Skip to content

@kleros/kleros-v2-web-devtools-0.1.0.tgz: 63 vulnerabilities (highest severity is: 9.8) #2567

Description

@mend-bolt-for-github
Vulnerable Library - @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Vulnerabilities

Vulnerability Severity CVSS Dependency Type Fixed in (@⁠kleros/kleros-v2-web-devtools version) Remediation Possible**
CVE-2026-41907 Critical 9.8 detected in multiple dependencies Transitive N/A*
CVE-2026-64645 Critical 9.3 next-14.2.28.tgz Transitive N/A*
CVE-2026-23527 High 8.9 h3-1.9.0.tgz Transitive N/A*
CVE-2025-9288 High 8.7 sha.js-2.4.11.tgz Transitive N/A*
CVE-2026-44578 High 8.6 next-14.2.28.tgz Transitive N/A*
CVE-2025-12816 High 8.6 node-forge-1.3.1.tgz Transitive N/A*
CVE-2026-64649 High 8.2 next-14.2.28.tgz Transitive N/A*
CVE-2026-4800 High 8.1 lodash-es-4.17.21.tgz Transitive N/A*
CVE-2026-42599 High 7.7 svelte-5.25.7.tgz Transitive N/A*
CVE-2026-69185 High 7.5 socket.io-parser-4.2.4.tgz Transitive N/A*
CVE-2026-64641 High 7.5 next-14.2.28.tgz Transitive N/A*
CVE-2026-6322 High 7.5 fast-uri-3.0.6.tgz Transitive N/A*
CVE-2026-6321 High 7.5 fast-uri-3.0.6.tgz Transitive N/A*
CVE-2026-48779 High 7.5 detected in multiple dependencies Transitive N/A*
CVE-2026-46625 High 7.5 js-cookie-2.2.1.tgz Transitive N/A*
CVE-2026-45822 High 7.5 decode-uri-component-0.2.2.tgz Transitive N/A*
CVE-2026-45623 High 7.5 postcss-8.4.31.tgz Transitive N/A*
CVE-2026-44573 High 7.5 next-14.2.28.tgz Transitive N/A*
CVE-2026-35209 High 7.5 defu-6.1.3.tgz Transitive N/A*
CVE-2026-33895 High 7.5 node-forge-1.3.1.tgz Transitive N/A*
CVE-2026-33894 High 7.5 node-forge-1.3.1.tgz Transitive N/A*
CVE-2026-33891 High 7.5 node-forge-1.3.1.tgz Transitive N/A*
CVE-2026-33671 High 7.5 picomatch-2.3.1.tgz Transitive N/A*
CVE-2026-33151 High 7.5 socket.io-parser-4.2.4.tgz Transitive N/A*
CVE-2026-33128 High 7.5 h3-1.9.0.tgz Transitive N/A*
CVE-2026-18446 High 7.5 fast-uri-3.0.6.tgz Transitive N/A*
CVE-2026-16221 High 7.5 fast-uri-3.0.6.tgz Transitive N/A*
CVE-2026-13676 High 7.5 fast-uri-3.0.6.tgz Transitive N/A*
CVE-2025-66031 High 7.5 node-forge-1.3.1.tgz Transitive N/A*
CVE-2025-27611 High 7.5 base-x-5.0.0.tgz Transitive N/A*
CVE-2024-37890 High 7.5 ws-8.11.0.tgz Transitive N/A*
CVE-2026-33896 High 7.4 node-forge-1.3.1.tgz Transitive N/A*
CVE-2025-13465 High 7.2 lodash-es-4.17.21.tgz Transitive N/A*
CVE-2026-64648 High 7.1 next-14.2.28.tgz Transitive N/A*
CVE-2026-2950 Medium 6.5 lodash-es-4.17.21.tgz Transitive N/A*
CVE-2026-29057 Medium 6.5 next-14.2.28.tgz Transitive N/A*
CVE-2025-57822 Medium 6.5 next-14.2.28.tgz Transitive N/A*
CVE-2025-57752 Medium 6.2 next-14.2.28.tgz Transitive N/A*
CVE-2025-27789 Medium 6.2 runtime-7.26.0.tgz Transitive N/A*
CVE-2026-44580 Medium 6.1 next-14.2.28.tgz Transitive N/A*
CVE-2026-41305 Medium 6.1 postcss-8.4.31.tgz Transitive N/A*
CVE-2026-67214 Medium 5.9 nanoid-3.3.7.tgz Transitive N/A*
CVE-2026-67213 Medium 5.9 nanoid-3.3.7.tgz Transitive N/A*
CVE-2026-44577 Medium 5.9 next-14.2.28.tgz Transitive N/A*
CVE-2025-59471 Medium 5.9 next-14.2.28.tgz Transitive N/A*
CVE-2025-14505 Medium 5.6 elliptic-6.6.1.tgz Transitive N/A*
CVE-2026-44576 Medium 5.4 next-14.2.28.tgz Transitive N/A*
CVE-2026-69153 Medium 5.3 postcss-8.4.31.tgz Transitive N/A*
CVE-2026-64646 Medium 5.3 next-14.2.28.tgz Transitive N/A*
CVE-2026-64643 Medium 5.3 next-14.2.28.tgz Transitive N/A*
CVE-2026-33672 Medium 5.3 picomatch-2.3.1.tgz Transitive N/A*
CVE-2026-27980 Medium 5.3 next-14.2.28.tgz Transitive N/A*
CVE-2026-2739 Medium 5.3 bn.js-5.2.1.tgz Transitive N/A*
CVE-2025-66400 Medium 5.3 mdast-util-to-hast-13.2.0.tgz Transitive N/A*
CVE-2025-66030 Medium 5.3 node-forge-1.3.1.tgz Transitive N/A*
CVE-2024-4067 Medium 5.3 micromatch-4.0.5.tgz Transitive N/A*
CVE-2026-27125 Medium 4.9 svelte-5.25.7.tgz Transitive N/A*
CVE-2026-64647 Medium 4.8 next-14.2.28.tgz Transitive N/A*
CVE-2026-44581 Medium 4.7 next-14.2.28.tgz Transitive N/A*
CVE-2025-48068 Medium 4.7 next-14.2.28.tgz Transitive N/A*
CVE-2026-45736 Medium 4.4 detected in multiple dependencies Transitive N/A*
CVE-2025-55173 Medium 4.3 next-14.2.28.tgz Transitive N/A*
CVE-2024-55565 Medium 4.3 nanoid-3.3.7.tgz Transitive N/A*

