|
cve="CVE-2026-42041"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.1"
recommendation="Upgrade to version 1.15.1 or later"
severity="moderate"
title="Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy"
url="https://github.com/advisories/GHSA-w9j2-pvgh-6h63"
|
4.8
|
|
cve="CVE-2026-42043"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.1"
recommendation="Upgrade to version 1.15.1 or later"
severity="high"
title="Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0"
url="https://github.com/advisories/GHSA-pmwg-cvhr-8vh7"
|
7.2
|
|
cve="CVE-2026-42044"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.2"
recommendation="Upgrade to version 1.15.2 or later"
severity="moderate"
title="Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`"
url="https://github.com/advisories/GHSA-3w6x-2g7m-8v23"
|
6.5
|
|
cve="CVE-2026-42040"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.1"
recommendation="Upgrade to version 1.15.1 or later"
severity="low"
title="Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams"
url="https://github.com/advisories/GHSA-xhjh-pmcv-23jw"
|
3.7
|
|
cve="CVE-2026-42037"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.1"
recommendation="Upgrade to version 1.15.1 or later"
severity="moderate"
title="Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream"
url="https://github.com/advisories/GHSA-445q-vr5w-6q77"
|
5.3
|
|
cve="CVE-2026-42038"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.1"
recommendation="Upgrade to version 1.15.1 or later"
severity="moderate"
title="Axios: no_proxy bypass via IP alias allows SSRF"
url="https://github.com/advisories/GHSA-m7pr-hjqh-92cm"
|
6.8
|
|
cve="CVE-2026-42034"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.1"
recommendation="Upgrade to version 1.15.1 or later"
severity="moderate"
title="Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0"
url="https://github.com/advisories/GHSA-5c9x-8gcm-mpgx"
|
5.3
|
|
cve="CVE-2026-42036"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.1"
recommendation="Upgrade to version 1.15.1 or later"
severity="moderate"
title="Axios: HTTP adapter streamed responses bypass maxContentLength"
url="https://github.com/advisories/GHSA-vf2m-468p-8v99"
|
5.3
|
|
cve="CVE-2026-42033"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.1"
recommendation="Upgrade to version 1.15.1 or later"
severity="high"
title="Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking"
url="https://github.com/advisories/GHSA-pf86-5x62-jrwf"
|
7.4
|
|
cve="CVE-2026-42035"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.1"
recommendation="Upgrade to version 1.15.1 or later"
severity="high"
title="Axios: Header Injection via Prototype Pollution"
url="https://github.com/advisories/GHSA-6chq-wfr3-2hj9"
|
7.4
|
|
cve="CVE-2026-42042"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.1"
recommendation="Upgrade to version 1.15.1 or later"
severity="moderate"
title="Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion"
url="https://github.com/advisories/GHSA-xx6v-rp6x-q39c"
|
5.4
|
|
cve="CVE-2026-42264"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.2"
recommendation="Upgrade to version 1.15.2 or later"
severity="high"
title="Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking"
url="https://github.com/advisories/GHSA-q8qp-cvcw-x6jj"
|
7.4
|
|
cve="CVE-2026-41907"
instance="gaeko-ui"
job="npm_audit"
package="uuid"
patched_versions=">=11.1.1"
recommendation="Upgrade to version 11.1.1 or later"
severity="moderate"
title="uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided"
url="https://github.com/advisories/GHSA-w5hq-g745-h8pq"
|
7.5
|
|
cve="CVE-2026-42211"
instance="gaeko-ui"
job="npm_audit"
package="react-router"
patched_versions=">=7.14.2"
recommendation="Upgrade to version 7.14.2 or later"
severity="high"
title="React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE"
url="https://github.com/advisories/GHSA-49rj-9fvp-4h2h"
|
8.1
|
|
cve="CVE-2026-42342"
instance="gaeko-ui"
job="npm_audit"
package="react-router"
patched_versions=">=7.15.0"
recommendation="Upgrade to version 7.15.0 or later"
severity="high"
title="React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint"
url="https://github.com/advisories/GHSA-8x6r-g9mw-2r78"
|
7.5
|
|
cve="CVE-2026-42039"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.1"
recommendation="Upgrade to version 1.15.1 or later"
severity="moderate"
title="Axios: unbounded recursion in toFormData causes DoS via deeply nested request data"
url="https://github.com/advisories/GHSA-62hf-57xw-28j9"
|
7.5
|
|
cve="CVE-2026-44496"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.16.0"
recommendation="Upgrade to version 1.16.0 or later"
severity="high"
