<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>OpenJS Foundation CVE Numbering Authority - Security Advisories</title>
    <description>The OpenJS Foundation&apos;s CVE Numbering Authority (CNA)</description>
    <link>https://cna.openjsf.org/security-advisories.html</link>
    <atom:link href="https://cna.openjsf.org/feed.xml" rel="self" type="application/rss+xml"/>
    <language>en</language>
    <lastBuildDate>Wed, 17 Jun 2026 17:32:27 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-11525: undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m</link>
      <guid isPermaLink="false">CVE-2026-11525::undici</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <description>undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching in undici. CVE: CVE-2026-11525. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m</description>
    </item>
    <item>
      <title>CVE-2026-6733: undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52</link>
      <guid isPermaLink="false">CVE-2026-6733::undici</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <description>undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse in undici. CVE: CVE-2026-6733. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52</description>
    </item>
    <item>
      <title>CVE-2026-9678: undici vulnerable to cross-user information disclosure via shared cache whitespace bypass</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6</link>
      <guid isPermaLink="false">CVE-2026-9678::undici</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <description>undici vulnerable to cross-user information disclosure via shared cache whitespace bypass in undici. CVE: CVE-2026-9678. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6</description>
    </item>
    <item>
      <title>CVE-2026-9679: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv</link>
      <guid isPermaLink="false">CVE-2026-9679::undici</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <description>undici vulnerable to HTTP header injection via Set-Cookie percent-decoding in undici. CVE: CVE-2026-9679. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv</description>
    </item>
    <item>
      <title>CVE-2026-9697: undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g</link>
      <guid isPermaLink="false">CVE-2026-9697::undici</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <description>undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent in undici. CVE: CVE-2026-9697. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g</description>
    </item>
    <item>
      <title>CVE-2026-6734: undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj</link>
      <guid isPermaLink="false">CVE-2026-6734::undici</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <description>undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse in undici. CVE: CVE-2026-6734. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj</description>
    </item>
    <item>
      <title>CVE-2026-9675: undici WebSocket client vulnerable to denial of service via cumulative fragment bypass</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-38rv-x7px-6hhq</link>
      <guid isPermaLink="false">CVE-2026-9675::undici</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <description>undici WebSocket client vulnerable to denial of service via cumulative fragment bypass in undici. CVE: CVE-2026-9675. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-38rv-x7px-6hhq</description>
    </item>
    <item>
      <title>CVE-2026-12151: undici WebSocket client vulnerable to denial of service via fragment count bypass</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q</link>
      <guid isPermaLink="false">CVE-2026-12151::undici</guid>
      <pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
      <description>undici WebSocket client vulnerable to denial of service via fragment count bypass in undici. CVE: CVE-2026-12151. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q</description>
    </item>
    <item>
      <title>CVE-2026-9595: webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies</title>
      <link>https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79</link>
      <guid isPermaLink="false">CVE-2026-9595::webpack-dev-server</guid>
      <pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate>
      <description>webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies in webpack-dev-server. CVE: CVE-2026-9595. Advisory: https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79</description>
    </item>
    <item>
      <title>CVE-2026-5038: multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads</title>