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

Partial details (19 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.

CVE-2026-41907

Vulnerable Libraries - uuid-9.0.1.tgz, uuid-8.3.2.tgz

uuid-9.0.1.tgz

Library home page: https://registry.npmjs.org/uuid/-/uuid-9.0.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • connectors-5.7.11.tgz
      • sdk-0.32.0.tgz
        • providers-16.1.0.tgz
          • utils-8.5.0.tgz
            • uuid-9.0.1.tgz (Vulnerable Library)

uuid-8.3.2.tgz

RFC4122 (v1, v4, and v5) UUIDs

Library home page: https://registry.npmjs.org/uuid/-/uuid-8.3.2.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • connectors-5.7.11.tgz
      • sdk-0.32.0.tgz
        • uuid-8.3.2.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.

Publish Date: 2026-04-24

URL: CVE-2026-41907

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-w5hq-g745-h8pq

Release Date: 2026-04-24

Fix Resolution: https://github.com/uuidjs/uuid.git - v11.1.1,https://github.com/uuidjs/uuid.git - v13.0.1,https://github.com/uuidjs/uuid.git - v12.0.1

Step up your Open Source Security Game with Mend here

CVE-2026-64645

Vulnerable Library - next-14.2.28.tgz

The React Framework

Library home page: https://registry.npmjs.org/next/-/next-14.2.28.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • next-14.2.28.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a
rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A redirects() rule configured this way is vulnerable to an Open Redirect. This issue has been fixed in versions 15.5.21 and 16.2.11.

Publish Date: 2026-07-27

URL: CVE-2026-64645

CVSS 3 Score Details (9.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-p9j2-gv94-2wf4

Release Date: 2026-07-23

Fix Resolution: https://github.com/vercel/next.js.git - v15.5.21,https://github.com/vercel/next.js.git - v16.2.11

Step up your Open Source Security Game with Mend here

CVE-2026-23527

Vulnerable Library - h3-1.9.0.tgz

Library home page: https://registry.npmjs.org/h3/-/h3-1.9.0.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • connectors-5.7.11.tgz
      • ethereum-provider-2.19.1.tgz
        • keyvaluestorage-1.1.1.tgz
          • unstorage-1.10.1.tgz
            • h3-1.9.0.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP Request Smuggling vulnerability. readRawBody is doing a strict case-sensitive check for the Transfer-Encoding header. It explicitly looks for "chunked", but per the RFC, this header should be case-insensitive. This vulnerability is fixed in 1.15.5.

