Skip to main content

DEFRA / forms team

Security

Open Dependabot vulnerability alerts across team repositories.

Last updated 3 minutes ago. Next update in 7 minutes.

708 open vulnerability alerts across team repositories.

Critical 15 alerts

Package Repo Severity Advisory ID Fixed in
basic-ftp forms-adaptor-template Critical Basic FTP has Path Traversal Vulnerability in its downloadToDir() method GHSA-5rq4-664w-9x2c / CVE-2026-27699 5.2.0
liquidjs forms-adaptor-template Critical LiquidJS is Vulnerable to Remote Code Execution GHSA-gf2q-c269-pqgc / CVE-2026-45618 10.26.0
maplibre-gl forms-adaptor-template Critical MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip GHSA-jrc7-96c5-q579 / CVE-2026-85061 6.4.1
maplibre-gl forms-designer Critical MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip GHSA-jrc7-96c5-q579 / CVE-2026-85061 6.4.1
basic-ftp forms-e2e-smoke-test Critical Basic FTP has Path Traversal Vulnerability in its downloadToDir() method GHSA-5rq4-664w-9x2c / CVE-2026-27699 5.2.0
maplibre-gl forms-engine-plugin Critical MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip GHSA-jrc7-96c5-q579 / CVE-2026-85061 6.4.1
liquidjs forms-engine-plugin-example-ui Critical LiquidJS is Vulnerable to Remote Code Execution GHSA-gf2q-c269-pqgc / CVE-2026-45618 10.26.0
maplibre-gl forms-engine-plugin-example-ui Critical MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip GHSA-jrc7-96c5-q579 / CVE-2026-85061 6.4.1
basic-ftp forms-newls-cwt-listener Critical Basic FTP has Path Traversal Vulnerability in its downloadToDir() method GHSA-5rq4-664w-9x2c / CVE-2026-27699 5.2.0
liquidjs forms-newls-cwt-listener Critical LiquidJS is Vulnerable to Remote Code Execution GHSA-gf2q-c269-pqgc / CVE-2026-45618 10.26.0
maplibre-gl forms-newls-cwt-listener Critical MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip GHSA-jrc7-96c5-q579 / CVE-2026-85061 6.4.1
maplibre-gl forms-notify-listener Critical MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip GHSA-jrc7-96c5-q579 / CVE-2026-85061 6.4.1
maplibre-gl forms-runner Critical MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip GHSA-jrc7-96c5-q579 / CVE-2026-85061 6.4.1
maplibre-gl forms-sharepoint-listener Critical MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip GHSA-jrc7-96c5-q579 / CVE-2026-85061 6.4.1
maplibre-gl forms-submission-api Critical MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip GHSA-jrc7-96c5-q579 / CVE-2026-85061 6.4.1

High 366 alerts

Package Repo Severity Advisory ID Fixed in
flatted address-lookup-plugin High Prototype Pollution via parse() in NodeJS flatted GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 3.4.2
js-yaml address-lookup-plugin High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 3.15.2
js-yaml address-lookup-plugin High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
tmp address-lookup-plugin High tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape GHSA-ph9p-34f9-6g65 / CVE-2026-44705 0.2.6
@faker-js/faker forms-acceptance-tests High Faker: helpers.fake exploitable into arbritary code execution GHSA-qxc2-j82w-r537 / CVE-2026-73231 10.5.0
@grpc/grpc-js forms-acceptance-tests High @grpc/grpc-js: A malformed request can cause a server crash GHSA-5375-pq7m-f5r2 / CVE-2026-48068 1.13.5
@grpc/grpc-js forms-acceptance-tests High @grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash GHSA-99f4-grh7-6pcq / CVE-2026-48069 1.13.5
deepmerge-ts forms-acceptance-tests High DeepmergeTS has stack exhaustion when merging recursive object graphs GHSA-ggr8-5vv4-36mx / CVE-2026-40345 8.0.0
extract-zip forms-acceptance-tests High extract-zip allows arbitrary file writes through symlink archive entries GHSA-7pqw-9j4j-h8q3 / CVE-2026-19693
extract-zip forms-acceptance-tests High extract-zip unvalidated symlink path traversal GHSA-jmr9-qjv8-65gv / CVE-2026-56876
js-yaml forms-acceptance-tests High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
serialize-javascript forms-acceptance-tests High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
undici forms-acceptance-tests High undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives GHSA-4cwx-7wf7-3272 / CVE-2026-13697 8.9.0
undici forms-acceptance-tests High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 8.5.0
undici forms-acceptance-tests High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 8.5.0
undici forms-acceptance-tests High undici WebSocket client vulnerable to denial of service via cumulative fragment bypass GHSA-38rv-x7px-6hhq / CVE-2026-9675 8.5.0
basic-ftp forms-adaptor-template High basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering GHSA-rpmf-866q-6p89 / CVE-2026-44240 5.3.1
basic-ftp forms-adaptor-template High basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list() GHSA-rp42-5vxx-qpwr / CVE-2026-41324 5.3.0
basic-ftp forms-adaptor-template High basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands GHSA-6v7q-wjvx-w8wg 5.2.2
brace-expansion forms-adaptor-template High brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation GHSA-rgw5-rvv9-x895 / CVE-2026-69152 1.1.18
brace-expansion forms-adaptor-template High brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation GHSA-rgw5-rvv9-x895 / CVE-2026-69152 2.1.4
brace-expansion forms-adaptor-template High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 2.1.2
brace-expansion forms-adaptor-template High brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash GHSA-mh99-v99m-4gvg / CVE-2026-14257 1.1.17
brace-expansion forms-adaptor-template High brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash GHSA-mh99-v99m-4gvg / CVE-2026-14257 2.1.3
brace-expansion forms-adaptor-template High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
brace-expansion forms-adaptor-template High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
browserslist forms-adaptor-template High Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) GHSA-73wf-gq98-2v4g / CVE-2026-73088 4.28.7
browserslist forms-adaptor-template High Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM GHSA-c83g-rgw3-j3cx / CVE-2026-73089 4.28.7
fast-uri forms-adaptor-template High fast-uri vulnerable to host confusion via percent-encoded scheme normalization GHSA-jqff-g426-hqxp / CVE-2026-76172 3.1.6
fast-uri forms-adaptor-template High fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization GHSA-f65p-4m7j-42xc / CVE-2026-75975 3.1.6
fast-uri forms-adaptor-template High fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding GHSA-fph4-wmhf-6fwf / CVE-2026-75899 3.1.6
fast-uri forms-adaptor-template High fast-uri vulnerable to host confusion via backslash authority introducer GHSA-7p8r-x3mc-p8w7 / CVE-2026-18446 3.1.5
fast-uri forms-adaptor-template High fast-uri vulnerable to host confusion via literal backslash authority delimiter GHSA-v2hh-gcrm-f6hx / CVE-2026-16221 3.1.4
fast-uri forms-adaptor-template High fast-uri vulnerable to host confusion via failed IDN canonicalization GHSA-4c8g-83qw-93j6 / CVE-2026-13676 3.1.3
flatted forms-adaptor-template High Prototype Pollution via parse() in NodeJS flatted GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 3.4.2
image-size forms-adaptor-template High image-size: JXL and HEIF parsers allow denial of service through infinite loops GHSA-5p2g-fcmc-qvqq / CVE-2025-71329
image-size forms-adaptor-template High image-size: ICNS parser allows denial of service through an infinite loop GHSA-w3rx-r6r6-pgpr / CVE-2025-71330
ip-address forms-adaptor-template High ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass GHSA-mwp4-54f8-5fhr / CVE-2026-69192 10.3.1
js-yaml forms-adaptor-template High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-adaptor-template High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 3.15.2
js-yaml forms-adaptor-template High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-adaptor-template High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 3.15.1
js-yaml forms-adaptor-template High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
js-yaml forms-adaptor-template High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 3.15.0
liquidjs forms-adaptor-template High LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process GHSA-4r6h-5v86-94p3 / CVE-2026-69222 10.27.2
liquidjs forms-adaptor-template High LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce GHSA-g357-x5c3-c72p / CVE-2026-55575 10.27.1
liquidjs forms-adaptor-template High LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex GHSA-r7g9-xpmj-5fcq / CVE-2026-45617 10.26.0
liquidjs forms-adaptor-template High LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime) GHSA-hh27-hf48-9f5q / CVE-2026-45357
liquidjs forms-adaptor-template High liquidjs has a Denial of Service via circular block reference in layout GHSA-4rc3-7j7w-m548 / CVE-2026-41311 10.25.7
nanoid forms-adaptor-template High nanoid: custom generators can loop indefinitely when size is zero GHSA-2v37-7h3g-55p8 / CVE-2026-67213 3.3.18
nanoid forms-adaptor-template High nanoid: non-secure generators can loop indefinitely with negative size GHSA-28wg-ghj8-5hjv / CVE-2026-67214 3.3.16
nanoid forms-adaptor-template High nanoid: non-secure generators can loop indefinitely with negative size GHSA-28wg-ghj8-5hjv / CVE-2026-67214 5.1.16
picomatch forms-adaptor-template High Picomatch has a ReDoS vulnerability via extglob quantifiers GHSA-c2c7-rcm5-vvqj / CVE-2026-33671 2.3.2
postcss forms-adaptor-template High PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure GHSA-r28c-9q8g-f849 / CVE-2026-73646 8.5.18
serialize-javascript forms-adaptor-template High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
shell-quote forms-adaptor-template High shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) GHSA-395f-4hp3-45gv / CVE-2026-13311 1.9.0
svgo forms-adaptor-template High SVGO: removeScripts allows executable links through namespace and control-character bypasses GHSA-w27v-7q3p-w38r / CVE-2026-84370 3.3.5
svgo forms-adaptor-template High SVGO removeScripts plugin leaves some executable scripts intact GHSA-2p49-hgcm-8545 / CVE-2026-73650 3.3.4
undici forms-adaptor-template High undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives GHSA-4cwx-7wf7-3272 / CVE-2026-13697 7.29.0
undici forms-adaptor-template High undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives GHSA-4cwx-7wf7-3272 / CVE-2026-13697 8.9.0
undici forms-adaptor-template High undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives GHSA-4cwx-7wf7-3272 / CVE-2026-13697 8.9.0
undici forms-adaptor-template High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 7.28.0
undici forms-adaptor-template High undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse GHSA-hm92-r4w5-c3mj / CVE-2026-6734 7.28.0
undici forms-adaptor-template High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 8.5.0
undici forms-adaptor-template High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 8.5.0
undici forms-adaptor-template High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 7.28.0