      <link>https://github.com/expressjs/multer/security/advisories/GHSA-3p4h-7m6x-2hcm</link>
      <guid isPermaLink="false">CVE-2026-5038::multer</guid>
      <pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate>
      <description>multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads in multer. CVE: CVE-2026-5038. Advisory: https://github.com/expressjs/multer/security/advisories/GHSA-3p4h-7m6x-2hcm</description>
    </item>
    <item>
      <title>CVE-2026-5079: multer vulnerable to Denial of Service via deeply nested field names</title>
      <link>https://github.com/expressjs/multer/security/advisories/GHSA-72gw-mp4g-v24j</link>
      <guid isPermaLink="false">CVE-2026-5079::multer</guid>
      <pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate>
      <description>multer vulnerable to Denial of Service via deeply nested field names in multer. CVE: CVE-2026-5079. Advisory: https://github.com/expressjs/multer/security/advisories/GHSA-72gw-mp4g-v24j</description>
    </item>
    <item>
      <title>CVE-2026-10796: nvm vulnerable to OS command injection via crafted version strings from a malicious Node.js mirror</title>
      <link>https://github.com/nvm-sh/nvm/security/advisories/GHSA-3c52-35h2-gfmm</link>
      <guid isPermaLink="false">CVE-2026-10796::nvm</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate>
      <description>nvm vulnerable to OS command injection via crafted version strings from a malicious Node.js mirror in nvm. CVE: CVE-2026-10796. Advisory: https://github.com/nvm-sh/nvm/security/advisories/GHSA-3c52-35h2-gfmm</description>
    </item>
    <item>
      <title>CVE-2026-5078: morgan vulnerable to Log Forging via unneutralized control characters in :remote-user</title>
      <link>https://github.com/expressjs/morgan/security/advisories/GHSA-4vj7-5mj6-jm8m</link>
      <guid isPermaLink="false">CVE-2026-5078::morgan</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate>
      <description>morgan vulnerable to Log Forging via unneutralized control characters in :remote-user in morgan. CVE: CVE-2026-5078. Advisory: https://github.com/expressjs/morgan/security/advisories/GHSA-4vj7-5mj6-jm8m</description>
    </item>
    <item>
      <title>CVE-2026-8162: multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing</title>
      <link>https://github.com/pillarjs/multiparty/security/advisories/GHSA-xh3c-6gcq-g4rv</link>
      <guid isPermaLink="false">CVE-2026-8162::multiparty</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 +0000</pubDate>
      <description>multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing in multiparty. CVE: CVE-2026-8162. Advisory: https://github.com/pillarjs/multiparty/security/advisories/GHSA-xh3c-6gcq-g4rv</description>
    </item>
    <item>
      <title>CVE-2026-8161: multiparty vulnerable to Denial of Service via Prototype Pollution leading to Uncaught Exception</title>
      <link>https://github.com/pillarjs/multiparty/security/advisories/GHSA-qxch-whhj-8956</link>
      <guid isPermaLink="false">CVE-2026-8161::multiparty</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 +0000</pubDate>
      <description>multiparty vulnerable to Denial of Service via Prototype Pollution leading to Uncaught Exception in multiparty. CVE: CVE-2026-8161. Advisory: https://github.com/pillarjs/multiparty/security/advisories/GHSA-qxch-whhj-8956</description>
    </item>
    <item>
      <title>CVE-2026-8159: multiparty vulnerable to ReDoS via filename parsing</title>
      <link>https://github.com/pillarjs/multiparty/security/advisories/GHSA-65x3-rw7q-gx94</link>
      <guid isPermaLink="false">CVE-2026-8159::multiparty</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 +0000</pubDate>
      <description>multiparty vulnerable to ReDoS via filename parsing in multiparty. CVE: CVE-2026-8159. Advisory: https://github.com/pillarjs/multiparty/security/advisories/GHSA-65x3-rw7q-gx94</description>
    </item>
    <item>
      <title>CVE-2026-6402: webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins</title>
      <link>https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-79cf-xcqc-c78w</link>
      <guid isPermaLink="false">CVE-2026-6402::webpack-dev-server</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 +0000</pubDate>
      <description>webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins in webpack-dev-server. CVE: CVE-2026-6402. Advisory: https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-79cf-xcqc-c78w</description>
    </item>
    <item>
      <title>CVE-2026-6322: fast-uri vulnerable to host confusion via percent-encoded authority delimiters</title>
      <link>https://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc</link>