Publish Date: 2026-01-15

URL: CVE-2026-23527

CVSS 3 Score Details (8.9)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-mp2g-9vg9-f4cg

Release Date: 2026-01-15

Fix Resolution: h3 - 1.15.5,https://github.com/h3js/h3.git - v1.15.5

Step up your Open Source Security Game with Mend here

CVE-2025-9288

Vulnerable Library - sha.js-2.4.11.tgz

Streamable SHA hashes in pure javascript

Library home page: https://registry.npmjs.org/sha.js/-/sha.js-2.4.11.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • connectors-5.7.11.tgz
      • cbw-sdk-3.9.3.tgz
        • sha.js-2.4.11.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.

Publish Date: 2025-08-20

URL: CVE-2025-9288

CVSS 3 Score Details (8.7)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2025-08-20

Fix Resolution: https://github.com/browserify/sha.js.git - v2.4.12,sha.js - 2.4.12

Step up your Open Source Security Game with Mend here

CVE-2026-44578

Vulnerable Library - next-14.2.28.tgz

The React Framework

Library home page: https://registry.npmjs.org/next/-/next-14.2.28.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • next-14.2.28.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.

Publish Date: 2026-05-13

URL: CVE-2026-44578

CVSS 3 Score Details (8.6)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-c4j6-fc7j-m34r

Release Date: 2026-05-05

Fix Resolution: next - 16.2.5,next - 15.5.16

Step up your Open Source Security Game with Mend here

CVE-2025-12816

Vulnerable Library - node-forge-1.3.1.tgz

JavaScript implementations of network transports, cryptography, ciphers, PKI, message digests, and various utilities.

Library home page: https://registry.npmjs.org/node-forge/-/node-forge-1.3.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • connectors-5.7.11.tgz
      • ethereum-provider-2.19.1.tgz
        • keyvaluestorage-1.1.1.tgz
          • unstorage-1.10.1.tgz
            • listhen-1.5.5.tgz
              • node-forge-1.3.1.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.

Publish Date: 2025-11-25

URL: CVE-2025-12816

CVSS 3 Score Details (8.6)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-5gfm-wpxj-wjgq

Release Date: 2025-11-25

Fix Resolution: node-forge - 1.3.2,https://github.com/digitalbazaar/forge.git - v1.3.2

Step up your Open Source Security Game with Mend here

CVE-2026-64649

Vulnerable Library - next-14.2.28.tgz

The React Framework

Library home page: https://registry.npmjs.org/next/-/next-14.2.28.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • next-14.2.28.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization. Applications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs on custom servers, or on deployments not behind a proxy that pins the host. Managed hosting pins the host upstream and is not affected; next start and standalone output do the same from version 14.2 onward. This issue has been fixed in versions 15.5.21 and 16.2.11.

Publish Date: 2026-07-27

URL: CVE-2026-64649

CVSS 3 Score Details (8.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-89xv-2m56-2m9x

Release Date: 2026-07-23

Fix Resolution: https://github.com/vercel/next.js.git - v15.5.21,https://github.com/vercel/next.js.git - v16.2.11

Step up your Open Source Security Game with Mend here

CVE-2026-4800

Vulnerable Library - lodash-es-4.17.21.tgz

Lodash exported as ES modules.

Library home page: https://registry.npmjs.org/lodash-es/-/lodash-es-4.17.21.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • vanilla-jsoneditor-3.3.1.tgz
      • lodash-es-4.17.21.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

Impact:
The fix for CVE-2021-23337 (GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.
When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.
Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function().
Patches:
Users should upgrade to version 4.18.0.
Workarounds:
Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

Publish Date: 2026-03-31

URL: CVE-2026-4800

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-r5fr-rjxr-66jc

Release Date: 2026-03-31

Fix Resolution: lodash-amd - 4.18.0,lodash.template - 4.18.0,lodash-es - 4.18.0,lodash - 4.18.0

Step up your Open Source Security Game with Mend here

CVE-2026-42599

Vulnerable Library - svelte-5.25.7.tgz

Cybernetically enhanced web apps

Library home page: https://registry.npmjs.org/svelte/-/svelte-5.25.7.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • vanilla-jsoneditor-3.3.1.tgz
      • svelte-5.25.7.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers. Note that this vulnerability only triggers if the user's browser has JavaScript enabled but Svelte's hydration mechanism does not reach the vulnerable element before the event fires. This issue has been patched in version 5.55.7.