undici forms-adaptor-template High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 8.5.0
undici forms-adaptor-template High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 8.5.0
undici forms-adaptor-template High undici WebSocket client vulnerable to denial of service via cumulative fragment bypass GHSA-38rv-x7px-6hhq / CVE-2026-9675 8.5.0
undici forms-adaptor-template High undici WebSocket client vulnerable to denial of service via cumulative fragment bypass GHSA-38rv-x7px-6hhq / CVE-2026-9675 8.5.0
validator forms-adaptor-template High Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements GHSA-vghf-hv5q-vc2g / CVE-2025-12758 13.15.22
fast-uri forms-ai-generator High fast-uri vulnerable to host confusion via percent-encoded scheme normalization GHSA-jqff-g426-hqxp / CVE-2026-76172 3.1.6
fast-uri forms-ai-generator High fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization GHSA-f65p-4m7j-42xc / CVE-2026-75975 3.1.6
fast-uri forms-ai-generator High fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding GHSA-fph4-wmhf-6fwf / CVE-2026-75899 3.1.6
fast-uri forms-ai-generator High fast-uri vulnerable to host confusion via backslash authority introducer GHSA-7p8r-x3mc-p8w7 / CVE-2026-18446 3.1.5
fast-uri forms-ai-generator High fast-uri vulnerable to host confusion via literal backslash authority delimiter GHSA-v2hh-gcrm-f6hx / CVE-2026-16221 3.1.4
fast-uri forms-ai-generator High fast-uri vulnerable to host confusion via failed IDN canonicalization GHSA-4c8g-83qw-93j6 / CVE-2026-13676 3.1.3
hono forms-ai-generator High hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard GHSA-88fw-hqm2-52qc / CVE-2026-54290 4.12.25
ip-address forms-ai-generator High ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass GHSA-mwp4-54f8-5fhr / CVE-2026-69192 10.3.1
brace-expansion forms-audit-api High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 2.1.2
brace-expansion forms-audit-api High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
brace-expansion forms-audit-api High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
ip-address forms-audit-api High ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass GHSA-mwp4-54f8-5fhr / CVE-2026-69192 10.3.1
js-yaml forms-audit-api High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 3.15.2
js-yaml forms-audit-api High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-audit-api High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-audit-api High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 3.15.1
js-yaml forms-audit-api High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
js-yaml forms-audit-api High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 3.15.0
nanoid forms-audit-api High nanoid: Integer Overflow or Wraparound GHSA-xwg4-73v4-xw9w / CVE-2026-73086 5.1.11
nanoid forms-audit-api High nanoid: non-secure generators can loop indefinitely with negative size GHSA-28wg-ghj8-5hjv / CVE-2026-67214 5.1.16
nanoid forms-designer High nanoid: Integer Overflow or Wraparound GHSA-xwg4-73v4-xw9w / CVE-2026-73086 5.1.11
nanoid forms-designer High nanoid: non-secure generators can loop indefinitely with negative size GHSA-28wg-ghj8-5hjv / CVE-2026-67214 5.1.16
nanoid forms-designer High nanoid: custom generators can loop indefinitely when size is zero GHSA-2v37-7h3g-55p8 / CVE-2026-67213 5.1.6
brace-expansion forms-development-tools High brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation GHSA-rgw5-rvv9-x895 / CVE-2026-69152 1.1.18
brace-expansion forms-development-tools High brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash GHSA-mh99-v99m-4gvg / CVE-2026-14257 1.1.17
browserslist forms-development-tools High Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) GHSA-73wf-gq98-2v4g / CVE-2026-73088 4.28.7
browserslist forms-development-tools High Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM GHSA-c83g-rgw3-j3cx / CVE-2026-73089 4.28.7
fast-uri forms-development-tools High fast-uri vulnerable to host confusion via percent-encoded scheme normalization GHSA-jqff-g426-hqxp / CVE-2026-76172 3.1.6
fast-uri forms-development-tools High fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization GHSA-f65p-4m7j-42xc / CVE-2026-75975 3.1.6
fast-uri forms-development-tools High fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references GHSA-5jgf-p345-68v8 / CVE-2026-75931 3.1.6
fast-uri forms-development-tools High fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding GHSA-fph4-wmhf-6fwf / CVE-2026-75899 3.1.6
fast-uri forms-development-tools High fast-uri vulnerable to host confusion via backslash authority introducer GHSA-7p8r-x3mc-p8w7 / CVE-2026-18446 3.1.5
fast-uri forms-development-tools High fast-uri vulnerable to host confusion via literal backslash authority delimiter GHSA-v2hh-gcrm-f6hx / CVE-2026-16221 3.1.4
image-size forms-development-tools High image-size: ICNS parser allows denial of service through an infinite loop GHSA-w3rx-r6r6-pgpr / CVE-2025-71330
image-size forms-development-tools High image-size: JXL and HEIF parsers allow denial of service through infinite loops GHSA-5p2g-fcmc-qvqq / CVE-2025-71329
js-yaml forms-development-tools High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-development-tools High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
nanoid forms-development-tools High nanoid: custom generators can loop indefinitely when size is zero GHSA-2v37-7h3g-55p8 / CVE-2026-67213 3.3.18
postcss forms-development-tools High PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure GHSA-r28c-9q8g-f849 / CVE-2026-73646 8.5.18
serialize-javascript forms-development-tools High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
svgo forms-development-tools High SVGO: removeScripts allows executable links through namespace and control-character bypasses GHSA-w27v-7q3p-w38r / CVE-2026-84370 3.3.5
undici forms-development-tools High undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives GHSA-4cwx-7wf7-3272 / CVE-2026-13697 7.29.0
@babel/plugin-transform-modules-systemjs forms-e2e-smoke-test High @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input GHSA-fv7c-fp4j-7gwp / CVE-2026-44728 7.29.4
basic-ftp forms-e2e-smoke-test High basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering GHSA-rpmf-866q-6p89 / CVE-2026-44240 5.3.1
basic-ftp forms-e2e-smoke-test High basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list() GHSA-rp42-5vxx-qpwr / CVE-2026-41324 5.3.0
basic-ftp forms-e2e-smoke-test High basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands GHSA-6v7q-wjvx-w8wg 5.2.2
brace-expansion forms-e2e-smoke-test High brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation GHSA-rgw5-rvv9-x895 / CVE-2026-69152 1.1.18
brace-expansion forms-e2e-smoke-test High brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation GHSA-rgw5-rvv9-x895 / CVE-2026-69152 2.1.4
brace-expansion forms-e2e-smoke-test High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 2.1.2
brace-expansion forms-e2e-smoke-test High brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash GHSA-mh99-v99m-4gvg / CVE-2026-14257 1.1.17
brace-expansion forms-e2e-smoke-test High brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash GHSA-mh99-v99m-4gvg / CVE-2026-14257 2.1.3
brace-expansion forms-e2e-smoke-test High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
braces forms-e2e-smoke-test High Uncontrolled resource consumption in braces GHSA-grv7-fg5c-xmjg / CVE-2024-4068 3.0.3
browserslist forms-e2e-smoke-test High Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM GHSA-c83g-rgw3-j3cx / CVE-2026-73089 4.28.7
browserslist forms-e2e-smoke-test High Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) GHSA-73wf-gq98-2v4g / CVE-2026-73088 4.28.7
deepmerge-ts forms-e2e-smoke-test High DeepmergeTS has stack exhaustion when merging recursive object graphs GHSA-ggr8-5vv4-36mx / CVE-2026-40345 8.0.0
extract-zip forms-e2e-smoke-test High extract-zip allows arbitrary file writes through symlink archive entries GHSA-7pqw-9j4j-h8q3 / CVE-2026-19693
extract-zip forms-e2e-smoke-test High extract-zip unvalidated symlink path traversal GHSA-jmr9-qjv8-65gv / CVE-2026-56876
flatted forms-e2e-smoke-test High Prototype Pollution via parse() in NodeJS flatted GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 3.4.2
glob forms-e2e-smoke-test High glob CLI: Command injection via -c/--cmd executes matches with shell:true GHSA-5j98-mcp5-4vw2 / CVE-2025-64756 10.5.0
ip-address forms-e2e-smoke-test High ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass GHSA-mwp4-54f8-5fhr / CVE-2026-69192 10.3.1
js-yaml forms-e2e-smoke-test High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-e2e-smoke-test High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-e2e-smoke-test High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
lodash forms-e2e-smoke-test High lodash vulnerable to Code Injection via `_.template` imports key names GHSA-r5fr-rjxr-66jc / CVE-2026-4800 4.18.0
minimatch forms-e2e-smoke-test High minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments GHSA-7r86-cg39-jmmj / CVE-2026-27903 3.1.3
minimatch forms-e2e-smoke-test High minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions GHSA-23c5-xmqv-rm74 / CVE-2026-27904 3.1.4
minimatch forms-e2e-smoke-test High minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments GHSA-7r86-cg39-jmmj / CVE-2026-27903 5.1.8
minimatch forms-e2e-smoke-test High minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions GHSA-23c5-xmqv-rm74 / CVE-2026-27904 5.1.8
minimatch forms-e2e-smoke-test High minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments GHSA-7r86-cg39-jmmj / CVE-2026-27903 9.0.7
minimatch forms-e2e-smoke-test High minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions GHSA-23c5-xmqv-rm74 / CVE-2026-27904 9.0.7
minimatch forms-e2e-smoke-test High minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern GHSA-3ppc-4f35-3m26 / CVE-2026-26996 3.1.3
minimatch forms-e2e-smoke-test High minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern GHSA-3ppc-4f35-3m26 / CVE-2026-26996 5.1.7
minimatch forms-e2e-smoke-test High minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern GHSA-3ppc-4f35-3m26 / CVE-2026-26996 9.0.6
picomatch forms-e2e-smoke-test High Picomatch has a ReDoS vulnerability via extglob quantifiers GHSA-c2c7-rcm5-vvqj / CVE-2026-33671 2.3.2
serialize-javascript forms-e2e-smoke-test High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
tar-fs forms-e2e-smoke-test High tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball GHSA-vj76-c3g6-qr5v / CVE-2025-59343 3.1.1
tar-fs forms-e2e-smoke-test High tar-fs can extract outside the specified dir with a specific tarball GHSA-8cj5-5rvv-wf4v / CVE-2025-48387 3.0.9
tar-fs forms-e2e-smoke-test High tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File GHSA-pq67-2wwv-3xjx / CVE-2024-12905 3.0.7
tmp forms-e2e-smoke-test High tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape GHSA-ph9p-34f9-6g65 / CVE-2026-44705 0.2.6
ws forms-e2e-smoke-test High ws: Memory exhaustion DoS from tiny fragments and data chunks GHSA-96hv-2xvq-fx4p / CVE-2026-48779 8.21.0