      <guid isPermaLink="false">CVE-2026-6322::fast-uri</guid>
      <pubDate>Tue, 05 May 2026 00:00:00 +0000</pubDate>
      <description>fast-uri vulnerable to host confusion via percent-encoded authority delimiters in fast-uri. CVE: CVE-2026-6322. Advisory: https://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc</description>
    </item>
    <item>
      <title>CVE-2026-6321: fast-uri vulnerable to path traversal via percent-encoded dot segments</title>
      <link>https://github.com/fastify/fast-uri/security/advisories/GHSA-q3j6-qgpj-74h6</link>
      <guid isPermaLink="false">CVE-2026-6321::fast-uri</guid>
      <pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate>
      <description>fast-uri vulnerable to path traversal via percent-encoded dot segments in fast-uri. CVE: CVE-2026-6321. Advisory: https://github.com/fastify/fast-uri/security/advisories/GHSA-q3j6-qgpj-74h6</description>
    </item>
    <item>
      <title>CVE-2026-7768: @fastify/accepts-serializer vulnerable to Denial of Service via Unbounded Accept Header Cache Growth</title>
      <link>https://github.com/fastify/fastify-accepts-serializer/security/advisories/GHSA-qxhc-wx3p-2wmg</link>
      <guid isPermaLink="false">CVE-2026-7768::@fastify/accepts-serializer</guid>
      <pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate>
      <description>@fastify/accepts-serializer vulnerable to Denial of Service via Unbounded Accept Header Cache Growth in @fastify/accepts-serializer. CVE: CVE-2026-7768. Advisory: https://github.com/fastify/fastify-accepts-serializer/security/advisories/GHSA-qxhc-wx3p-2wmg</description>
    </item>
    <item>
      <title>CVE-2026-33804: @fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option</title>
      <link>https://github.com/fastify/middie/security/advisories/GHSA-v9ww-2j6r-98q6</link>
      <guid isPermaLink="false">CVE-2026-33804::@fastify/middie</guid>
      <pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate>
      <description>@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option in @fastify/middie. CVE: CVE-2026-33804. Advisory: https://github.com/fastify/middie/security/advisories/GHSA-v9ww-2j6r-98q6</description>
    </item>
    <item>
      <title>CVE-2026-6270: @fastify/middie vulnerable to middleware authentication bypass in child plugin scopes</title>
      <link>https://github.com/fastify/middie/security/advisories/GHSA-72c6-fx6q-fr5w</link>
      <guid isPermaLink="false">CVE-2026-6270::@fastify/middie</guid>
      <pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate>
      <description>@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes in @fastify/middie. CVE: CVE-2026-6270. Advisory: https://github.com/fastify/middie/security/advisories/GHSA-72c6-fx6q-fr5w</description>
    </item>
    <item>
      <title>CVE-2026-6410: @fastify/static vulnerable to path traversal in directory listing</title>
      <link>https://github.com/fastify/fastify-static/security/advisories/GHSA-pr96-94w5-mx2h</link>
      <guid isPermaLink="false">CVE-2026-6410::@fastify/static</guid>
      <pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate>
      <description>@fastify/static vulnerable to path traversal in directory listing in @fastify/static. CVE: CVE-2026-6410. Advisory: https://github.com/fastify/fastify-static/security/advisories/GHSA-pr96-94w5-mx2h</description>
    </item>
    <item>
      <title>CVE-2026-6414: @fastify/static vulnerable to route guard bypass via encoded path separators</title>
      <link>https://github.com/fastify/fastify-static/security/advisories/GHSA-x428-ghpx-8j92</link>
      <guid isPermaLink="false">CVE-2026-6414::@fastify/static</guid>
      <pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate>
      <description>@fastify/static vulnerable to route guard bypass via encoded path separators in @fastify/static. CVE: CVE-2026-6414. Advisory: https://github.com/fastify/fastify-static/security/advisories/GHSA-x428-ghpx-8j92</description>
    </item>
    <item>
      <title>CVE-2026-33805: @fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headers</title>
      <link>https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-gwhp-pf74-vj37</link>
      <guid isPermaLink="false">CVE-2026-33805::@fastify/reply-from</guid>
      <pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate>
      <description>@fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headers in @fastify/reply-from. CVE: CVE-2026-33805. Advisory: https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-gwhp-pf74-vj37</description>
    </item>
    <item>
      <title>CVE-2026-33805: @fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headers</title>