Publish Date: 2026-06-09

URL: CVE-2026-42599

CVSS 3 Score Details (7.7)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: High
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-05-16

Fix Resolution: https://github.com/sveltejs/svelte.git - svelte@5.55.7

Step up your Open Source Security Game with Mend here

CVE-2026-69185

Vulnerable Library - socket.io-parser-4.2.4.tgz

Library home page: https://registry.npmjs.org/socket.io-parser/-/socket.io-parser-4.2.4.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • connectors-5.7.11.tgz
      • sdk-0.32.0.tgz
        • socket.io-client-4.7.4.tgz
          • socket.io-parser-4.2.4.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

Publish Date: 2026-08-03

URL: CVE-2026-69185

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: https://github.com/socketio/socket.io.git - socket.io-parser@4.2.7,https://github.com/socketio/socket.io.git - socket.io-parser@3.4.5,https://github.com/socketio/socket.io.git - socket.io-parser@3.3.6

Step up your Open Source Security Game with Mend here

CVE-2026-64641

Vulnerable Library - next-14.2.28.tgz

The React Framework

Library home page: https://registry.npmjs.org/next/-/next-14.2.28.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • next-14.2.28.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. This issue has been fixed in versions 15.5.21 and 16.2.11.

Publish Date: 2026-07-27

URL: CVE-2026-64641

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-m99w-x7hq-7vfj

Release Date: 2026-07-23

Fix Resolution: https://github.com/vercel/next.js.git - v15.5.21,https://github.com/vercel/next.js.git - v16.2.11

Step up your Open Source Security Game with Mend here

CVE-2026-6322

Vulnerable Library - fast-uri-3.0.6.tgz

Dependency-free RFC 3986 URI toolbox

Library home page: https://registry.npmjs.org/fast-uri/-/fast-uri-3.0.6.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • vanilla-jsoneditor-3.3.1.tgz
      • ajv-8.17.1.tgz
        • fast-uri-3.0.6.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a different authority than the input appeared to specify. Versions <= 3.1.1 are affected. Update to 3.1.2 or later.

Publish Date: 2026-05-05

URL: CVE-2026-6322

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-05-05

Fix Resolution: fast-uri - 3.1.2,https://github.com/fastify/fast-uri.git - v3.1.2

Step up your Open Source Security Game with Mend here

CVE-2026-6321

Vulnerable Library - fast-uri-3.0.6.tgz

Dependency-free RFC 3986 URI toolbox

Library home page: https://registry.npmjs.org/fast-uri/-/fast-uri-3.0.6.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • vanilla-jsoneditor-3.3.1.tgz
      • ajv-8.17.1.tgz
        • fast-uri-3.0.6.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Versions <= 3.1.0 are affected. Update to 3.1.1 or later.

Publish Date: 2026-05-04

URL: CVE-2026-6321

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-q3j6-qgpj-74h6

Release Date: 2026-05-04

Fix Resolution: fast-uri - 3.1.1

Step up your Open Source Security Game with Mend here

CVE-2026-48779

Vulnerable Libraries - ws-8.11.0.tgz, ws-8.18.1.tgz, ws-7.5.10.tgz

ws-8.11.0.tgz

Simple to use, blazing fast and thoroughly tested websocket client and server for Node.js

Library home page: https://registry.npmjs.org/ws/-/ws-8.11.0.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • connectors-5.7.11.tgz
      • sdk-0.32.0.tgz
        • socket.io-client-4.7.4.tgz
          • engine.io-client-6.5.3.tgz
            • ws-8.11.0.tgz (Vulnerable Library)

ws-8.18.1.tgz

Simple to use, blazing fast and thoroughly tested websocket client and server for Node.js

Library home page: https://registry.npmjs.org/ws/-/ws-8.18.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • viem-2.24.1.tgz
      • ws-8.18.1.tgz (Vulnerable Library)

ws-7.5.10.tgz

Library home page: https://registry.npmjs.org/ws/-/ws-7.5.10.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • connectors-5.7.11.tgz
      • ethereum-provider-2.19.1.tgz
        • sign-client-2.19.1.tgz
          • core-2.19.1.tgz
            • jsonrpc-ws-connection-1.0.16.tgz
              • ws-7.5.10.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.

Publish Date: 2026-06-16

URL: CVE-2026-48779

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-06-16

Fix Resolution: https://github.com/websockets/ws.git - 7.5.11,https://github.com/websockets/ws.git - 8.21.0,https://github.com/websockets/ws.git - 6.2.4,https://github.com/websockets/ws.git - 5.2.5