ws forms-e2e-smoke-test High ws affected by a DoS when handling a request with many HTTP headers GHSA-3h5v-q93c-6h6q / CVE-2024-37890 8.17.1
brace-expansion forms-engine-plugin High brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation GHSA-rgw5-rvv9-x895 / CVE-2026-69152 2.1.4
browserslist forms-engine-plugin High Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) GHSA-73wf-gq98-2v4g / CVE-2026-73088 4.28.7
fast-uri forms-engine-plugin High fast-uri vulnerable to host confusion via percent-encoded scheme normalization GHSA-jqff-g426-hqxp / CVE-2026-76172 3.1.6
fast-uri forms-engine-plugin High fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization GHSA-f65p-4m7j-42xc / CVE-2026-75975 3.1.6
fast-uri forms-engine-plugin High fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references GHSA-5jgf-p345-68v8 / CVE-2026-75931 3.1.6
fast-uri forms-engine-plugin High fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding GHSA-fph4-wmhf-6fwf / CVE-2026-75899 3.1.6
fast-uri forms-engine-plugin High fast-uri vulnerable to host confusion via backslash authority introducer GHSA-7p8r-x3mc-p8w7 / CVE-2026-18446 3.1.5
ip-address forms-engine-plugin High ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass GHSA-mwp4-54f8-5fhr / CVE-2026-69192 10.3.1
js-yaml forms-engine-plugin High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 3.15.2
js-yaml forms-engine-plugin High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-engine-plugin High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-engine-plugin High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 3.15.1
liquidjs forms-engine-plugin High LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process GHSA-4r6h-5v86-94p3 / CVE-2026-69222 10.27.2
nanoid forms-engine-plugin High nanoid: Integer Overflow or Wraparound GHSA-xwg4-73v4-xw9w / CVE-2026-73086 5.1.11
nanoid forms-engine-plugin High nanoid: non-secure generators can loop indefinitely with negative size GHSA-28wg-ghj8-5hjv / CVE-2026-67214 5.1.16
svgo forms-engine-plugin High SVGO: removeScripts allows executable links through namespace and control-character bypasses GHSA-w27v-7q3p-w38r / CVE-2026-84370 3.3.5
svgo forms-engine-plugin High SVGO: removeScripts allows executable links through namespace and control-character bypasses GHSA-w27v-7q3p-w38r / CVE-2026-84370 4.1.0
undici forms-engine-plugin High undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives GHSA-4cwx-7wf7-3272 / CVE-2026-13697 7.29.0
basic-ftp forms-engine-plugin-example-ui High basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering GHSA-rpmf-866q-6p89 / CVE-2026-44240 5.3.1
basic-ftp forms-engine-plugin-example-ui High basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list() GHSA-rp42-5vxx-qpwr / CVE-2026-41324 5.3.0
basic-ftp forms-engine-plugin-example-ui High basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands GHSA-6v7q-wjvx-w8wg 5.2.2
basic-ftp forms-engine-plugin-example-ui High basic-ftp has FTP Command Injection via CRLF GHSA-chqc-8p9q-pq6q / CVE-2026-39983 5.2.1
brace-expansion forms-engine-plugin-example-ui High brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation GHSA-rgw5-rvv9-x895 / CVE-2026-69152 2.1.4
brace-expansion forms-engine-plugin-example-ui High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 2.1.2
brace-expansion forms-engine-plugin-example-ui High brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash GHSA-mh99-v99m-4gvg / CVE-2026-14257 2.1.3
brace-expansion forms-engine-plugin-example-ui High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
brace-expansion forms-engine-plugin-example-ui High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
browserslist forms-engine-plugin-example-ui High Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) GHSA-73wf-gq98-2v4g / CVE-2026-73088 4.28.7
fast-uri forms-engine-plugin-example-ui High fast-uri vulnerable to host confusion via percent-encoded scheme normalization GHSA-jqff-g426-hqxp / CVE-2026-76172 3.1.6
fast-uri forms-engine-plugin-example-ui High fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization GHSA-f65p-4m7j-42xc / CVE-2026-75975 3.1.6
fast-uri forms-engine-plugin-example-ui High fast-uri vulnerable to path traversal via percent-encoded dot segments GHSA-q3j6-qgpj-74h6 / CVE-2026-6321 3.1.1
fast-uri forms-engine-plugin-example-ui High fast-uri vulnerable to host confusion via percent-encoded authority delimiters GHSA-v39h-62p7-jpjc / CVE-2026-6322 3.1.2
fast-uri forms-engine-plugin-example-ui High fast-uri vulnerable to host confusion via backslash authority introducer GHSA-7p8r-x3mc-p8w7 / CVE-2026-18446 3.1.5
fast-uri forms-engine-plugin-example-ui High fast-uri vulnerable to host confusion via literal backslash authority delimiter GHSA-v2hh-gcrm-f6hx / CVE-2026-16221 3.1.4
fast-uri forms-engine-plugin-example-ui High fast-uri vulnerable to host confusion via failed IDN canonicalization GHSA-4c8g-83qw-93j6 / CVE-2026-13676 3.1.3
flatted forms-engine-plugin-example-ui High Prototype Pollution via parse() in NodeJS flatted GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 3.4.2
immutable forms-engine-plugin-example-ui High Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set GHSA-xvcm-6775-5m9r / CVE-2026-59880 5.1.8
immutable forms-engine-plugin-example-ui High Immutable.js `List` 32-bit trie overflow → unrecoverable DoS GHSA-v56q-mh7h-f735 / CVE-2026-59879 5.1.8
ip-address forms-engine-plugin-example-ui High ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass GHSA-mwp4-54f8-5fhr / CVE-2026-69192 10.3.1
js-yaml forms-engine-plugin-example-ui High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 3.15.2
js-yaml forms-engine-plugin-example-ui High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-engine-plugin-example-ui High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-engine-plugin-example-ui High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 3.15.1
js-yaml forms-engine-plugin-example-ui High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
js-yaml forms-engine-plugin-example-ui High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 3.15.0
liquidjs forms-engine-plugin-example-ui High LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process GHSA-4r6h-5v86-94p3 / CVE-2026-69222 10.27.2
liquidjs forms-engine-plugin-example-ui High LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce GHSA-g357-x5c3-c72p / CVE-2026-55575 10.27.1
liquidjs forms-engine-plugin-example-ui High LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex GHSA-r7g9-xpmj-5fcq / CVE-2026-45617 10.26.0
liquidjs forms-engine-plugin-example-ui High LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime) GHSA-hh27-hf48-9f5q / CVE-2026-45357
liquidjs forms-engine-plugin-example-ui High liquidjs has a Denial of Service via circular block reference in layout GHSA-4rc3-7j7w-m548 / CVE-2026-41311 10.25.7
liquidjs forms-engine-plugin-example-ui High LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates GHSA-56p5-8mhr-2fph / CVE-2026-35525 10.25.3
picomatch forms-engine-plugin-example-ui High Picomatch has a ReDoS vulnerability via extglob quantifiers GHSA-c2c7-rcm5-vvqj / CVE-2026-33671 2.3.2
postcss forms-engine-plugin-example-ui High PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure GHSA-r28c-9q8g-f849 / CVE-2026-73646 8.5.18
shell-quote forms-engine-plugin-example-ui High shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) GHSA-395f-4hp3-45gv / CVE-2026-13311 1.9.0
svgo forms-engine-plugin-example-ui High SVGO: removeScripts allows executable links through namespace and control-character bypasses GHSA-w27v-7q3p-w38r / CVE-2026-84370 4.1.0
svgo forms-engine-plugin-example-ui High SVGO removeScripts plugin leaves some executable scripts intact GHSA-2p49-hgcm-8545 / CVE-2026-73650 4.0.2
undici forms-engine-plugin-example-ui High undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives GHSA-4cwx-7wf7-3272 / CVE-2026-13697 7.29.0
undici forms-engine-plugin-example-ui High undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives GHSA-4cwx-7wf7-3272 / CVE-2026-13697 8.9.0
undici forms-engine-plugin-example-ui High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 8.5.0
undici forms-engine-plugin-example-ui High undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse GHSA-hm92-r4w5-c3mj / CVE-2026-6734 7.28.0
undici forms-engine-plugin-example-ui High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 8.5.0
undici forms-engine-plugin-example-ui High undici WebSocket client vulnerable to denial of service via cumulative fragment bypass GHSA-38rv-x7px-6hhq / CVE-2026-9675 8.5.0
undici forms-engine-plugin-example-ui High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 7.28.0
brace-expansion forms-entitlement-api High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 2.1.2
brace-expansion forms-entitlement-api High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
brace-expansion forms-entitlement-api High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
browserslist forms-entitlement-api High Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) GHSA-73wf-gq98-2v4g / CVE-2026-73088 4.28.7
fast-xml-parser forms-entitlement-api High fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits GHSA-8r6m-32jq-jx6q / CVE-2026-73569 5.10.1
ip-address forms-entitlement-api High ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass GHSA-mwp4-54f8-5fhr / CVE-2026-69192 10.3.1
js-yaml forms-entitlement-api High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-entitlement-api High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 3.15.2
js-yaml forms-entitlement-api High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-entitlement-api High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 3.15.1
js-yaml forms-entitlement-api High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
js-yaml forms-entitlement-api High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 3.15.0
nanoid forms-entitlement-api High nanoid: Integer Overflow or Wraparound GHSA-xwg4-73v4-xw9w / CVE-2026-73086 5.1.11
nanoid forms-entitlement-api High nanoid: non-secure generators can loop indefinitely with negative size GHSA-28wg-ghj8-5hjv / CVE-2026-67214 5.1.16
nanoid forms-entitlement-api High nanoid: custom generators can loop indefinitely when size is zero GHSA-2v37-7h3g-55p8 / CVE-2026-67213 5.1.6
SonarSource/sonarqube-scan-action forms-entitlement-api High Argument injection vulnerability in SonarQube Scan Action GHSA-5xq9-5g24-4g6f / CVE-2025-59844 6.0.0
undici forms-entitlement-api High undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives GHSA-4cwx-7wf7-3272 / CVE-2026-13697 8.9.0
undici forms-entitlement-api High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 8.5.0
undici forms-entitlement-api High undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent GHSA-vmh5-mc38-953g / CVE-2026-9697 8.5.0
undici forms-entitlement-api High undici WebSocket client vulnerable to denial of service via cumulative fragment bypass GHSA-38rv-x7px-6hhq / CVE-2026-9675 8.5.0