      <link>https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-gwhp-pf74-vj37</link>
      <guid isPermaLink="false">CVE-2026-33805::@fastify/http-proxy</guid>
      <pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate>
      <description>@fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headers in @fastify/http-proxy. CVE: CVE-2026-33805. Advisory: https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-gwhp-pf74-vj37</description>
    </item>
    <item>
      <title>CVE-2026-33807: @fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes</title>
      <link>https://github.com/fastify/fastify-express/security/advisories/GHSA-hrwm-hgmj-7p9c</link>
      <guid isPermaLink="false">CVE-2026-33807::@fastify/express</guid>
      <pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate>
      <description>@fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes in @fastify/express. CVE: CVE-2026-33807. Advisory: https://github.com/fastify/fastify-express/security/advisories/GHSA-hrwm-hgmj-7p9c</description>
    </item>
    <item>
      <title>CVE-2026-33808: @fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)</title>
      <link>https://github.com/fastify/fastify-express/security/advisories/GHSA-6hw5-45gm-fj88</link>
      <guid isPermaLink="false">CVE-2026-33808::@fastify/express</guid>
      <pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate>
      <description>@fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons) in @fastify/express. CVE: CVE-2026-33808. Advisory: https://github.com/fastify/fastify-express/security/advisories/GHSA-6hw5-45gm-fj88</description>
    </item>
    <item>
      <title>CVE-2026-33806: fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header</title>
      <link>https://github.com/fastify/fastify/security/advisories/GHSA-247c-9743-5963</link>
      <guid isPermaLink="false">CVE-2026-33806::fastify</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate>
      <description>fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header in fastify. CVE: CVE-2026-33806. Advisory: https://github.com/fastify/fastify/security/advisories/GHSA-247c-9743-5963</description>
    </item>
    <item>
      <title>CVE-2026-4800: Incomplete fix for CVE-2021-23337 allows code injection via _.template imports key names</title>
      <link>https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc</link>
      <guid isPermaLink="false">CVE-2026-4800::lodash</guid>
      <pubDate>Tue, 31 Mar 2026 00:00:00 +0000</pubDate>
      <description>Incomplete fix for CVE-2021-23337 allows code injection via _.template imports key names in lodash. CVE: CVE-2026-4800. Advisory: https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc</description>
    </item>
    <item>
      <title>CVE-2026-2950: lodash vulnerable to Prototype Pollution via array path bypass in _.unset and _.omit</title>
      <link>https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh</link>
      <guid isPermaLink="false">CVE-2026-2950::lodash</guid>
      <pubDate>Tue, 31 Mar 2026 00:00:00 +0000</pubDate>
      <description>lodash vulnerable to Prototype Pollution via array path bypass in _.unset and _.omit in lodash. CVE: CVE-2026-2950. Advisory: https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh</description>
    </item>
    <item>
      <title>CVE-2026-4926: path-to-regexp vulnerable to Denial of Service via sequential optional groups</title>
      <link>https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-j3q9-mxjg-w52f</link>
      <guid isPermaLink="false">CVE-2026-4926::path-to-regexp</guid>
      <pubDate>Thu, 26 Mar 2026 00:00:00 +0000</pubDate>
      <description>path-to-regexp vulnerable to Denial of Service via sequential optional groups in path-to-regexp. CVE: CVE-2026-4926. Advisory: https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-j3q9-mxjg-w52f</description>
    </item>
    <item>
      <title>CVE-2026-4923: ReDoS possible with multiple wildcards</title>
      <link>https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-27v5-c462-wpq7</link>
      <guid isPermaLink="false">CVE-2026-4923::path-to-regexp</guid>
      <pubDate>Thu, 26 Mar 2026 00:00:00 +0000</pubDate>
      <description>ReDoS possible with multiple wildcards in path-to-regexp. CVE: CVE-2026-4923. Advisory: https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-27v5-c462-wpq7</description>
    </item>
    <item>
      <title>CVE-2026-4867: path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters</title>
      <link>https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-37ch-88jc-xwx2</link>
