Skip to main content

DEFRA / forms team

Security

Open Dependabot vulnerability alerts across team repositories.

Last updated 2 minutes ago. Next update in 8 minutes.

372 open vulnerability alerts across team repositories.

Critical 8 alerts

Package Repo Severity Advisory ID Fixed in
basic-ftp forms-adaptor-template Critical Basic FTP has Path Traversal Vulnerability in its downloadToDir() method GHSA-5rq4-664w-9x2c / CVE-2026-27699 5.2.0
liquidjs forms-adaptor-template Critical LiquidJS is Vulnerable to Remote Code Execution GHSA-gf2q-c269-pqgc / CVE-2026-45618 10.26.0
shell-quote forms-designer Critical shell-quote quote() does not escape newlines in object .op values GHSA-w7jw-789q-3m8p / CVE-2026-9277 1.8.4
basic-ftp forms-e2e-smoke-test Critical Basic FTP has Path Traversal Vulnerability in its downloadToDir() method GHSA-5rq4-664w-9x2c / CVE-2026-27699 5.2.0
liquidjs forms-engine-plugin-example-ui Critical LiquidJS is Vulnerable to Remote Code Execution GHSA-gf2q-c269-pqgc / CVE-2026-45618 10.26.0
basic-ftp forms-newls-cwt-listener Critical Basic FTP has Path Traversal Vulnerability in its downloadToDir() method GHSA-5rq4-664w-9x2c / CVE-2026-27699 5.2.0
liquidjs forms-newls-cwt-listener Critical LiquidJS is Vulnerable to Remote Code Execution GHSA-gf2q-c269-pqgc / CVE-2026-45618 10.26.0
liquidjs forms-notify-listener Critical LiquidJS is Vulnerable to Remote Code Execution GHSA-gf2q-c269-pqgc / CVE-2026-45618 10.26.0

High 174 alerts

Package Repo Severity Advisory ID Fixed in
@grpc/grpc-js forms-acceptance-tests High @grpc/grpc-js: A malformed request can cause a server crash GHSA-5375-pq7m-f5r2 / CVE-2026-48068 1.13.5
@grpc/grpc-js forms-acceptance-tests High @grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash GHSA-99f4-grh7-6pcq / CVE-2026-48069 1.13.5
brace-expansion forms-acceptance-tests High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
serialize-javascript forms-acceptance-tests High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
undici forms-acceptance-tests High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 8.5.0
undici forms-acceptance-tests High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 8.5.0
undici forms-acceptance-tests High undici WebSocket client vulnerable to denial of service via cumulative fragment bypass GHSA-38rv-x7px-6hhq / CVE-2026-9675 8.5.0
basic-ftp forms-adaptor-template High basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering GHSA-rpmf-866q-6p89 / CVE-2026-44240 5.3.1
basic-ftp forms-adaptor-template High basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list() GHSA-rp42-5vxx-qpwr / CVE-2026-41324 5.3.0
basic-ftp forms-adaptor-template High basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands GHSA-6v7q-wjvx-w8wg 5.2.2
brace-expansion forms-adaptor-template High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
flatted forms-adaptor-template High Prototype Pollution via parse() in NodeJS flatted GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 3.4.2
liquidjs forms-adaptor-template High LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex GHSA-r7g9-xpmj-5fcq / CVE-2026-45617 10.26.0
liquidjs forms-adaptor-template High LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime) GHSA-hh27-hf48-9f5q / CVE-2026-45357
liquidjs forms-adaptor-template High liquidjs has a Denial of Service via circular block reference in layout GHSA-4rc3-7j7w-m548 / CVE-2026-41311 10.25.7
picomatch forms-adaptor-template High Picomatch has a ReDoS vulnerability via extglob quantifiers GHSA-c2c7-rcm5-vvqj / CVE-2026-33671 2.3.2
serialize-javascript forms-adaptor-template High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
svgo forms-adaptor-template High SVGO removeScripts plugin leaves some executable scripts intact GHSA-2p49-hgcm-8545 3.3.4
undici forms-adaptor-template High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 7.28.0
undici forms-adaptor-template High undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse GHSA-hm92-r4w5-c3mj / CVE-2026-6734 7.28.0
undici forms-adaptor-template High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 8.5.0
undici forms-adaptor-template High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 8.5.0
undici forms-adaptor-template High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 7.28.0
undici forms-adaptor-template High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 8.5.0
undici forms-adaptor-template High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 8.5.0
undici forms-adaptor-template High undici WebSocket client vulnerable to denial of service via cumulative fragment bypass GHSA-38rv-x7px-6hhq / CVE-2026-9675 8.5.0
undici forms-adaptor-template High undici WebSocket client vulnerable to denial of service via cumulative fragment bypass GHSA-38rv-x7px-6hhq / CVE-2026-9675 8.5.0
validator forms-adaptor-template High Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements GHSA-vghf-hv5q-vc2g / CVE-2025-12758 13.15.22
brace-expansion forms-audit-api High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
brace-expansion forms-designer High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 2.1.2
brace-expansion forms-designer High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
brace-expansion forms-designer High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
fast-uri forms-designer High fast-uri vulnerable to host confusion via literal backslash authority delimiter GHSA-v2hh-gcrm-f6hx / CVE-2026-16221 3.1.4
fast-uri forms-designer High fast-uri vulnerable to host confusion via failed IDN canonicalization GHSA-4c8g-83qw-93j6 / CVE-2026-13676 3.1.3