Step up your Open Source Security Game with Mend here

CVE-2026-46625

Vulnerable Library - js-cookie-2.2.1.tgz

A simple, lightweight JavaScript API for handling cookies

Library home page: https://registry.npmjs.org/js-cookie/-/js-cookie-2.2.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • react-use-17.5.1.tgz
      • js-cookie-2.2.1.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "proto" member is an own enumerable property, so the for…in enumerates it and the target[key] = source[key] write triggers the Object.prototype.proto setter on the fresh target ({}). The result is a per-instance prototype hijack: Object.prototype itself is untouched, but the merged attributes object now inherits attacker-controlled keys. Because the consuming set() function then enumerates the merged object with another for...in, every key the attacker placed on the polluted prototype lands in the resulting Set-Cookie string as an attribute pair. The attacker can set domain=, secure=, samesite=, expires=, and path= on cookies whose attributes the developer thought were locked down. This issue has been patched in version 3.0.7.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026-06-10

URL: CVE-2026-46625

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-05-23

Fix Resolution: https://github.com/js-cookie/js-cookie.git - v3.0.7,js-cookie - 3.0.7

Step up your Open Source Security Game with Mend here

CVE-2026-45822

Vulnerable Library - decode-uri-component-0.2.2.tgz

Library home page: https://registry.npmjs.org/decode-uri-component/-/decode-uri-component-0.2.2.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • connectors-5.7.11.tgz
      • ethereum-provider-2.19.1.tgz
        • utils-2.19.1.tgz
          • query-string-7.1.3.tgz
            • decode-uri-component-0.2.2.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-linear parsing time: 200 '%ab' tokens takes approximately 0.7s, 700 tokens approximately 6s, and 1400 tokens approximately 33s. An attacker can cause significant CPU consumption and event-loop blocking via crafted input.

Publish Date: 2026-06-30

URL: CVE-2026-45822

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-06-30

Fix Resolution: https://github.com/SamVerschueren/decode-uri-component.git - v0.5.0,decode-uri-component - 0.5.0

Step up your Open Source Security Game with Mend here

CVE-2026-45623

Vulnerable Library - postcss-8.4.31.tgz

Library home page: https://registry.npmjs.org/postcss/-/postcss-8.4.31.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • next-14.2.28.tgz
      • postcss-8.4.31.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to read any file readable by Node and leak the first ~10 bytes of its content through the resulting JSON.parse SyntaxError message. The bug also yields a precise file-existence oracle and a controllable-read primitive that may be combined with large-file targets for DoS. The behaviour is triggered with PostCSS's default options — no from, no map, no plugins required — and is therefore reachable from any pipeline that runs untrusted CSS through PostCSS (CMS themes, user-uploaded styles, browser-extension/userstyle processors, build pipelines for third-party packages, blog comment renderers, etc.). This issue has been fixed in version 8.5.12.

Publish Date: 2026-07-27

URL: CVE-2026-45623

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-07-23

Fix Resolution: postcss - 8.5.12,https://github.com/postcss/postcss.git - 8.5.12

Step up your Open Source Security Game with Mend here

CVE-2026-44573

Vulnerable Library - next-14.2.28.tgz

The React Framework

Library home page: https://registry.npmjs.org/next/-/next-14.2.28.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • next-14.2.28.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data//.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intended authorization checks. This vulnerability is fixed in 15.5.16 and 16.2.5.

Publish Date: 2026-05-13

URL: CVE-2026-44573

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-36qx-fr4f-26g5

Release Date: 2026-05-05

Fix Resolution: next - 15.5.16,next - 16.2.5

Step up your Open Source Security Game with Mend here

CVE-2026-35209

Vulnerable Library - defu-6.1.3.tgz

Library home page: https://registry.npmjs.org/defu/-/defu-6.1.3.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @⁠kleros/kleros-v2-web-devtools-0.1.0.tgz (Root Library)
    • connectors-5.7.11.tgz
      • ethereum-provider-2.19.1.tgz
        • keyvaluestorage-1.1.1.tgz
          • unstorage-1.10.1.tgz
            • h3-1.9.0.tgz
              • defu-6.1.3.tgz (Vulnerable Library)

Found in base branches: dev, master

Vulnerability Details

defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources) as the first argument to "defu()" are vulnerable to prototype pollution. A crafted payload containing a "proto" key can override intended default values in the merged resul. The internal "_defu" function used "Object.assign({}, defaults)" to copy the defaults object. "Object.assign" invokes the "proto" setter, which replaces the resulting object's "[[Prototype]]" with attacker-controlled values. Properties inherited from the polluted prototype then bypass the existing "proto" key guard in the "for...in" loop and land in the final result. Version 6.1.5 replaces "Object.assign({}, defaults)" with object spread ("{ ...defaults }"), which uses "[[DefineOwnProperty]]" and does not invoke the "proto" setter.

Publish Date: 2026-04-06

URL: CVE-2026-35209

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-737v-mqg7-c878

Release Date: 2026-04-04

Fix Resolution: defu - 6.1.5

Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions