms-submission-api |
High
|
Argument injection vulnerability in SonarQube Scan Action
|
GHSA-5xq9-5g24-4g6f
/ CVE-2025-59844
|
6.0.0 |