form-data forms-designer High form-data: CRLF injection in form-data via unescaped multipart field names and filenames GHSA-hmw2-7cc7-3qxx / CVE-2026-12143 4.0.6
immutable forms-designer High Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set GHSA-xvcm-6775-5m9r / CVE-2026-59880 5.1.8
immutable forms-designer High Immutable.js `List` 32-bit trie overflow → unrecoverable DoS GHSA-v56q-mh7h-f735 / CVE-2026-59879 5.1.8
js-yaml forms-designer High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
js-yaml forms-designer High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 3.15.0
shell-quote forms-designer High shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) GHSA-395f-4hp3-45gv / CVE-2026-13311 1.9.0
svgo forms-designer High SVGO removeScripts plugin leaves some executable scripts intact GHSA-2p49-hgcm-8545 3.3.4
serialize-javascript forms-development-tools High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
@babel/plugin-transform-modules-systemjs forms-e2e-smoke-test High @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input GHSA-fv7c-fp4j-7gwp / CVE-2026-44728 7.29.4
basic-ftp forms-e2e-smoke-test High basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering GHSA-rpmf-866q-6p89 / CVE-2026-44240 5.3.1
basic-ftp forms-e2e-smoke-test High basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list() GHSA-rp42-5vxx-qpwr / CVE-2026-41324 5.3.0
basic-ftp forms-e2e-smoke-test High basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands GHSA-6v7q-wjvx-w8wg 5.2.2
braces forms-e2e-smoke-test High Uncontrolled resource consumption in braces GHSA-grv7-fg5c-xmjg / CVE-2024-4068 3.0.3
flatted forms-e2e-smoke-test High Prototype Pollution via parse() in NodeJS flatted GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 3.4.2
glob forms-e2e-smoke-test High glob CLI: Command injection via -c/--cmd executes matches with shell:true GHSA-5j98-mcp5-4vw2 / CVE-2025-64756 10.5.0
lodash forms-e2e-smoke-test High lodash vulnerable to Code Injection via `_.template` imports key names GHSA-r5fr-rjxr-66jc / CVE-2026-4800 4.18.0
minimatch forms-e2e-smoke-test High minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments GHSA-7r86-cg39-jmmj / CVE-2026-27903 3.1.3
minimatch forms-e2e-smoke-test High minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions GHSA-23c5-xmqv-rm74 / CVE-2026-27904 3.1.4
minimatch forms-e2e-smoke-test High minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments GHSA-7r86-cg39-jmmj / CVE-2026-27903 5.1.8
minimatch forms-e2e-smoke-test High minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions GHSA-23c5-xmqv-rm74 / CVE-2026-27904 5.1.8
minimatch forms-e2e-smoke-test High minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments GHSA-7r86-cg39-jmmj / CVE-2026-27903 9.0.7
minimatch forms-e2e-smoke-test High minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions GHSA-23c5-xmqv-rm74 / CVE-2026-27904 9.0.7
minimatch forms-e2e-smoke-test High minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern GHSA-3ppc-4f35-3m26 / CVE-2026-26996 3.1.3
minimatch forms-e2e-smoke-test High minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern GHSA-3ppc-4f35-3m26 / CVE-2026-26996 5.1.7
minimatch forms-e2e-smoke-test High minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern GHSA-3ppc-4f35-3m26 / CVE-2026-26996 9.0.6
picomatch forms-e2e-smoke-test High Picomatch has a ReDoS vulnerability via extglob quantifiers GHSA-c2c7-rcm5-vvqj / CVE-2026-33671 2.3.2
serialize-javascript forms-e2e-smoke-test High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
tar-fs forms-e2e-smoke-test High tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball GHSA-vj76-c3g6-qr5v / CVE-2025-59343 3.1.1
tar-fs forms-e2e-smoke-test High tar-fs can extract outside the specified dir with a specific tarball GHSA-8cj5-5rvv-wf4v / CVE-2025-48387 3.0.9
tar-fs forms-e2e-smoke-test High tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File GHSA-pq67-2wwv-3xjx / CVE-2024-12905 3.0.7
tmp forms-e2e-smoke-test High tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape GHSA-ph9p-34f9-6g65 / CVE-2026-44705 0.2.6
ws forms-e2e-smoke-test High ws: Memory exhaustion DoS from tiny fragments and data chunks GHSA-96hv-2xvq-fx4p / CVE-2026-48779 8.21.0
ws forms-e2e-smoke-test High ws affected by a DoS when handling a request with many HTTP headers GHSA-3h5v-q93c-6h6q / CVE-2024-37890 8.17.1
basic-ftp forms-engine-plugin-example-ui High basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering GHSA-rpmf-866q-6p89 / CVE-2026-44240 5.3.1
basic-ftp forms-engine-plugin-example-ui High basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list() GHSA-rp42-5vxx-qpwr / CVE-2026-41324 5.3.0
basic-ftp forms-engine-plugin-example-ui High basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands GHSA-6v7q-wjvx-w8wg 5.2.2
basic-ftp forms-engine-plugin-example-ui High basic-ftp has FTP Command Injection via CRLF GHSA-chqc-8p9q-pq6q / CVE-2026-39983 5.2.1
brace-expansion forms-engine-plugin-example-ui High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
fast-uri forms-engine-plugin-example-ui High fast-uri vulnerable to host confusion via percent-encoded authority delimiters GHSA-v39h-62p7-jpjc / CVE-2026-6322 3.1.2
fast-uri forms-engine-plugin-example-ui High fast-uri vulnerable to path traversal via percent-encoded dot segments GHSA-q3j6-qgpj-74h6 / CVE-2026-6321 3.1.1
flatted forms-engine-plugin-example-ui High Prototype Pollution via parse() in NodeJS flatted GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 3.4.2
immutable forms-engine-plugin-example-ui High Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set GHSA-xvcm-6775-5m9r / CVE-2026-59880 5.1.8