title="Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection"
url="https://github.com/advisories/GHSA-hfxv-24rg-xrqf"
|
7.5
|
|
cve="CVE-2026-44488"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.16.0"
recommendation="Upgrade to version 1.16.0 or later"
severity="high"
title="Allocation of Resources Without Limits or Throttling in Axios"
url="https://github.com/advisories/GHSA-777c-7fjr-54vf"
|
7.5
|
|
cve="CVE-2026-44487"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.16.0"
recommendation="Upgrade to version 1.16.0 or later"
severity="high"
title="Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter"
url="https://github.com/advisories/GHSA-p92q-9vqr-4j8v"
|
0
|
|
cve="CVE-2026-44486"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.16.0"
recommendation="Upgrade to version 1.16.0 or later"
severity="high"
title="Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection"
url="https://github.com/advisories/GHSA-j5f8-grm9-p9fc"
|
7.5
|
|
cve="CVE-2026-44495"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.15.2"
recommendation="Upgrade to version 1.15.2 or later"
severity="high"
title="axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge"
url="https://github.com/advisories/GHSA-3g43-6gmg-66jw"
|
7
|
|
cve="CVE-2026-44494"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.16.0"
recommendation="Upgrade to version 1.16.0 or later"
severity="high"
title="axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`"
url="https://github.com/advisories/GHSA-35jp-ww65-95wh"
|
8.7
|
|
cve="CVE-2026-44490"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.16.0"
recommendation="Upgrade to version 1.16.0 or later"
severity="moderate"
title="axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions"
url="https://github.com/advisories/GHSA-898c-q2cr-xwhg"
|
4.8
|
|
cve="CVE-2026-53632"
instance="gaeko-ui"
job="npm_audit"
package="vite"
patched_versions=">=8.0.16"
recommendation="Upgrade to version 8.0.16 or later"
severity="moderate"
title="launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows"
url="https://github.com/advisories/GHSA-v6wh-96g9-6wx3"
|
0
|
|
cve="CVE-2026-53663"
instance="gaeko-ui"
job="npm_audit"
package="react-router"
patched_versions=">=7.15.1"
recommendation="Upgrade to version 7.15.1 or later"
severity="low"
title="React Router: Potential CSRF via PUT/PATCH/DELETE document requests"
url="https://github.com/advisories/GHSA-84g9-w2xq-vcv6"
|
3.1
|
|
cve="CVE-2026-55849"
instance="gaeko-ui"
job="npm_audit"
package="@cyclonedx/cyclonedx-npm"
patched_versions=">=5.0.0"
recommendation="Upgrade to version 5.0.0 or later"
severity="high"
title="@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument"
url="https://github.com/advisories/GHSA-v75r-vx73-82pj"
|
0
|
|
cve="CVE-2026-53571"
instance="gaeko-ui"
job="npm_audit"
package="vite"
patched_versions=">=8.0.16"
recommendation="Upgrade to version 8.0.16 or later"
severity="high"
title="vite: `server.fs.deny` bypass on Windows alternate paths"
url="https://github.com/advisories/GHSA-fx2h-pf6j-xcff"
|
7.5
|
|
cve="CVE-2026-39244"
instance="gaeko-ui"
job="npm_audit"
package="adm-zip"
patched_versions=">=0.6.0"
recommendation="Upgrade to version 0.6.0 or later"
severity="high"
title="adm-zip: Crafted ZIP file triggers 4GB memory allocation"
url="https://github.com/advisories/GHSA-xcpc-8h2w-3j85"
|
7.5
|
|
cve="CVE-2026-44492"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.16.0"
recommendation="Upgrade to version 1.16.0 or later"
severity="high"
title="axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)"
url="https://github.com/advisories/GHSA-pjwm-pj3p-43mv"
|
8.6
|
|
cve="GHSA-42h9-826w-cgv3"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.18.0"
recommendation="Upgrade to version 1.18.0 or later"
severity="moderate"
title="Axios: Excessive recursion in formDataToJSON can cause denial of service"
url="https://github.com/advisories/GHSA-42h9-826w-cgv3"
|
0
|
|
cve="GHSA-pmv8-rq9r-6j72"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.18.0"
recommendation="Upgrade to version 1.18.0 or later"
severity="moderate"
title="Axios: Deep formToJSON Key Recursion Can Cause Denial of Service"
url="https://github.com/advisories/GHSA-pmv8-rq9r-6j72"
|
0
|
|
cve="GHSA-jqh4-m9w3-8hp9"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.18.0"
recommendation="Upgrade to version 1.18.0 or later"
severity="moderate"
title="Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`"
url="https://github.com/advisories/GHSA-jqh4-m9w3-8hp9"
|
0
|
|
cve="GHSA-mmx7-hfxf-jppx"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.18.0"
recommendation="Upgrade to version 1.18.0 or later"
severity="moderate"
title="Axios: Prototype pollution gadgets can alter axios request construction"