      <guid isPermaLink="false">CVE-2026-4867::path-to-regexp</guid>
      <pubDate>Thu, 26 Mar 2026 00:00:00 +0000</pubDate>
      <description>path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters in path-to-regexp. CVE: CVE-2026-4867. Advisory: https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-37ch-88jc-xwx2</description>
    </item>
    <item>
      <title>CVE-2026-3635: Fastify request.protocol and request.host spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust function</title>
      <link>https://github.com/fastify/fastify/security/advisories/GHSA-444r-cwp2-x5xf</link>
      <guid isPermaLink="false">CVE-2026-3635::fastify</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate>
      <description>Fastify request.protocol and request.host spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust function in fastify. CVE: CVE-2026-3635. Advisory: https://github.com/fastify/fastify/security/advisories/GHSA-444r-cwp2-x5xf</description>
    </item>
    <item>
      <title>CVE-2026-2581: Unbounded Memory Consumption in Undici&apos;s DeduplicationHandler via Response Buffering leads to DoS</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-phc3-fgpg-7m6h</link>
      <guid isPermaLink="false">CVE-2026-2581::undici</guid>
      <pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate>
      <description>Unbounded Memory Consumption in Undici&apos;s DeduplicationHandler via Response Buffering leads to DoS in undici. CVE: CVE-2026-2581. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-phc3-fgpg-7m6h</description>
    </item>
    <item>
      <title>CVE-2026-1527: CRLF Injection in undici via upgrade option</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-4992-7rv2-5pvq</link>
      <guid isPermaLink="false">CVE-2026-1527::undici</guid>
      <pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate>
      <description>CRLF Injection in undici via upgrade option in undici. CVE: CVE-2026-1527. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-4992-7rv2-5pvq</description>
    </item>
    <item>
      <title>CVE-2026-1528: Malicious WebSocket 64-bit length overflows undici parser and crashes the client</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvj</link>
      <guid isPermaLink="false">CVE-2026-1528::undici</guid>
      <pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate>
      <description>Malicious WebSocket 64-bit length overflows undici parser and crashes the client in undici. CVE: CVE-2026-1528. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvj</description>
    </item>
    <item>
      <title>CVE-2026-2229: Unhandled Exception in undici WebSocket Client Due to Invalid server_max_window_bits Validation</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8</link>
      <guid isPermaLink="false">CVE-2026-2229::undici</guid>
      <pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate>
      <description>Unhandled Exception in undici WebSocket Client Due to Invalid server_max_window_bits Validation in undici. CVE: CVE-2026-2229. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8</description>
    </item>
    <item>
      <title>CVE-2026-1526: Unbounded Memory Consumption in undici WebSocket permessage-deflate Decompression</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-vrm6-8vpv-qv8q</link>
      <guid isPermaLink="false">CVE-2026-1526::undici</guid>
      <pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate>
      <description>Unbounded Memory Consumption in undici WebSocket permessage-deflate Decompression in undici. CVE: CVE-2026-1526. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-vrm6-8vpv-qv8q</description>
    </item>
    <item>
      <title>CVE-2026-1525: Inconsistent Interpretation of HTTP Requests (HTTP Request/Response Smuggling) in undici</title>
      <link>https://github.com/nodejs/undici/security/advisories/GHSA-2mjp-6q6p-2qxm</link>
      <guid isPermaLink="false">CVE-2026-1525::undici</guid>
      <pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate>
      <description>Inconsistent Interpretation of HTTP Requests (HTTP Request/Response Smuggling) in undici in undici. CVE: CVE-2026-1525. Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-2mjp-6q6p-2qxm</description>
    </item>
    <item>
      <title>CVE-2026-3419: Fastify vulnerable to missing end anchor in subtypeNameReg Allows Malformed Content-Types to Pass Validation</title>
      <link>https://github.com/fastify/fastify/security/advisories/GHSA-573f-x89g-hqp9</link>
      <guid isPermaLink="false">CVE-2026-3419::fastify</guid>
      <pubDate>Thu, 05 Mar 2026 00:00:00 +0000</pubDate>