immutable forms-engine-plugin-example-ui High Immutable.js `List` 32-bit trie overflow → unrecoverable DoS GHSA-v56q-mh7h-f735 / CVE-2026-59879 5.1.8
liquidjs forms-engine-plugin-example-ui High LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex GHSA-r7g9-xpmj-5fcq / CVE-2026-45617 10.26.0
liquidjs forms-engine-plugin-example-ui High LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime) GHSA-hh27-hf48-9f5q / CVE-2026-45357
liquidjs forms-engine-plugin-example-ui High liquidjs has a Denial of Service via circular block reference in layout GHSA-4rc3-7j7w-m548 / CVE-2026-41311 10.25.7
liquidjs forms-engine-plugin-example-ui High LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates GHSA-56p5-8mhr-2fph / CVE-2026-35525 10.25.3
picomatch forms-engine-plugin-example-ui High Picomatch has a ReDoS vulnerability via extglob quantifiers GHSA-c2c7-rcm5-vvqj / CVE-2026-33671 2.3.2
serialize-javascript forms-engine-plugin-example-ui High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
svgo forms-engine-plugin-example-ui High SVGO removeScripts plugin leaves some executable scripts intact GHSA-2p49-hgcm-8545 3.3.4
svgo forms-engine-plugin-example-ui High SVGO removeScripts plugin leaves some executable scripts intact GHSA-2p49-hgcm-8545 4.0.2
undici forms-engine-plugin-example-ui High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 7.28.0
undici forms-engine-plugin-example-ui High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 8.5.0
undici forms-engine-plugin-example-ui High undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse GHSA-hm92-r4w5-c3mj / CVE-2026-6734 7.28.0
undici forms-engine-plugin-example-ui High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 8.5.0
undici forms-engine-plugin-example-ui High undici WebSocket client vulnerable to denial of service via cumulative fragment bypass GHSA-38rv-x7px-6hhq / CVE-2026-9675 8.5.0
undici forms-engine-plugin-example-ui High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 7.28.0
brace-expansion forms-entitlement-api High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
fast-xml-parser forms-entitlement-api High fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits GHSA-8r6m-32jq-jx6q 5.10.1
SonarSource/sonarqube-scan-action forms-entitlement-api High Argument injection vulnerability in SonarQube Scan Action GHSA-5xq9-5g24-4g6f / CVE-2025-59844 6.0.0
undici forms-entitlement-api High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 8.5.0
undici forms-entitlement-api High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 8.5.0
undici forms-entitlement-api High undici WebSocket client vulnerable to denial of service via cumulative fragment bypass GHSA-38rv-x7px-6hhq / CVE-2026-9675 8.5.0
brace-expansion forms-manager High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 2.1.2
brace-expansion forms-manager High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
brace-expansion forms-manager High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
fast-xml-parser forms-manager High fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits GHSA-8r6m-32jq-jx6q 5.10.1
js-yaml forms-manager High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
js-yaml forms-manager High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 3.15.0
basic-ftp forms-newls-cwt-listener High basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering GHSA-rpmf-866q-6p89 / CVE-2026-44240 5.3.1
basic-ftp forms-newls-cwt-listener High basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list() GHSA-rp42-5vxx-qpwr / CVE-2026-41324 5.3.0
basic-ftp forms-newls-cwt-listener High basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands GHSA-6v7q-wjvx-w8wg 5.2.2
brace-expansion forms-newls-cwt-listener High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
flatted forms-newls-cwt-listener High Prototype Pollution via parse() in NodeJS flatted GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 3.4.2
liquidjs forms-newls-cwt-listener High LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex GHSA-r7g9-xpmj-5fcq / CVE-2026-45617 10.26.0
liquidjs forms-newls-cwt-listener High LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime) GHSA-hh27-hf48-9f5q / CVE-2026-45357
liquidjs forms-newls-cwt-listener High liquidjs has a Denial of Service via circular block reference in layout GHSA-4rc3-7j7w-m548 / CVE-2026-41311 10.25.7
liquidjs forms-newls-cwt-listener High LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates GHSA-56p5-8mhr-2fph / CVE-2026-35525 10.25.3
liquidjs forms-newls-cwt-listener High LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern GHSA-6q5m-63h6-5x4v / CVE-2026-33287
liquidjs forms-newls-cwt-listener High LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash GHSA-9r5m-9576-7f6x / CVE-2026-33285
liquidjs forms-newls-cwt-listener High liquidjs has a path traversal fallback vulnerability GHSA-wmfp-5q7x-987x / CVE-2026-30952 10.25.0
minimatch forms-newls-cwt-listener High minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments GHSA-7r86-cg39-jmmj / CVE-2026-27903 9.0.7
minimatch forms-newls-cwt-listener High minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments GHSA-7r86-cg39-jmmj / CVE-2026-27903 10.2.3
picomatch forms-newls-cwt-listener High Picomatch has a ReDoS vulnerability via extglob quantifiers GHSA-c2c7-rcm5-vvqj / CVE-2026-33671 2.3.2
serialize-javascript forms-newls-cwt-listener High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
svgo forms-newls-cwt-listener High SVGO removeScripts plugin leaves some executable scripts intact GHSA-2p49-hgcm-8545 3.3.4