js-yaml forms-identity-api High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-identity-api High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 3.15.2
js-yaml forms-identity-api High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-identity-api High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 3.15.1
fast-uri forms-identity-ui High fast-uri vulnerable to host confusion via percent-encoded scheme normalization GHSA-jqff-g426-hqxp / CVE-2026-76172 3.1.6
fast-uri forms-identity-ui High fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization GHSA-f65p-4m7j-42xc / CVE-2026-75975 3.1.6
fast-uri forms-identity-ui High fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding GHSA-fph4-wmhf-6fwf / CVE-2026-75899 3.1.6
fast-uri forms-identity-ui High fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references GHSA-5jgf-p345-68v8 / CVE-2026-75931 3.1.6
fast-uri forms-identity-ui High fast-uri vulnerable to host confusion via backslash authority introducer GHSA-7p8r-x3mc-p8w7 / CVE-2026-18446 3.1.5
js-yaml forms-identity-ui High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-identity-ui High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 3.15.2
js-yaml forms-identity-ui High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-identity-ui High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 3.15.1
svgo forms-identity-ui High SVGO: removeScripts allows executable links through namespace and control-character bypasses GHSA-w27v-7q3p-w38r / CVE-2026-84370 4.1.0
brace-expansion forms-manager High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 2.1.2
brace-expansion forms-manager High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
brace-expansion forms-manager High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
browserslist forms-manager High Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) GHSA-73wf-gq98-2v4g / CVE-2026-73088 4.28.7
fast-xml-parser forms-manager High fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits GHSA-8r6m-32jq-jx6q / CVE-2026-73569 5.10.1
ip-address forms-manager High ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass GHSA-mwp4-54f8-5fhr / CVE-2026-69192 10.3.1
js-yaml forms-manager High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 3.15.2
js-yaml forms-manager High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-manager High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-manager High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 3.15.1
js-yaml forms-manager High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
js-yaml forms-manager High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 3.15.0
nanoid forms-manager High nanoid: Integer Overflow or Wraparound GHSA-xwg4-73v4-xw9w / CVE-2026-73086 5.1.11
nanoid forms-manager High nanoid: non-secure generators can loop indefinitely with negative size GHSA-28wg-ghj8-5hjv / CVE-2026-67214 5.1.16
basic-ftp forms-newls-cwt-listener High basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering GHSA-rpmf-866q-6p89 / CVE-2026-44240 5.3.1
basic-ftp forms-newls-cwt-listener High basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list() GHSA-rp42-5vxx-qpwr / CVE-2026-41324 5.3.0
basic-ftp forms-newls-cwt-listener High basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands GHSA-6v7q-wjvx-w8wg 5.2.2
brace-expansion forms-newls-cwt-listener High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 2.1.2
brace-expansion forms-newls-cwt-listener High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
brace-expansion forms-newls-cwt-listener High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
browserslist forms-newls-cwt-listener High Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) GHSA-73wf-gq98-2v4g / CVE-2026-73088 4.28.7
flatted forms-newls-cwt-listener High Prototype Pollution via parse() in NodeJS flatted GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 3.4.2
ip-address forms-newls-cwt-listener High ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass GHSA-mwp4-54f8-5fhr / CVE-2026-69192 10.3.1
js-yaml forms-newls-cwt-listener High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-newls-cwt-listener High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-newls-cwt-listener High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
liquidjs forms-newls-cwt-listener High LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process GHSA-4r6h-5v86-94p3 / CVE-2026-69222 10.27.2
liquidjs forms-newls-cwt-listener High LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce GHSA-g357-x5c3-c72p / CVE-2026-55575 10.27.1
liquidjs forms-newls-cwt-listener High LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex GHSA-r7g9-xpmj-5fcq / CVE-2026-45617 10.26.0
liquidjs forms-newls-cwt-listener High LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime) GHSA-hh27-hf48-9f5q / CVE-2026-45357
liquidjs forms-newls-cwt-listener High liquidjs has a Denial of Service via circular block reference in layout GHSA-4rc3-7j7w-m548 / CVE-2026-41311 10.25.7
liquidjs forms-newls-cwt-listener High LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates GHSA-56p5-8mhr-2fph / CVE-2026-35525 10.25.3
liquidjs forms-newls-cwt-listener High LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern GHSA-6q5m-63h6-5x4v / CVE-2026-33287
liquidjs forms-newls-cwt-listener High LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash GHSA-9r5m-9576-7f6x / CVE-2026-33285
liquidjs forms-newls-cwt-listener High liquidjs has a path traversal fallback vulnerability GHSA-wmfp-5q7x-987x / CVE-2026-30952 10.25.0
minimatch forms-newls-cwt-listener High minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments GHSA-7r86-cg39-jmmj / CVE-2026-27903 9.0.7
minimatch forms-newls-cwt-listener High minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments GHSA-7r86-cg39-jmmj / CVE-2026-27903 10.2.3
picomatch forms-newls-cwt-listener High Picomatch has a ReDoS vulnerability via extglob quantifiers GHSA-c2c7-rcm5-vvqj / CVE-2026-33671 2.3.2
postcss forms-newls-cwt-listener High PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure GHSA-r28c-9q8g-f849 / CVE-2026-73646 8.5.18
shell-quote forms-newls-cwt-listener High shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) GHSA-395f-4hp3-45gv / CVE-2026-13311 1.9.0
validator forms-newls-cwt-listener High Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements GHSA-vghf-hv5q-vc2g / CVE-2025-12758 13.15.22
browserslist forms-notify-listener High Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) GHSA-73wf-gq98-2v4g / CVE-2026-73088 4.28.7
js-yaml forms-notify-listener High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 3.15.2
js-yaml forms-notify-listener High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-notify-listener High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-notify-listener High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 3.15.1
brace-expansion forms-runner-acceptance-tests High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
brace-expansion forms-runner-acceptance-tests High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
js-yaml forms-runner-acceptance-tests High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-runner-acceptance-tests High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-runner-acceptance-tests High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
nanoid forms-runner-acceptance-tests High nanoid: non-secure generators can loop indefinitely with negative size GHSA-28wg-ghj8-5hjv / CVE-2026-67214 5.1.16
undici forms-runner-acceptance-tests High undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives GHSA-4cwx-7wf7-3272 / CVE-2026-13697 7.29.0
undici forms-runner-acceptance-tests High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 7.28.0
undici forms-runner-acceptance-tests High Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression GHSA-vrm6-8vpv-qv8q / CVE-2026-1526 7.24.0
undici forms-runner-acceptance-tests High Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation GHSA-v9p9-hfj2-hcw8 / CVE-2026-2229 7.24.0
undici forms-runner-acceptance-tests High Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client GHSA-f269-vfmq-vjvj / CVE-2026-1528 7.24.0
brace-expansion forms-runner-tests High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 2.1.2
brace-expansion forms-runner-tests High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
brace-expansion forms-runner-tests High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
flatted forms-runner-tests High Prototype Pollution via parse() in NodeJS flatted GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 3.4.2
js-yaml forms-runner-tests High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-runner-tests High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-runner-tests High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
nanoid forms-runner-tests High nanoid: Integer Overflow or Wraparound GHSA-xwg4-73v4-xw9w / CVE-2026-73086 5.1.11
nanoid forms-runner-tests High nanoid: non-secure generators can loop indefinitely with negative size GHSA-28wg-ghj8-5hjv / CVE-2026-67214 5.1.16
brace-expansion forms-sharepoint-listener High brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation GHSA-rgw5-rvv9-x895 / CVE-2026-69152 2.1.4
brace-expansion forms-sharepoint-listener High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 2.1.2
brace-expansion forms-sharepoint-listener High brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash GHSA-mh99-v99m-4gvg / CVE-2026-14257 2.1.3
brace-expansion forms-sharepoint-listener High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
brace-expansion forms-sharepoint-listener High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 5.0.7
browserslist forms-sharepoint-listener High Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) GHSA-73wf-gq98-2v4g / CVE-2026-73088 4.28.7
ip-address forms-sharepoint-listener High ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass GHSA-mwp4-54f8-5fhr / CVE-2026-69192 10.3.1
js-yaml forms-sharepoint-listener High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-sharepoint-listener High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 3.15.2
js-yaml forms-sharepoint-listener High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-sharepoint-listener High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 3.15.1
js-yaml forms-sharepoint-listener High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
js-yaml forms-sharepoint-listener High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 3.15.0
liquidjs forms-sharepoint-listener High LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process GHSA-4r6h-5v86-94p3 / CVE-2026-69222 10.27.2
@babel/plugin-transform-modules-systemjs forms-smoke-test High @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input GHSA-fv7c-fp4j-7gwp / CVE-2026-44728 7.29.4
basic-ftp forms-smoke-test High basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering GHSA-rpmf-866q-6p89 / CVE-2026-44240 5.3.1