      <description>Fastify vulnerable to missing end anchor in subtypeNameReg Allows Malformed Content-Types to Pass Validation in fastify. CVE: CVE-2026-3419. Advisory: https://github.com/fastify/fastify/security/advisories/GHSA-573f-x89g-hqp9</description>
    </item>
    <item>
      <title>CVE-2026-3520: Multer vulnerable to Denial of Service via uncontrolled recursion</title>
      <link>https://github.com/expressjs/multer/security/advisories/GHSA-5528-5vmv-3xc2</link>
      <guid isPermaLink="false">CVE-2026-3520::multer</guid>
      <pubDate>Wed, 04 Mar 2026 00:00:00 +0000</pubDate>
      <description>Multer vulnerable to Denial of Service via uncontrolled recursion in multer. CVE: CVE-2026-3520. Advisory: https://github.com/expressjs/multer/security/advisories/GHSA-5528-5vmv-3xc2</description>
    </item>
    <item>
      <title>CVE-2026-2880: @fastify/middie has an improper path normalization vulnerability</title>
      <link>https://github.com/fastify/middie/security/advisories/GHSA-8p85-9qpw-fwgw</link>
      <guid isPermaLink="false">CVE-2026-2880::@fastify/middie</guid>
      <pubDate>Fri, 27 Feb 2026 00:00:00 +0000</pubDate>
      <description>@fastify/middie has an improper path normalization vulnerability in @fastify/middie. CVE: CVE-2026-2880. Advisory: https://github.com/fastify/middie/security/advisories/GHSA-8p85-9qpw-fwgw</description>
    </item>
    <item>
      <title>CVE-2026-3304: Multer vulnerable to Denial of Service via incomplete cleanup</title>
      <link>https://github.com/expressjs/multer/security/advisories/GHSA-xf7r-hgr6-v32p</link>
      <guid isPermaLink="false">CVE-2026-3304::multer</guid>
      <pubDate>Fri, 27 Feb 2026 00:00:00 +0000</pubDate>
      <description>Multer vulnerable to Denial of Service via incomplete cleanup in multer. CVE: CVE-2026-3304. Advisory: https://github.com/expressjs/multer/security/advisories/GHSA-xf7r-hgr6-v32p</description>
    </item>
    <item>
      <title>CVE-2026-2359: multer vulnerable to Denial of Service via resource exhaustion</title>
      <link>https://github.com/expressjs/multer/security/advisories/GHSA-v52c-386h-88mc</link>
      <guid isPermaLink="false">CVE-2026-2359::multer</guid>
      <pubDate>Fri, 27 Feb 2026 00:00:00 +0000</pubDate>
      <description>multer vulnerable to Denial of Service via resource exhaustion in multer. CVE: CVE-2026-2359. Advisory: https://github.com/expressjs/multer/security/advisories/GHSA-v52c-386h-88mc</description>
    </item>
    <item>
      <title>CVE-2025-13465: Prototype Pollution Vulnerability in Lodash `_.unset` and `_.omit` functions</title>
      <link>https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg</link>
      <guid isPermaLink="false">CVE-2025-13465::lodash</guid>
      <pubDate>Wed, 21 Jan 2026 00:00:00 +0000</pubDate>
      <description>Prototype Pollution Vulnerability in Lodash `_.unset` and `_.omit` functions in lodash. CVE: CVE-2025-13465. Advisory: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg</description>
    </item>
    <item>
      <title>CVE-2025-13466: body-parser vulnerable to denial of service when url encoding is used</title>
      <link>https://github.com/expressjs/body-parser/security/advisories/GHSA-wqch-xfxh-vrr4</link>
      <guid isPermaLink="false">CVE-2025-13466::body-parser</guid>
      <pubDate>Mon, 24 Nov 2025 00:00:00 +0000</pubDate>
      <description>body-parser vulnerable to denial of service when url encoding is used in body-parser. CVE: CVE-2025-13466. Advisory: https://github.com/expressjs/body-parser/security/advisories/GHSA-wqch-xfxh-vrr4</description>
    </item>
    <item>
      <title>CVE-2025-7339: on-headers vulnerable to http response header manipulation</title>
      <link>https://github.com/jshttp/on-headers/security/advisories/GHSA-76c9-3jph-rj3q</link>
      <guid isPermaLink="false">CVE-2025-7339::on-headers</guid>
      <pubDate>Thu, 17 Jul 2025 00:00:00 +0000</pubDate>
      <description>on-headers vulnerable to http response header manipulation in on-headers. CVE: CVE-2025-7339. Advisory: https://github.com/jshttp/on-headers/security/advisories/GHSA-76c9-3jph-rj3q</description>
    </item>
    <item>
      <title>CVE-2025-7338: Multer vulnerable to Denial of Service via unhandled exception from malformed request</title>
      <link>https://github.com/expressjs/multer/security/advisories/GHSA-fjgf-rc76-4x9p</link>
      <guid isPermaLink="false">CVE-2025-7338::multer</guid>
      <pubDate>Thu, 17 Jul 2025 00:00:00 +0000</pubDate>
      <description>Multer vulnerable to Denial of Service via unhandled exception from malformed request in multer. CVE: CVE-2025-7338. Advisory: https://github.com/expressjs/multer/security/advisories/GHSA-fjgf-rc76-4x9p</description>
    </item>
  </channel>
</rss>