undici forms-newls-cwt-listener High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 7.28.0
undici forms-newls-cwt-listener High undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse GHSA-hm92-r4w5-c3mj / CVE-2026-6734 7.28.0
undici forms-newls-cwt-listener High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 7.28.0
validator forms-newls-cwt-listener High Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements GHSA-vghf-hv5q-vc2g / CVE-2025-12758 13.15.22
basic-ftp forms-notify-listener High basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering GHSA-rpmf-866q-6p89 / CVE-2026-44240 5.3.1
basic-ftp forms-notify-listener High basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list() GHSA-rp42-5vxx-qpwr / CVE-2026-41324 5.3.0
basic-ftp forms-notify-listener High basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands GHSA-6v7q-wjvx-w8wg 5.2.2
basic-ftp forms-notify-listener High basic-ftp has FTP Command Injection via CRLF GHSA-chqc-8p9q-pq6q / CVE-2026-39983 5.2.1
brace-expansion forms-notify-listener High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 2.1.2
brace-expansion forms-notify-listener High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
brace-expansion forms-notify-listener High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
js-yaml forms-notify-listener High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
js-yaml forms-notify-listener High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 3.15.0
liquidjs forms-notify-listener High LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex GHSA-r7g9-xpmj-5fcq / CVE-2026-45617 10.26.0
liquidjs forms-notify-listener High LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime) GHSA-hh27-hf48-9f5q / CVE-2026-45357
liquidjs forms-notify-listener High liquidjs has a Denial of Service via circular block reference in layout GHSA-4rc3-7j7w-m548 / CVE-2026-41311 10.25.7
liquidjs forms-notify-listener High LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates GHSA-56p5-8mhr-2fph / CVE-2026-35525 10.25.3
shell-quote forms-runner High shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) GHSA-395f-4hp3-45gv / CVE-2026-13311 1.9.0
brace-expansion forms-runner-acceptance-tests High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
undici forms-runner-acceptance-tests High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 7.28.0
undici forms-runner-acceptance-tests High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 7.28.0
undici forms-runner-acceptance-tests High Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression GHSA-vrm6-8vpv-qv8q / CVE-2026-1526 7.24.0
undici forms-runner-acceptance-tests High Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation GHSA-v9p9-hfj2-hcw8 / CVE-2026-2229 7.24.0
undici forms-runner-acceptance-tests High Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client GHSA-f269-vfmq-vjvj / CVE-2026-1528 7.24.0
brace-expansion forms-runner-tests High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
flatted forms-runner-tests High Prototype Pollution via parse() in NodeJS flatted GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 3.4.2
brace-expansion forms-sharepoint-listener High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
serialize-javascript forms-sharepoint-listener High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
svgo forms-sharepoint-listener High SVGO removeScripts plugin leaves some executable scripts intact GHSA-2p49-hgcm-8545 3.3.4
undici forms-sharepoint-listener High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 7.28.0
undici forms-sharepoint-listener High undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse GHSA-hm92-r4w5-c3mj / CVE-2026-6734 7.28.0
undici forms-sharepoint-listener High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 7.28.0
@babel/plugin-transform-modules-systemjs forms-smoke-test High @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input GHSA-fv7c-fp4j-7gwp / CVE-2026-44728 7.29.4
basic-ftp forms-smoke-test High basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering GHSA-rpmf-866q-6p89 / CVE-2026-44240 5.3.1
basic-ftp forms-smoke-test High basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list() GHSA-rp42-5vxx-qpwr / CVE-2026-41324 5.3.0
basic-ftp forms-smoke-test High basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands GHSA-6v7q-wjvx-w8wg 5.2.2
basic-ftp forms-smoke-test High basic-ftp has FTP Command Injection via CRLF GHSA-chqc-8p9q-pq6q / CVE-2026-39983 5.2.1
fast-xml-parser forms-smoke-test High fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278) GHSA-8gc5-j5rx-235r / CVE-2026-33036 4.5.5
flatted forms-smoke-test High Prototype Pollution via parse() in NodeJS flatted GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 3.4.2
lodash forms-smoke-test High lodash vulnerable to Code Injection via `_.template` imports key names GHSA-r5fr-rjxr-66jc / CVE-2026-4800 4.18.0
minimatch forms-smoke-test High minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments GHSA-7r86-cg39-jmmj / CVE-2026-27903 3.1.3
minimatch forms-smoke-test High minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions GHSA-23c5-xmqv-rm74 / CVE-2026-27904 3.1.4
minimatch forms-smoke-test High minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern GHSA-3ppc-4f35-3m26 / CVE-2026-26996 3.1.3
picomatch forms-smoke-test High Picomatch has a ReDoS vulnerability via extglob quantifiers GHSA-c2c7-rcm5-vvqj / CVE-2026-33671 2.3.2
serialize-javascript forms-smoke-test High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
tmp forms-smoke-test High tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape GHSA-ph9p-34f9-6g65 / CVE-2026-44705 0.2.6