basic-ftp forms-smoke-test High basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list() GHSA-rp42-5vxx-qpwr / CVE-2026-41324 5.3.0
basic-ftp forms-smoke-test High basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands GHSA-6v7q-wjvx-w8wg 5.2.2
basic-ftp forms-smoke-test High basic-ftp has FTP Command Injection via CRLF GHSA-chqc-8p9q-pq6q / CVE-2026-39983 5.2.1
brace-expansion forms-smoke-test High brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation GHSA-rgw5-rvv9-x895 / CVE-2026-69152 1.1.18
brace-expansion forms-smoke-test High brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation GHSA-rgw5-rvv9-x895 / CVE-2026-69152 2.1.4
brace-expansion forms-smoke-test High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 2.1.2
brace-expansion forms-smoke-test High brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash GHSA-mh99-v99m-4gvg / CVE-2026-14257 1.1.17
brace-expansion forms-smoke-test High brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash GHSA-mh99-v99m-4gvg / CVE-2026-14257 2.1.3
brace-expansion forms-smoke-test High brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 1.1.16
browserslist forms-smoke-test High Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM GHSA-c83g-rgw3-j3cx / CVE-2026-73089 4.28.7
browserslist forms-smoke-test High Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) GHSA-73wf-gq98-2v4g / CVE-2026-73088 4.28.7
deepmerge-ts forms-smoke-test High DeepmergeTS has stack exhaustion when merging recursive object graphs GHSA-ggr8-5vv4-36mx / CVE-2026-40345 8.0.0
extract-zip forms-smoke-test High extract-zip allows arbitrary file writes through symlink archive entries GHSA-7pqw-9j4j-h8q3 / CVE-2026-19693
extract-zip forms-smoke-test High extract-zip unvalidated symlink path traversal GHSA-jmr9-qjv8-65gv / CVE-2026-56876
fast-xml-parser forms-smoke-test High fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278) GHSA-8gc5-j5rx-235r / CVE-2026-33036 4.5.5
flatted forms-smoke-test High Prototype Pollution via parse() in NodeJS flatted GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 3.4.2
ip-address forms-smoke-test High ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass GHSA-mwp4-54f8-5fhr / CVE-2026-69192 10.3.1
js-yaml forms-smoke-test High js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources GHSA-2883-xcg3-v3hh / CVE-2026-84375 4.3.2
js-yaml forms-smoke-test High JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported GHSA-5p4m-2wfm-xmqj 4.3.1
js-yaml forms-smoke-test High js-yaml: YAML merge-key chains can force quadratic CPU consumption GHSA-52cp-r559-cp3m / CVE-2026-59869 4.3.0
lodash forms-smoke-test High lodash vulnerable to Code Injection via `_.template` imports key names GHSA-r5fr-rjxr-66jc / CVE-2026-4800 4.18.0
minimatch forms-smoke-test High minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments GHSA-7r86-cg39-jmmj / CVE-2026-27903 3.1.3
minimatch forms-smoke-test High minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions GHSA-23c5-xmqv-rm74 / CVE-2026-27904 3.1.4
minimatch forms-smoke-test High minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern GHSA-3ppc-4f35-3m26 / CVE-2026-26996 3.1.3
picomatch forms-smoke-test High Picomatch has a ReDoS vulnerability via extglob quantifiers GHSA-c2c7-rcm5-vvqj / CVE-2026-33671 2.3.2
serialize-javascript forms-smoke-test High Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GHSA-5c6j-r48x-rmvq 7.0.3
tmp forms-smoke-test High tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape GHSA-ph9p-34f9-6g65 / CVE-2026-44705 0.2.6
undici forms-smoke-test High undici WebSocket client vulnerable to denial of service via fragment count bypass GHSA-vxpw-j846-p89q / CVE-2026-12151 6.27.0
undici forms-smoke-test High Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation GHSA-v9p9-hfj2-hcw8 / CVE-2026-2229 6.24.0
undici forms-smoke-test High Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression GHSA-vrm6-8vpv-qv8q / CVE-2026-1526 6.24.0
undici forms-smoke-test High Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client GHSA-f269-vfmq-vjvj / CVE-2026-1528 6.24.0
ws forms-smoke-test High ws: Memory exhaustion DoS from tiny fragments and data chunks GHSA-96hv-2xvq-fx4p / CVE-2026-48779 8.21.0
SonarSource/sonarqube-scan-action forms-submission-api High Argument injection vulnerability in SonarQube Scan Action GHSA-5xq9-5g24-4g6f / CVE-2025-59844 6.0.0
SonarSource/sonarqube-scan-action forms-submission-api High Argument injection vulnerability in SonarQube Scan Action GHSA-5xq9-5g24-4g6f / CVE-2025-59844 6.0.0

Medium 229 alerts

Package Repo Severity Advisory ID Fixed in
serialize-javascript forms-acceptance-tests Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
undici forms-acceptance-tests Medium undici vulnerable to CRLF Injection via blob-like body 'type' property GHSA-m8rv-5g2x-5cg5 / CVE-2026-15157 8.9.0
undici forms-acceptance-tests Medium undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives GHSA-jr45-8vmc-qm54 / CVE-2026-14643 8.9.0
undici forms-acceptance-tests Medium undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields GHSA-v3r7-h72x-cjcm / CVE-2026-16729 8.9.0
undici forms-acceptance-tests Medium undici vulnerable to downstream response desynchronization via retry interceptor GHSA-8xcm-r25x-g524 / CVE-2026-16728 8.9.0
undici forms-acceptance-tests Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 8.5.0
undici forms-acceptance-tests Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 8.5.0
uuid forms-acceptance-tests Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1
@hapi/inert forms-adaptor-template Medium @hapi/inert has a static-file confinement bypass via sibling-prefix path GHSA-rcvq-m9j9-6f4g / CVE-2026-48049 7.1.1
@humanfs/node forms-adaptor-template Medium humanfs: Recursive copy follows symlinked files and copies data from outside the source tree GHSA-p498-v437-472g 0.16.8
@vitest/mocker forms-adaptor-template Medium Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock GHSA-82fw-gwwq-j7x9 / CVE-2026-84373 4.1.11
baseline-browser-mapping forms-adaptor-template Medium baseline-browser-mapping process termination on invalid input causes denial of service GHSA-w5vr-8v7q-w6rv / CVE-2026-45819 2.11.0
brace-expansion forms-adaptor-template Medium brace-expansion: Zero-step sequence causes process hang and memory exhaustion GHSA-f886-m6hf-6m8v / CVE-2026-33750 1.1.13
colord forms-adaptor-template Medium Colord: Slow rejection of oversized malformed color strings GHSA-2wm5-q62r-hmrv / CVE-2026-85062 2.9.4
http-proxy-middleware forms-adaptor-template Medium http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass GHSA-64mm-vxmg-q3vj / CVE-2026-55602 2.0.10
ip-address forms-adaptor-template Medium ip-address has XSS in Address6 HTML-emitting methods GHSA-v2v4-37r5-5v8g / CVE-2026-42338 10.1.1
joi forms-adaptor-template Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-adaptor-template Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
liquidjs forms-adaptor-template Medium LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()` GHSA-9x9p-qf8f-mvjg / CVE-2026-44646
liquidjs forms-adaptor-template Medium LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body GHSA-8xx9-69p8-7jp3 / CVE-2026-44645
liquidjs forms-adaptor-template Medium LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS GHSA-2qv6-9wx5-cwv4 / CVE-2026-44644
picomatch forms-adaptor-template Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 2.3.2
postcss forms-adaptor-template Medium PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset GHSA-fxqj-rqcc-2cmp / CVE-2026-69153 8.5.23
qs forms-adaptor-template Medium qs: Denial of Service via Attacker Controlled isBuffer GHSA-4mjr-xmp4-gh2g / CVE-2026-82417 6.16.0
qs forms-adaptor-template Medium qs array-limit bypass via bracket-key comma parsing GHSA-x5fp-wj9c-mxmx / CVE-2026-82562 6.16.0
serialize-javascript forms-adaptor-template Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
svgo forms-adaptor-template Medium SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements GHSA-4vpr-x523-8j87 / CVE-2026-84369 3.3.5
undici forms-adaptor-template Medium undici vulnerable to CRLF Injection via blob-like body 'type' property GHSA-m8rv-5g2x-5cg5 / CVE-2026-15157 7.29.0
undici forms-adaptor-template Medium undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives GHSA-jr45-8vmc-qm54 / CVE-2026-14643 7.29.0
undici forms-adaptor-template Medium undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields GHSA-v3r7-h72x-cjcm / CVE-2026-16729 7.29.0
undici forms-adaptor-template Medium undici vulnerable to downstream response desynchronization via retry interceptor GHSA-8xcm-r25x-g524 / CVE-2026-16728 7.29.0
undici forms-adaptor-template Medium undici vulnerable to CRLF Injection via blob-like body 'type' property GHSA-m8rv-5g2x-5cg5 / CVE-2026-15157 8.9.0
undici forms-adaptor-template Medium undici vulnerable to CRLF Injection via blob-like body 'type' property GHSA-m8rv-5g2x-5cg5 / CVE-2026-15157 8.9.0
undici forms-adaptor-template Medium undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives GHSA-jr45-8vmc-qm54 / CVE-2026-14643 8.9.0
undici forms-adaptor-template Medium undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives GHSA-jr45-8vmc-qm54 / CVE-2026-14643 8.9.0
undici forms-adaptor-template Medium undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields GHSA-v3r7-h72x-cjcm / CVE-2026-16729 8.9.0
undici forms-adaptor-template Medium undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields GHSA-v3r7-h72x-cjcm / CVE-2026-16729 8.9.0
undici forms-adaptor-template Medium undici vulnerable to downstream response desynchronization via retry interceptor GHSA-8xcm-r25x-g524 / CVE-2026-16728 8.9.0
undici forms-adaptor-template Medium undici vulnerable to downstream response desynchronization via retry interceptor GHSA-8xcm-r25x-g524 / CVE-2026-16728 8.9.0
undici forms-adaptor-template Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 7.28.0
undici forms-adaptor-template Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 8.5.0
undici forms-adaptor-template Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 8.5.0
undici forms-adaptor-template Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 7.28.0
undici forms-adaptor-template Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 8.5.0
undici forms-adaptor-template Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 8.5.0
uuid forms-adaptor-template Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1
validator forms-adaptor-template Medium validator.js has a URL validation bypass vulnerability in its isURL function GHSA-9965-vmph-33xx / CVE-2025-56200 13.15.20
vitest forms-adaptor-template Medium Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock GHSA-82fw-gwwq-j7x9 / CVE-2026-84373 4.1.11
vitest forms-adaptor-template Medium Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock GHSA-82fw-gwwq-j7x9 / CVE-2026-84373 4.1.11
webpack-dev-server forms-adaptor-template Medium webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header GHSA-m28w-2pqf-7qgj / CVE-2026-14631 5.2.6
webpack-dev-server forms-adaptor-template Medium webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints GHSA-f5vj-f2hx-8m93 / CVE-2026-14620 5.2.6
webpack-dev-server forms-adaptor-template Medium webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies GHSA-mx8g-39q3-5c79 / CVE-2026-9595 5.2.5
yaml forms-adaptor-template Medium yaml is vulnerable to Stack Overflow via deeply nested YAML collections GHSA-48c2-rrv3-qjmp / CVE-2026-33532 2.8.3
@hono/node-server forms-ai-generator Medium Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) GHSA-frvp-7c67-39w9 1.19.15
hono forms-ai-generator Medium Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion GHSA-g6gw-c38x-mqfc / CVE-2026-84364 4.13.5
hono forms-ai-generator Medium Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials GHSA-crvj-82cr-hjcx / CVE-2026-84363 4.13.5
hono forms-ai-generator Medium Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory GHSA-gqvv-2mrq-wpjv / CVE-2026-84365 4.13.5
hono forms-ai-generator Medium Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure GHSA-f23p-vx2j-j53r / CVE-2026-71850 4.12.34
hono forms-ai-generator Medium Hono: Algorithmic Complexity DoS in Language Middleware GHSA-54fx-42gc-7vw4 / CVE-2026-71848 4.12.34
hono forms-ai-generator Medium Hono: ReDoS in CORS middleware via Access-Control-Request-Headers GHSA-8j4g-w8fx-2239 / CVE-2026-69207 4.12.34
hono forms-ai-generator Medium hono/jsx does not isolate context per request, leading to cross-request data disclosure GHSA-hvrm-45r6-mjfj / CVE-2026-59896 4.12.27
hono forms-ai-generator Medium Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility GHSA-w62v-xxxg-mg59 / CVE-2026-59895 4.12.27
hono forms-ai-generator Medium Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication GHSA-xgm2-5f3f-mvvc / CVE-2026-59897 4.12.27
hono forms-ai-generator Medium hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` GHSA-rv63-4mwf-qqc2 / CVE-2026-54288 4.12.25
hono forms-ai-generator Medium hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest GHSA-wgpf-jwqj-8h8p / CVE-2026-54289 4.12.25
hono forms-ai-generator Medium hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) GHSA-wwfh-h76j-fc44 / CVE-2026-54286 4.12.25
hono forms-ai-generator Medium hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice GHSA-j6c9-x7qj-28xf / CVE-2026-54287 4.12.25
ip-address forms-ai-generator Medium ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks GHSA-4xrf-jv44-h6hh / CVE-2026-69198 10.2.2
ip-address forms-ai-generator Medium ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks GHSA-22jq-vg5j-6vgg / CVE-2026-54272 10.2.1
qs forms-ai-generator Medium qs: Denial of Service via Attacker Controlled isBuffer GHSA-4mjr-xmp4-gh2g / CVE-2026-82417 6.16.0
qs forms-ai-generator Medium qs array-limit bypass via bracket-key comma parsing GHSA-x5fp-wj9c-mxmx / CVE-2026-82562 6.16.0
@humanfs/node forms-audit-api Medium humanfs: Recursive copy follows symlinked files and copies data from outside the source tree GHSA-p498-v437-472g 0.16.8
ip-address forms-audit-api Medium ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks GHSA-4xrf-jv44-h6hh / CVE-2026-69198 10.2.2
ip-address forms-audit-api Medium ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks GHSA-22jq-vg5j-6vgg / CVE-2026-54272 10.2.1
joi forms-audit-api Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
joi forms-audit-api Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 18.2.1
js-yaml forms-audit-api Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
js-yaml forms-audit-api Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 4.2.0
colord forms-designer Medium Colord: Slow rejection of oversized malformed color strings GHSA-2wm5-q62r-hmrv / CVE-2026-85062 2.9.4
joi forms-designer Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
react-router forms-designer Medium React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass) GHSA-wrjc-x8rr-h8h6 / CVE-2026-53669 7.18.0
react-router forms-designer Medium React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration GHSA-337j-9hxr-rhxg / CVE-2026-53666 7.18.0
baseline-browser-mapping forms-development-tools Medium baseline-browser-mapping process termination on invalid input causes denial of service GHSA-w5vr-8v7q-w6rv / CVE-2026-45819 2.11.0
colord forms-development-tools Medium Colord: Slow rejection of oversized malformed color strings GHSA-2wm5-q62r-hmrv / CVE-2026-85062 2.9.4
postcss forms-development-tools Medium PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset GHSA-fxqj-rqcc-2cmp / CVE-2026-69153 8.5.23
postcss forms-development-tools Medium PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset GHSA-fxqj-rqcc-2cmp / CVE-2026-69153 8.5.23
qs forms-development-tools Medium qs: Denial of Service via Attacker Controlled isBuffer GHSA-4mjr-xmp4-gh2g / CVE-2026-82417 6.16.0
qs forms-development-tools Medium qs array-limit bypass via bracket-key comma parsing GHSA-x5fp-wj9c-mxmx / CVE-2026-82562 6.16.0
serialize-javascript forms-development-tools Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
svgo forms-development-tools Medium SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements GHSA-4vpr-x523-8j87 / CVE-2026-84369 3.3.5
undici forms-development-tools Medium undici vulnerable to CRLF Injection via blob-like body 'type' property GHSA-m8rv-5g2x-5cg5 / CVE-2026-15157 7.29.0
undici forms-development-tools Medium undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields GHSA-v3r7-h72x-cjcm / CVE-2026-16729 7.29.0
undici forms-development-tools Medium undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives GHSA-jr45-8vmc-qm54 / CVE-2026-14643 7.29.0
undici forms-development-tools Medium undici vulnerable to downstream response desynchronization via retry interceptor GHSA-8xcm-r25x-g524 / CVE-2026-16728 7.29.0
uuid forms-development-tools Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1
@babel/helpers forms-e2e-smoke-test Medium Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups GHSA-968p-4wvh-cqc8 / CVE-2025-27789 7.26.10
@babel/runtime forms-e2e-smoke-test Medium Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups GHSA-968p-4wvh-cqc8 / CVE-2025-27789 7.26.10
brace-expansion forms-e2e-smoke-test Medium brace-expansion: Zero-step sequence causes process hang and memory exhaustion GHSA-f886-m6hf-6m8v / CVE-2026-33750 2.0.3
ejs forms-e2e-smoke-test Medium ejs lacks certain pollution protection GHSA-ghr5-ch3p-vcr6 / CVE-2024-33883 3.1.10
ip-address forms-e2e-smoke-test Medium ip-address has XSS in Address6 HTML-emitting methods GHSA-v2v4-37r5-5v8g / CVE-2026-42338 10.1.1
js-yaml forms-e2e-smoke-test Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 4.2.0
js-yaml forms-e2e-smoke-test Medium js-yaml has prototype pollution in merge (<<) GHSA-mh29-5h37-fv8m / CVE-2025-64718 4.1.1
lodash forms-e2e-smoke-test Medium lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` GHSA-f23m-r3pf-42rh / CVE-2026-2950 4.18.0
lodash forms-e2e-smoke-test Medium Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions GHSA-xxjr-mmjv-4gpg / CVE-2025-13465 4.17.23
micromatch forms-e2e-smoke-test Medium Regular Expression Denial of Service (ReDoS) in micromatch GHSA-952p-6rrq-rcjv / CVE-2024-4067 4.0.8
picomatch forms-e2e-smoke-test Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 2.3.2
serialize-javascript forms-e2e-smoke-test Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
serialize-javascript forms-e2e-smoke-test Medium Cross-site Scripting (XSS) in serialize-javascript GHSA-76p7-773f-r4q5 / CVE-2024-11831 6.0.2
ws forms-e2e-smoke-test Medium ws: Uninitialized memory disclosure GHSA-58qx-3vcg-4xpx / CVE-2026-45736 8.20.1
@humanfs/node forms-engine-plugin Medium humanfs: Recursive copy follows symlinked files and copies data from outside the source tree GHSA-p498-v437-472g 0.16.8
baseline-browser-mapping forms-engine-plugin Medium baseline-browser-mapping process termination on invalid input causes denial of service GHSA-w5vr-8v7q-w6rv / CVE-2026-45819 2.11.0
ip-address forms-engine-plugin Medium ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks GHSA-4xrf-jv44-h6hh / CVE-2026-69198 10.2.2
ip-address forms-engine-plugin Medium ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks GHSA-22jq-vg5j-6vgg / CVE-2026-54272 10.2.1
joi forms-engine-plugin Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
svgo forms-engine-plugin Medium SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements GHSA-4vpr-x523-8j87 / CVE-2026-84369 3.3.5
svgo forms-engine-plugin Medium SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements GHSA-4vpr-x523-8j87 / CVE-2026-84369 4.1.0
undici forms-engine-plugin Medium undici vulnerable to CRLF Injection via blob-like body 'type' property GHSA-m8rv-5g2x-5cg5 / CVE-2026-15157 7.29.0
undici forms-engine-plugin Medium undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields GHSA-v3r7-h72x-cjcm / CVE-2026-16729 7.29.0
undici forms-engine-plugin Medium undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives GHSA-jr45-8vmc-qm54 / CVE-2026-14643 7.29.0
undici forms-engine-plugin Medium undici vulnerable to downstream response desynchronization via retry interceptor GHSA-8xcm-r25x-g524 / CVE-2026-16728 7.29.0
uuid forms-engine-plugin Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1
baseline-browser-mapping forms-engine-plugin-example-ui Medium baseline-browser-mapping process termination on invalid input causes denial of service GHSA-w5vr-8v7q-w6rv / CVE-2026-45819 2.11.0
brace-expansion forms-engine-plugin-example-ui Medium brace-expansion: Zero-step sequence causes process hang and memory exhaustion GHSA-f886-m6hf-6m8v / CVE-2026-33750 2.0.3
ip-address forms-engine-plugin-example-ui Medium ip-address has XSS in Address6 HTML-emitting methods GHSA-v2v4-37r5-5v8g / CVE-2026-42338 10.1.1
joi forms-engine-plugin-example-ui Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-engine-plugin-example-ui Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
js-yaml forms-engine-plugin-example-ui Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 4.2.0
liquidjs forms-engine-plugin-example-ui Medium LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()` GHSA-9x9p-qf8f-mvjg / CVE-2026-44646
liquidjs forms-engine-plugin-example-ui Medium LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body GHSA-8xx9-69p8-7jp3 / CVE-2026-44645
liquidjs forms-engine-plugin-example-ui Medium LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS GHSA-2qv6-9wx5-cwv4 / CVE-2026-44644
liquidjs forms-engine-plugin-example-ui Medium LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read GHSA-v273-448j-v4qj / CVE-2026-39859 10.25.5
liquidjs forms-engine-plugin-example-ui Medium LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel GHSA-rv5g-f82m-qrvv / CVE-2026-39412 10.25.4
picomatch forms-engine-plugin-example-ui Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 2.3.2
picomatch forms-engine-plugin-example-ui Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 4.0.4
postcss forms-engine-plugin-example-ui Medium PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset GHSA-fxqj-rqcc-2cmp / CVE-2026-69153 8.5.23