undici forms-smoke-test High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 6.27.0
undici forms-smoke-test High Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation GHSA-v9p9-hfj2-hcw8 / CVE-2026-2229 6.24.0
undici forms-smoke-test High Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression GHSA-vrm6-8vpv-qv8q / CVE-2026-1526 6.24.0
undici forms-smoke-test High Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client GHSA-f269-vfmq-vjvj / CVE-2026-1528 6.24.0
ws forms-smoke-test High ws: Memory exhaustion DoS from tiny fragments and data chunks GHSA-96hv-2xvq-fx4p / CVE-2026-48779 8.21.0
serialize-javascript forms-submission-api High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
SonarSource/sonarqube-scan-action forms-submission-api High Argument injection vulnerability in SonarQube Scan Action GHSA-5xq9-5g24-4g6f / CVE-2025-59844 6.0.0
SonarSource/sonarqube-scan-action forms-submission-api High Argument injection vulnerability in SonarQube Scan Action GHSA-5xq9-5g24-4g6f / CVE-2025-59844 6.0.0

Medium 146 alerts

Package Repo Severity Advisory ID Fixed in
protobufjs forms-acceptance-tests Medium protobufjs: Denial of Service via infinite loop in .proto option parsing GHSA-j3f2-48v5-ccww / CVE-2026-59877 7.6.5
serialize-javascript forms-acceptance-tests Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
undici forms-acceptance-tests Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 8.5.0
undici forms-acceptance-tests Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 8.5.0
uuid forms-acceptance-tests Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1
@hapi/inert forms-adaptor-template Medium @hapi/inert has a static-file confinement bypass via sibling-prefix path GHSA-rcvq-m9j9-6f4g / CVE-2026-48049 7.1.1
brace-expansion forms-adaptor-template Medium brace-expansion: Zero-step sequence causes process hang and memory exhaustion GHSA-f886-m6hf-6m8v / CVE-2026-33750 1.1.13
http-proxy-middleware forms-adaptor-template Medium http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass GHSA-64mm-vxmg-q3vj / CVE-2026-55602 2.0.10
ip-address forms-adaptor-template Medium ip-address has XSS in Address6 HTML-emitting methods GHSA-v2v4-37r5-5v8g / CVE-2026-42338 10.1.1
joi forms-adaptor-template Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-adaptor-template Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
liquidjs forms-adaptor-template Medium LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()` GHSA-9x9p-qf8f-mvjg / CVE-2026-44646
liquidjs forms-adaptor-template Medium LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body GHSA-8xx9-69p8-7jp3 / CVE-2026-44645
liquidjs forms-adaptor-template Medium LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS GHSA-2qv6-9wx5-cwv4 / CVE-2026-44644
picomatch forms-adaptor-template Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 2.3.2
serialize-javascript forms-adaptor-template Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
undici forms-adaptor-template Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 7.28.0
undici forms-adaptor-template Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 8.5.0
undici forms-adaptor-template Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 8.5.0
undici forms-adaptor-template Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 7.28.0
undici forms-adaptor-template Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 8.5.0
undici forms-adaptor-template Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 8.5.0
uuid forms-adaptor-template Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1
validator forms-adaptor-template Medium validator.js has a URL validation bypass vulnerability in its isURL function GHSA-9965-vmph-33xx / CVE-2025-56200 13.15.20
webpack-dev-server forms-adaptor-template Medium webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies GHSA-mx8g-39q3-5c79 / CVE-2026-9595 5.2.5
yaml forms-adaptor-template Medium yaml is vulnerable to Stack Overflow via deeply nested YAML collections GHSA-48c2-rrv3-qjmp / CVE-2026-33532 2.8.3
joi forms-audit-api Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
joi forms-audit-api Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 18.2.1
js-yaml forms-audit-api Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
js-yaml forms-audit-api Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 4.2.0
@hapi/inert forms-designer Medium @hapi/inert has a static-file confinement bypass via sibling-prefix path GHSA-rcvq-m9j9-6f4g / CVE-2026-48049 7.1.1
joi forms-designer Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-designer Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
js-yaml forms-designer Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 4.2.0
react-router forms-designer Medium React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass) GHSA-wrjc-x8rr-h8h6 / CVE-2026-53669 7.18.0
react-router forms-designer Medium React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration GHSA-337j-9hxr-rhxg / CVE-2026-53666 7.18.0
react-router forms-designer Medium React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation GHSA-2j2x-hqr9-3h42 / CVE-2026-40181 6.30.4
react-router-dom forms-designer Medium React Router: Open redirect leading to XSS GHSA-jjmj-jmhj-qwj2 / CVE-2026-53668
serialize-javascript forms-development-tools Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
uuid forms-development-tools Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1
@babel/helpers forms-e2e-smoke-test Medium Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups GHSA-968p-4wvh-cqc8 / CVE-2025-27789 7.26.10
@babel/runtime forms-e2e-smoke-test Medium Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups GHSA-968p-4wvh-cqc8 / CVE-2025-27789 7.26.10
brace-expansion forms-e2e-smoke-test Medium brace-expansion: Zero-step sequence causes process hang and memory exhaustion GHSA-f886-m6hf-6m8v / CVE-2026-33750 2.0.3
ejs forms-e2e-smoke-test Medium ejs lacks certain pollution protection GHSA-ghr5-ch3p-vcr6 / CVE-2024-33883 3.1.10
ip-address forms-e2e-smoke-test Medium ip-address has XSS in Address6 HTML-emitting methods GHSA-v2v4-37r5-5v8g / CVE-2026-42338 10.1.1
js-yaml forms-e2e-smoke-test Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 4.2.0
js-yaml forms-e2e-smoke-test Medium js-yaml has prototype pollution in merge (<<) GHSA-mh29-5h37-fv8m / CVE-2025-64718 4.1.1
lodash forms-e2e-smoke-test Medium lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` GHSA-f23m-r3pf-42rh / CVE-2026-2950 4.18.0
lodash forms-e2e-smoke-test Medium Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions GHSA-xxjr-mmjv-4gpg / CVE-2025-13465 4.17.23
micromatch forms-e2e-smoke-test Medium Regular Expression Denial of Service (ReDoS) in micromatch GHSA-952p-6rrq-rcjv / CVE-2024-4067 4.0.8
picomatch forms-e2e-smoke-test Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 2.3.2
serialize-javascript forms-e2e-smoke-test Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
serialize-javascript forms-e2e-smoke-test Medium Cross-site Scripting (XSS) in serialize-javascript GHSA-76p7-773f-r4q5 / CVE-2024-11831 6.0.2
ws forms-e2e-smoke-test Medium ws: Uninitialized memory disclosure GHSA-58qx-3vcg-4xpx / CVE-2026-45736 8.20.1
joi forms-engine-plugin Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
uuid forms-engine-plugin Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1
brace-expansion forms-engine-plugin-example-ui Medium brace-expansion: Zero-step sequence causes process hang and memory exhaustion GHSA-f886-m6hf-6m8v / CVE-2026-33750 2.0.3
http-proxy-middleware forms-engine-plugin-example-ui Medium http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass GHSA-64mm-vxmg-q3vj / CVE-2026-55602 2.0.10
ip-address forms-engine-plugin-example-ui Medium ip-address has XSS in Address6 HTML-emitting methods GHSA-v2v4-37r5-5v8g / CVE-2026-42338 10.1.1
joi forms-engine-plugin-example-ui Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-engine-plugin-example-ui Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
js-yaml forms-engine-plugin-example-ui Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 4.2.0
liquidjs forms-engine-plugin-example-ui Medium LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()` GHSA-9x9p-qf8f-mvjg / CVE-2026-44646
liquidjs forms-engine-plugin-example-ui Medium LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body GHSA-8xx9-69p8-7jp3 / CVE-2026-44645
liquidjs forms-engine-plugin-example-ui Medium LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS GHSA-2qv6-9wx5-cwv4 / CVE-2026-44644
liquidjs forms-engine-plugin-example-ui Medium LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read GHSA-v273-448j-v4qj / CVE-2026-39859 10.25.5
liquidjs forms-engine-plugin-example-ui Medium LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel GHSA-rv5g-f82m-qrvv / CVE-2026-39412 10.25.4
picomatch forms-engine-plugin-example-ui Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 2.3.2
picomatch forms-engine-plugin-example-ui Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 4.0.4
serialize-javascript forms-engine-plugin-example-ui Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
undici forms-engine-plugin-example-ui Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 7.28.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 8.5.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 7.28.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 8.5.0
uuid forms-engine-plugin-example-ui Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1
webpack-dev-server forms-engine-plugin-example-ui Medium webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies GHSA-mx8g-39q3-5c79 / CVE-2026-9595 5.2.5
yaml forms-engine-plugin-example-ui Medium yaml is vulnerable to Stack Overflow via deeply nested YAML collections GHSA-48c2-rrv3-qjmp / CVE-2026-33532 2.8.3
joi forms-entitlement-api Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-entitlement-api Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
undici forms-entitlement-api Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 8.5.0
undici forms-entitlement-api Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 8.5.0
js-yaml forms-manager Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
@hapi/inert forms-newls-cwt-listener Medium @hapi/inert has a static-file confinement bypass via sibling-prefix path GHSA-rcvq-m9j9-6f4g / CVE-2026-48049 7.1.1
brace-expansion forms-newls-cwt-listener Medium brace-expansion: Zero-step sequence causes process hang and memory exhaustion GHSA-f886-m6hf-6m8v / CVE-2026-33750 1.1.13
http-proxy-middleware forms-newls-cwt-listener Medium http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass GHSA-64mm-vxmg-q3vj / CVE-2026-55602 2.0.10
ip-address forms-newls-cwt-listener Medium ip-address has XSS in Address6 HTML-emitting methods GHSA-v2v4-37r5-5v8g / CVE-2026-42338 10.1.1
joi forms-newls-cwt-listener Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-newls-cwt-listener Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
liquidjs forms-newls-cwt-listener Medium LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()` GHSA-9x9p-qf8f-mvjg / CVE-2026-44646
liquidjs forms-newls-cwt-listener Medium LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body GHSA-8xx9-69p8-7jp3 / CVE-2026-44645
liquidjs forms-newls-cwt-listener Medium LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS GHSA-2qv6-9wx5-cwv4 / CVE-2026-44644
liquidjs forms-newls-cwt-listener Medium LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read GHSA-v273-448j-v4qj / CVE-2026-39859 10.25.5
liquidjs forms-newls-cwt-listener Medium LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel GHSA-rv5g-f82m-qrvv / CVE-2026-39412 10.25.4
picomatch forms-newls-cwt-listener Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 2.3.2
serialize-javascript forms-newls-cwt-listener Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
undici forms-newls-cwt-listener Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 7.28.0
undici forms-newls-cwt-listener Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 7.28.0
uuid forms-newls-cwt-listener Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1
validator forms-newls-cwt-listener Medium validator.js has a URL validation bypass vulnerability in its isURL function GHSA-9965-vmph-33xx / CVE-2025-56200 13.15.20
webpack-dev-server forms-newls-cwt-listener Medium webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies GHSA-mx8g-39q3-5c79 / CVE-2026-9595 5.2.5
yaml forms-newls-cwt-listener Medium yaml is vulnerable to Stack Overflow via deeply nested YAML collections GHSA-48c2-rrv3-qjmp / CVE-2026-33532 2.8.3
@hapi/inert forms-notify-listener Medium @hapi/inert has a static-file confinement bypass via sibling-prefix path GHSA-rcvq-m9j9-6f4g / CVE-2026-48049 7.1.1
ip-address forms-notify-listener Medium ip-address has XSS in Address6 HTML-emitting methods GHSA-v2v4-37r5-5v8g / CVE-2026-42338 10.1.1
joi forms-notify-listener Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-notify-listener Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
liquidjs forms-notify-listener Medium LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()` GHSA-9x9p-qf8f-mvjg / CVE-2026-44646
liquidjs forms-notify-listener Medium LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body GHSA-8xx9-69p8-7jp3 / CVE-2026-44645
liquidjs forms-notify-listener Medium LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS GHSA-2qv6-9wx5-cwv4 / CVE-2026-44644
liquidjs forms-notify-listener Medium LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read GHSA-v273-448j-v4qj / CVE-2026-39859 10.25.5
liquidjs forms-notify-listener Medium LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel GHSA-rv5g-f82m-qrvv / CVE-2026-39412 10.25.4
joi forms-runner Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
joi forms-runner-acceptance-tests Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-runner-acceptance-tests Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 4.2.0
undici forms-runner-acceptance-tests Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 7.28.0
undici forms-runner-acceptance-tests Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 7.28.0
undici forms-runner-acceptance-tests Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 7.28.0
undici forms-runner-acceptance-tests Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 7.28.0
undici forms-runner-acceptance-tests Medium Undici has CRLF Injection in undici via `upgrade` option GHSA-4992-7rv2-5pvq / CVE-2026-1527 7.24.0
undici forms-runner-acceptance-tests Medium Undici has an HTTP Request/Response Smuggling issue GHSA-2mjp-6q6p-2qxm / CVE-2026-1525 7.24.0
undici forms-runner-acceptance-tests Medium Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion GHSA-g9mf-h72j-4rw9 / CVE-2026-22036 7.18.2
joi forms-runner-tests Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-runner-tests Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 4.2.0
picomatch forms-runner-tests Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 4.0.4
uuid forms-runner-tests Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1
joi forms-sharepoint-listener Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-sharepoint-listener Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
serialize-javascript forms-sharepoint-listener Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
undici forms-sharepoint-listener Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 7.28.0
undici forms-sharepoint-listener Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 7.28.0
uuid forms-sharepoint-listener Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1
brace-expansion forms-smoke-test Medium brace-expansion: Zero-step sequence causes process hang and memory exhaustion GHSA-f886-m6hf-6m8v / CVE-2026-33750 2.0.3
esbuild forms-smoke-test Medium esbuild enables any website to send any requests to the development server and read the response GHSA-67mh-4wv8-2f99 0.25.0
fast-xml-parser forms-smoke-test Medium fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters GHSA-gh4j-gqv2-49f6 / CVE-2026-41650 5.7.0
fast-xml-parser forms-smoke-test Medium Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser GHSA-jp2q-39xq-3w4g / CVE-2026-33349 4.5.5
ip-address forms-smoke-test Medium ip-address has XSS in Address6 HTML-emitting methods GHSA-v2v4-37r5-5v8g / CVE-2026-42338 10.1.1
js-yaml forms-smoke-test Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 4.2.0
lodash forms-smoke-test Medium lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` GHSA-f23m-r3pf-42rh / CVE-2026-2950 4.18.0
picomatch forms-smoke-test Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 2.3.2
serialize-javascript forms-smoke-test Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
undici forms-smoke-test Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 6.27.0
undici forms-smoke-test Medium Undici has CRLF Injection in undici via `upgrade` option GHSA-4992-7rv2-5pvq / CVE-2026-1527 6.24.0
undici forms-smoke-test Medium Undici has an HTTP Request/Response Smuggling issue GHSA-2mjp-6q6p-2qxm / CVE-2026-1525 6.24.0
ws forms-smoke-test Medium ws: Uninitialized memory disclosure GHSA-58qx-3vcg-4xpx / CVE-2026-45736 8.20.1
joi forms-submission-api Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
serialize-javascript forms-submission-api Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
uuid forms-submission-api Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1

Low 44 alerts

Package Repo Severity Advisory ID Fixed in
undici forms-acceptance-tests Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 8.5.0
undici forms-acceptance-tests Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 8.5.0
undici forms-adaptor-template Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 7.28.0
undici forms-adaptor-template Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 7.28.0
undici forms-adaptor-template Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 8.5.0
undici forms-adaptor-template Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 8.5.0
undici forms-adaptor-template Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 8.5.0
undici forms-adaptor-template Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 8.5.0
@babel/core forms-audit-api Low @babel/core: Arbitrary File Read via sourceMappingURL Comment GHSA-4x5r-pxfx-6jf8 / CVE-2026-49356 7.29.6
esbuild forms-audit-api Low esbuild allows arbitrary file read when running the development server on Windows GHSA-g7r4-m6w7-qqqr 0.28.1
esbuild forms-development-tools Low esbuild allows arbitrary file read when running the development server on Windows GHSA-g7r4-m6w7-qqqr 0.28.1
@babel/core forms-e2e-smoke-test Low @babel/core: Arbitrary File Read via sourceMappingURL Comment GHSA-4x5r-pxfx-6jf8 / CVE-2026-49356 7.29.6
@babel/core forms-e2e-smoke-test Low @babel/core: Arbitrary File Read via sourceMappingURL Comment GHSA-4x5r-pxfx-6jf8 / CVE-2026-49356 7.29.6
brace-expansion forms-e2e-smoke-test Low brace-expansion Regular Expression Denial of Service vulnerability GHSA-v6h2-p8h4-qcjw / CVE-2025-5889 2.0.2
diff forms-e2e-smoke-test Low jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch GHSA-73rr-hh4g-fpgx / CVE-2026-24001 5.2.2
tmp forms-e2e-smoke-test Low tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter GHSA-52f5-9888-hmc6 / CVE-2025-54798 0.2.4
esbuild forms-engine-plugin Low esbuild allows arbitrary file read when running the development server on Windows GHSA-g7r4-m6w7-qqqr 0.28.1
esbuild forms-engine-plugin-example-ui Low esbuild allows arbitrary file read when running the development server on Windows GHSA-g7r4-m6w7-qqqr 0.28.1
liquidjs forms-engine-plugin-example-ui Low LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter GHSA-mmg9-6m6j-jqqx / CVE-2026-34166 10.25.3
undici forms-engine-plugin-example-ui Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 7.28.0
undici forms-engine-plugin-example-ui Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 7.28.0
undici forms-engine-plugin-example-ui Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 8.5.0
undici forms-engine-plugin-example-ui Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 8.5.0
esbuild forms-entitlement-api Low esbuild allows arbitrary file read when running the development server on Windows GHSA-g7r4-m6w7-qqqr 0.28.1
undici forms-entitlement-api Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 8.5.0
undici forms-entitlement-api Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 8.5.0
@babel/core forms-newls-cwt-listener Low @babel/core: Arbitrary File Read via sourceMappingURL Comment GHSA-4x5r-pxfx-6jf8 / CVE-2026-49356 7.29.6
liquidjs forms-newls-cwt-listener Low LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter GHSA-mmg9-6m6j-jqqx / CVE-2026-34166 10.25.3
undici forms-newls-cwt-listener Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 7.28.0
undici forms-newls-cwt-listener Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 7.28.0
esbuild forms-notify-listener Low esbuild allows arbitrary file read when running the development server on Windows GHSA-g7r4-m6w7-qqqr 0.28.1
liquidjs forms-notify-listener Low LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter GHSA-mmg9-6m6j-jqqx / CVE-2026-34166 10.25.3
undici forms-runner-acceptance-tests Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 7.28.0
undici forms-runner-acceptance-tests Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 7.28.0
undici forms-runner-acceptance-tests Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 7.28.0
undici forms-runner-acceptance-tests Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 7.28.0
undici forms-runner-acceptance-tests Low undici Denial of Service attack via bad certificate data GHSA-cxrh-j4jr-qwg3 / CVE-2025-47279 7.5.0
undici forms-sharepoint-listener Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 7.28.0
undici forms-sharepoint-listener Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 7.28.0
@babel/core forms-smoke-test Low @babel/core: Arbitrary File Read via sourceMappingURL Comment GHSA-4x5r-pxfx-6jf8 / CVE-2026-49356 7.29.6
@babel/core forms-smoke-test Low @babel/core: Arbitrary File Read via sourceMappingURL Comment GHSA-4x5r-pxfx-6jf8 / CVE-2026-49356 7.29.6
tmp forms-smoke-test Low tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter GHSA-52f5-9888-hmc6 / CVE-2025-54798 0.2.4
undici forms-smoke-test Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 6.27.0
undici forms-smoke-test Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 6.27.0