serialize-javascript forms-engine-plugin-example-ui Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
svgo forms-engine-plugin-example-ui Medium SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements GHSA-4vpr-x523-8j87 / CVE-2026-84369 4.1.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to CRLF Injection via blob-like body 'type' property GHSA-m8rv-5g2x-5cg5 / CVE-2026-15157 7.29.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives GHSA-jr45-8vmc-qm54 / CVE-2026-14643 7.29.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields GHSA-v3r7-h72x-cjcm / CVE-2026-16729 7.29.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to downstream response desynchronization via retry interceptor GHSA-8xcm-r25x-g524 / CVE-2026-16728 7.29.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to CRLF Injection via blob-like body 'type' property GHSA-m8rv-5g2x-5cg5 / CVE-2026-15157 8.9.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives GHSA-jr45-8vmc-qm54 / CVE-2026-14643 8.9.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields GHSA-v3r7-h72x-cjcm / CVE-2026-16729 8.9.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to downstream response desynchronization via retry interceptor GHSA-8xcm-r25x-g524 / CVE-2026-16728 8.9.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 7.28.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 8.5.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 7.28.0
undici forms-engine-plugin-example-ui Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 8.5.0
yaml forms-engine-plugin-example-ui Medium yaml is vulnerable to Stack Overflow via deeply nested YAML collections GHSA-48c2-rrv3-qjmp / CVE-2026-33532 2.8.3
@humanfs/node forms-entitlement-api Medium humanfs: Recursive copy follows symlinked files and copies data from outside the source tree GHSA-p498-v437-472g 0.16.8
baseline-browser-mapping forms-entitlement-api Medium baseline-browser-mapping process termination on invalid input causes denial of service GHSA-w5vr-8v7q-w6rv / CVE-2026-45819 2.11.0
ip-address forms-entitlement-api Medium ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks GHSA-4xrf-jv44-h6hh / CVE-2026-69198 10.2.2
ip-address forms-entitlement-api Medium ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks GHSA-22jq-vg5j-6vgg / CVE-2026-54272 10.2.1
joi forms-entitlement-api Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-entitlement-api Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
undici forms-entitlement-api Medium undici vulnerable to CRLF Injection via blob-like body 'type' property GHSA-m8rv-5g2x-5cg5 / CVE-2026-15157 8.9.0
undici forms-entitlement-api Medium undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives GHSA-jr45-8vmc-qm54 / CVE-2026-14643 8.9.0
undici forms-entitlement-api Medium undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields GHSA-v3r7-h72x-cjcm / CVE-2026-16729 8.9.0
undici forms-entitlement-api Medium undici vulnerable to downstream response desynchronization via retry interceptor GHSA-8xcm-r25x-g524 / CVE-2026-16728 8.9.0
undici forms-entitlement-api Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 8.5.0
undici forms-entitlement-api Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 8.5.0
joi forms-identity-ui Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
svgo forms-identity-ui Medium SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements GHSA-4vpr-x523-8j87 / CVE-2026-84369 4.1.0
@humanfs/node forms-manager Medium humanfs: Recursive copy follows symlinked files and copies data from outside the source tree GHSA-p498-v437-472g 0.16.8
baseline-browser-mapping forms-manager Medium baseline-browser-mapping process termination on invalid input causes denial of service GHSA-w5vr-8v7q-w6rv / CVE-2026-45819 2.11.0
ip-address forms-manager Medium ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks GHSA-4xrf-jv44-h6hh / CVE-2026-69198 10.2.2
ip-address forms-manager Medium ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks GHSA-22jq-vg5j-6vgg / CVE-2026-54272 10.2.1
js-yaml forms-manager Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
@hapi/inert forms-newls-cwt-listener Medium @hapi/inert has a static-file confinement bypass via sibling-prefix path GHSA-rcvq-m9j9-6f4g / CVE-2026-48049 7.1.1
@humanfs/node forms-newls-cwt-listener Medium humanfs: Recursive copy follows symlinked files and copies data from outside the source tree GHSA-p498-v437-472g 0.16.8
@vitest/mocker forms-newls-cwt-listener Medium Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock GHSA-82fw-gwwq-j7x9 / CVE-2026-84373 4.1.11
baseline-browser-mapping forms-newls-cwt-listener Medium baseline-browser-mapping process termination on invalid input causes denial of service GHSA-w5vr-8v7q-w6rv / CVE-2026-45819 2.11.0
ip-address forms-newls-cwt-listener Medium ip-address has XSS in Address6 HTML-emitting methods GHSA-v2v4-37r5-5v8g / CVE-2026-42338 10.1.1
joi forms-newls-cwt-listener Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
liquidjs forms-newls-cwt-listener Medium LiquidJS's `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()` GHSA-9x9p-qf8f-mvjg / CVE-2026-44646
liquidjs forms-newls-cwt-listener Medium LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body GHSA-8xx9-69p8-7jp3 / CVE-2026-44645
liquidjs forms-newls-cwt-listener Medium LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS GHSA-2qv6-9wx5-cwv4 / CVE-2026-44644
liquidjs forms-newls-cwt-listener Medium LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read GHSA-v273-448j-v4qj / CVE-2026-39859 10.25.5
liquidjs forms-newls-cwt-listener Medium LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel GHSA-rv5g-f82m-qrvv / CVE-2026-39412 10.25.4
picomatch forms-newls-cwt-listener Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 2.3.2
postcss forms-newls-cwt-listener Medium PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset GHSA-fxqj-rqcc-2cmp / CVE-2026-69153 8.5.23
validator forms-newls-cwt-listener Medium validator.js has a URL validation bypass vulnerability in its isURL function GHSA-9965-vmph-33xx / CVE-2025-56200 13.15.20
vitest forms-newls-cwt-listener Medium Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock GHSA-82fw-gwwq-j7x9 / CVE-2026-84373 4.1.11
vitest forms-newls-cwt-listener Medium Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock GHSA-82fw-gwwq-j7x9 / CVE-2026-84373 4.1.11
yaml forms-newls-cwt-listener Medium yaml is vulnerable to Stack Overflow via deeply nested YAML collections GHSA-48c2-rrv3-qjmp / CVE-2026-33532 2.8.3
@humanfs/node forms-notify-listener Medium humanfs: Recursive copy follows symlinked files and copies data from outside the source tree GHSA-p498-v437-472g 0.16.8
baseline-browser-mapping forms-notify-listener Medium baseline-browser-mapping process termination on invalid input causes denial of service GHSA-w5vr-8v7q-w6rv / CVE-2026-45819 2.11.0
joi forms-notify-listener Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
joi forms-runner Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
joi forms-runner-acceptance-tests Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-runner-acceptance-tests Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 4.2.0
undici forms-runner-acceptance-tests Medium undici vulnerable to CRLF Injection via blob-like body 'type' property GHSA-m8rv-5g2x-5cg5 / CVE-2026-15157 7.29.0
undici forms-runner-acceptance-tests Medium undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives GHSA-jr45-8vmc-qm54 / CVE-2026-14643 7.29.0
undici forms-runner-acceptance-tests Medium undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields GHSA-v3r7-h72x-cjcm / CVE-2026-16729 7.29.0
undici forms-runner-acceptance-tests Medium undici vulnerable to downstream response desynchronization via retry interceptor GHSA-8xcm-r25x-g524 / CVE-2026-16728 7.29.0
undici forms-runner-acceptance-tests Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 7.28.0
undici forms-runner-acceptance-tests Medium undici vulnerable to cross-user information disclosure via shared cache whitespace bypass GHSA-pr7r-676h-xcf6 / CVE-2026-9678 7.28.0
undici forms-runner-acceptance-tests Medium Undici has CRLF Injection in undici via `upgrade` option GHSA-4992-7rv2-5pvq / CVE-2026-1527 7.24.0
undici forms-runner-acceptance-tests Medium Undici has an HTTP Request/Response Smuggling issue GHSA-2mjp-6q6p-2qxm / CVE-2026-1525 7.24.0
undici forms-runner-acceptance-tests Medium Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion GHSA-g9mf-h72j-4rw9 / CVE-2026-22036 7.18.2
@humanfs/node forms-runner-tests Medium humanfs: Recursive copy follows symlinked files and copies data from outside the source tree GHSA-p498-v437-472g 0.16.8
joi forms-runner-tests Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-runner-tests Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 4.2.0
picomatch forms-runner-tests Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 4.0.4
uuid forms-runner-tests Medium uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided GHSA-w5hq-g745-h8pq / CVE-2026-41907 11.1.1
@humanfs/node forms-sharepoint-listener Medium humanfs: Recursive copy follows symlinked files and copies data from outside the source tree GHSA-p498-v437-472g 0.16.8
baseline-browser-mapping forms-sharepoint-listener Medium baseline-browser-mapping process termination on invalid input causes denial of service GHSA-w5vr-8v7q-w6rv / CVE-2026-45819 2.11.0
ip-address forms-sharepoint-listener Medium ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks GHSA-4xrf-jv44-h6hh / CVE-2026-69198 10.2.2
ip-address forms-sharepoint-listener Medium ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks GHSA-22jq-vg5j-6vgg / CVE-2026-54272 10.2.1
joi forms-sharepoint-listener Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4
js-yaml forms-sharepoint-listener Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 3.15.0
brace-expansion forms-smoke-test Medium brace-expansion: Zero-step sequence causes process hang and memory exhaustion GHSA-f886-m6hf-6m8v / CVE-2026-33750 2.0.3
esbuild forms-smoke-test Medium esbuild enables any website to send any requests to the development server and read the response GHSA-67mh-4wv8-2f99 0.25.0
fast-xml-parser forms-smoke-test Medium fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters GHSA-gh4j-gqv2-49f6 / CVE-2026-41650 5.7.0
fast-xml-parser forms-smoke-test Medium Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser GHSA-jp2q-39xq-3w4g / CVE-2026-33349 4.5.5
ip-address forms-smoke-test Medium ip-address has XSS in Address6 HTML-emitting methods GHSA-v2v4-37r5-5v8g / CVE-2026-42338 10.1.1
js-yaml forms-smoke-test Medium JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases GHSA-h67p-54hq-rp68 / CVE-2026-53550 4.2.0
lodash forms-smoke-test Medium lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` GHSA-f23m-r3pf-42rh / CVE-2026-2950 4.18.0
picomatch forms-smoke-test Medium Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching GHSA-3v7f-55p6-f55p / CVE-2026-33672 2.3.2
serialize-javascript forms-smoke-test Medium Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 7.0.5
undici forms-smoke-test Medium undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields GHSA-v3r7-h72x-cjcm / CVE-2026-16729 6.28.0
undici forms-smoke-test Medium undici vulnerable to CRLF Injection via blob-like body 'type' property GHSA-m8rv-5g2x-5cg5 / CVE-2026-15157 6.28.0
undici forms-smoke-test Medium undici vulnerable to downstream response desynchronization via retry interceptor GHSA-8xcm-r25x-g524 / CVE-2026-16728 6.28.0
undici forms-smoke-test Medium undici vulnerable to HTTP header injection via Set-Cookie percent-decoding GHSA-p88m-4jfj-68fv / CVE-2026-9679 6.27.0
undici forms-smoke-test Medium Undici has CRLF Injection in undici via `upgrade` option GHSA-4992-7rv2-5pvq / CVE-2026-1527 6.24.0
undici forms-smoke-test Medium Undici has an HTTP Request/Response Smuggling issue GHSA-2mjp-6q6p-2qxm / CVE-2026-1525 6.24.0
ws forms-smoke-test Medium ws: Uninitialized memory disclosure GHSA-58qx-3vcg-4xpx / CVE-2026-45736 8.20.1
joi forms-submission-api Medium joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas GHSA-q7cg-457f-vx79 / CVE-2026-48038 17.13.4

Low 98 alerts

Package Repo Severity Advisory ID Fixed in
tmp address-lookup-plugin Low tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter GHSA-52f5-9888-hmc6 / CVE-2025-54798 0.2.4
undici forms-acceptance-tests Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 8.5.0
undici forms-acceptance-tests Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 8.5.0
@hapi/joi forms-adaptor-template Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368
body-parser forms-adaptor-template Low body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement GHSA-v422-hmwv-36x6 / CVE-2026-12590 1.20.6
joi forms-adaptor-template Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
joi forms-adaptor-template Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-adaptor-template Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-adaptor-template Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
postcss-selector-parser forms-adaptor-template Low postcss-selector-parser allows denial of service through uncontrolled AST recursion GHSA-w9m9-85wc-3x92 / CVE-2026-9358 6.1.3
postcss-selector-parser forms-adaptor-template Low postcss-selector-parser allows denial of service through uncontrolled AST recursion GHSA-w9m9-85wc-3x92 / CVE-2026-9358 7.1.3
undici forms-adaptor-template Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 7.28.0
undici forms-adaptor-template Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 7.28.0
undici forms-adaptor-template Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 8.5.0
undici forms-adaptor-template Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 8.5.0
undici forms-adaptor-template Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 8.5.0
undici forms-adaptor-template Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 8.5.0
body-parser forms-ai-generator Low body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement GHSA-v422-hmwv-36x6 / CVE-2026-12590 2.3.0
esbuild forms-ai-generator Low esbuild allows arbitrary file read when running the development server on Windows GHSA-g7r4-m6w7-qqqr 0.28.1
hono forms-ai-generator Low Hono: Proxy Helper does not remove response headers listed in the `Connection` header GHSA-79qm-7rj5-m7r9 / CVE-2026-71849 4.12.34
esbuild forms-audit-api Low esbuild allows arbitrary file read when running the development server on Windows GHSA-g7r4-m6w7-qqqr 0.28.1
joi forms-audit-api Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
joi forms-audit-api Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-audit-api Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 18.2.4
joi forms-audit-api Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 18.2.5
@hapi/joi forms-designer Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368
joi forms-designer Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-designer Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
esbuild forms-development-tools Low esbuild allows arbitrary file read when running the development server on Windows GHSA-g7r4-m6w7-qqqr 0.28.1
joi forms-development-tools Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-development-tools Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
@babel/core forms-e2e-smoke-test Low @babel/core: Arbitrary File Read via sourceMappingURL Comment GHSA-4x5r-pxfx-6jf8 / CVE-2026-49356 7.29.6
@babel/core forms-e2e-smoke-test Low @babel/core: Arbitrary File Read via sourceMappingURL Comment GHSA-4x5r-pxfx-6jf8 / CVE-2026-49356 7.29.6
brace-expansion forms-e2e-smoke-test Low brace-expansion Regular Expression Denial of Service vulnerability GHSA-v6h2-p8h4-qcjw / CVE-2025-5889 2.0.2
diff forms-e2e-smoke-test Low jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch GHSA-73rr-hh4g-fpgx / CVE-2026-24001 5.2.2
tmp forms-e2e-smoke-test Low tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter GHSA-52f5-9888-hmc6 / CVE-2025-54798 0.2.4
@hapi/joi forms-engine-plugin Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368
esbuild forms-engine-plugin Low esbuild allows arbitrary file read when running the development server on Windows GHSA-g7r4-m6w7-qqqr 0.28.1
joi forms-engine-plugin Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-engine-plugin Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
postcss-selector-parser forms-engine-plugin Low postcss-selector-parser allows denial of service through uncontrolled AST recursion GHSA-w9m9-85wc-3x92 / CVE-2026-9358 7.1.3
@hapi/joi forms-engine-plugin-example-ui Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368
esbuild forms-engine-plugin-example-ui Low esbuild allows arbitrary file read when running the development server on Windows GHSA-g7r4-m6w7-qqqr 0.28.1
joi forms-engine-plugin-example-ui Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
joi forms-engine-plugin-example-ui Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
liquidjs forms-engine-plugin-example-ui Low LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter GHSA-mmg9-6m6j-jqqx / CVE-2026-34166 10.25.3
postcss-selector-parser forms-engine-plugin-example-ui Low postcss-selector-parser allows denial of service through uncontrolled AST recursion GHSA-w9m9-85wc-3x92 / CVE-2026-9358 7.1.3
undici forms-engine-plugin-example-ui Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 7.28.0
undici forms-engine-plugin-example-ui Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 7.28.0
undici forms-engine-plugin-example-ui Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 8.5.0
undici forms-engine-plugin-example-ui Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 8.5.0
esbuild forms-entitlement-api Low esbuild allows arbitrary file read when running the development server on Windows GHSA-g7r4-m6w7-qqqr 0.28.1
joi forms-entitlement-api Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
joi forms-entitlement-api Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
joi forms-entitlement-api Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-entitlement-api Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
undici forms-entitlement-api Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 8.5.0
undici forms-entitlement-api Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 8.5.0
joi forms-identity-api Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-identity-api Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
joi forms-identity-api Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 18.2.5
joi forms-identity-api Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 18.2.4
@hapi/joi forms-identity-ui Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368
joi forms-identity-ui Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-identity-ui Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
joi forms-manager Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-manager Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
@babel/core forms-newls-cwt-listener Low @babel/core: Arbitrary File Read via sourceMappingURL Comment GHSA-4x5r-pxfx-6jf8 / CVE-2026-49356 7.29.6
@hapi/joi forms-newls-cwt-listener Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368
joi forms-newls-cwt-listener Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-newls-cwt-listener Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
joi forms-newls-cwt-listener Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-newls-cwt-listener Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
liquidjs forms-newls-cwt-listener Low LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter GHSA-mmg9-6m6j-jqqx / CVE-2026-34166 10.25.3
@hapi/joi forms-notify-listener Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368
joi forms-notify-listener Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-notify-listener Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
@hapi/joi forms-runner Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368
joi forms-runner Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-runner Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
joi forms-runner-acceptance-tests Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
joi forms-runner-acceptance-tests Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
undici forms-runner-acceptance-tests Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 7.28.0
undici forms-runner-acceptance-tests Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 7.28.0
undici forms-runner-acceptance-tests Low undici Denial of Service attack via bad certificate data GHSA-cxrh-j4jr-qwg3 / CVE-2025-47279 7.5.0
joi forms-runner-tests Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
joi forms-runner-tests Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
@hapi/joi forms-sharepoint-listener Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368
joi forms-sharepoint-listener Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-sharepoint-listener Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5
@babel/core forms-smoke-test Low @babel/core: Arbitrary File Read via sourceMappingURL Comment GHSA-4x5r-pxfx-6jf8 / CVE-2026-49356 7.29.6
@babel/core forms-smoke-test Low @babel/core: Arbitrary File Read via sourceMappingURL Comment GHSA-4x5r-pxfx-6jf8 / CVE-2026-49356 7.29.6
tmp forms-smoke-test Low tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter GHSA-52f5-9888-hmc6 / CVE-2025-54798 0.2.4
undici forms-smoke-test Low undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching GHSA-g8m3-5g58-fq7m / CVE-2026-11525 6.27.0
undici forms-smoke-test Low undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse GHSA-35p6-xmwp-9g52 / CVE-2026-6733 6.27.0
@hapi/joi forms-submission-api Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368
joi forms-submission-api Low joi: Prototype pollution via a `__proto__` language key in custom messages GHSA-6w3j-5fw6-r9vr / CVE-2026-84368 17.13.6
joi forms-submission-api Low joi: object().rename() with a template target can set the validated object's prototype GHSA-gg4h-3hg2-grpc / CVE-2026-84367 17.13.5