url="https://github.com/advisories/GHSA-mmx7-hfxf-jppx"
|
0
|
|
cve="GHSA-f4gw-2p7v-4548"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.18.0"
recommendation="Upgrade to version 1.18.0 or later"
severity="moderate"
title="Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios"
url="https://github.com/advisories/GHSA-f4gw-2p7v-4548"
|
0
|
|
cve="GHSA-7q8q-rj6j-mhjq"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.18.0"
recommendation="Upgrade to version 1.18.0 or later"
severity="moderate"
title="Axios: Nested axios option objects can consume polluted prototype values"
url="https://github.com/advisories/GHSA-7q8q-rj6j-mhjq"
|
0
|
|
cve="GHSA-mwf2-3pr3-8698"
instance="gaeko-ui"
job="npm_audit"
package="axios"
patched_versions=">=1.18.0"
recommendation="Upgrade to version 1.18.0 or later"
severity="moderate"
title="Axios: HTTP/2 streamed uploads bypass `maxBodyLength`"
url="https://github.com/advisories/GHSA-mwf2-3pr3-8698"
|
0
|
|
cve="CVE-2026-53669"
instance="gaeko-ui"
job="npm_audit"
package="react-router"
patched_versions=">=7.18.0"
recommendation="Upgrade to version 7.18.0 or later"
severity="moderate"
title="React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)"
url="https://github.com/advisories/GHSA-wrjc-x8rr-h8h6"
|
0
|
|
cve="CVE-2026-53667"
instance="gaeko-ui"
job="npm_audit"
package="react-router"
patched_versions=">=7.18.0"
recommendation="Upgrade to version 7.18.0 or later"
severity="moderate"
title="React Router: RSCErrorHandler Missing Protocol Validation (XSS)"
url="https://github.com/advisories/GHSA-h8fp-f39c-q6mh"
|
6.9
|
|
cve="CVE-2026-53666"
instance="gaeko-ui"
job="npm_audit"
package="react-router"
patched_versions=">=7.18.0"
recommendation="Upgrade to version 7.18.0 or later"
severity="moderate"
title="React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration"
url="https://github.com/advisories/GHSA-337j-9hxr-rhxg"
|
6.1
|
|
cve="CVE-2026-55685"
instance="gaeko-ui"
job="npm_audit"
package="react-router"
patched_versions=">=7.18.0"
recommendation="Upgrade to version 7.18.0 or later"
severity="high"
title="React Router: Unauthenticated Denial of Service via Inefficient Route Matching"
url="https://github.com/advisories/GHSA-chx6-hx7r-mcp5"
|
0
|
|
cve="CVE-2026-14257"
instance="gaeko-ui"
job="npm_audit"
package="brace-expansion"
patched_versions=">=1.1.17"
recommendation="Upgrade to version 1.1.17 or later"
severity="high"
title="brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash"
url="https://github.com/advisories/GHSA-mh99-v99m-4gvg"
|
7.5
|
|
cve="CVE-2026-14257"
instance="gaeko-ui"
job="npm_audit"
package="brace-expansion"
patched_versions=">=2.1.3"
recommendation="Upgrade to version 2.1.3 or later"
severity="high"
title="brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash"
url="https://github.com/advisories/GHSA-mh99-v99m-4gvg"
|
7.5
|
|
cve="CVE-2026-18446"
instance="gaeko-ui"
job="npm_audit"
package="fast-uri"
patched_versions=">=3.1.5"
recommendation="Upgrade to version 3.1.5 or later"
severity="high"
title="fast-uri vulnerable to host confusion via backslash authority introducer"
url="https://github.com/advisories/GHSA-7p8r-x3mc-p8w7"
|
7.5
|
|
cve="CVE-2026-69152"
instance="gaeko-ui"
job="npm_audit"
package="brace-expansion"
patched_versions=">=5.0.9"
recommendation="Upgrade to version 5.0.9 or later"
severity="high"
title="brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation"
url="https://github.com/advisories/GHSA-rgw5-rvv9-x895"
|
7.5
|
|
cve="CVE-2026-69152"
instance="gaeko-ui"
job="npm_audit"
package="brace-expansion"
patched_versions=">=2.1.4"
recommendation="Upgrade to version 2.1.4 or later"
severity="high"
title="brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation"
url="https://github.com/advisories/GHSA-rgw5-rvv9-x895"
|
7.5
|
|
cve="CVE-2026-69152"
instance="gaeko-ui"
job="npm_audit"
package="brace-expansion"
patched_versions=">=1.1.18"
recommendation="Upgrade to version 1.1.18 or later"
severity="high"
title="brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation"
url="https://github.com/advisories/GHSA-rgw5-rvv9-x895"
|
7.5
|
|
cve="GHSA-5p4m-2wfm-xmqj"
instance="gaeko-ui"
job="npm_audit"
package="js-yaml"
patched_versions=">=4.3.1"
recommendation="Upgrade to version 4.3.1 or later"
severity="high"
title="JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported"
url="https://github.com/advisories/GHSA-5p4m-2wfm-xmqj"
|
7.5
|
|
cve="GHSA-qwww-vcr4-c8h2"
instance="gaeko-ui"
job="npm_audit"
package="react-router"
patched_versions=">=7.18.2"
recommendation="Upgrade to version 7.18.2 or later"
severity="high"
title="React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response"
url="https://github.com/advisories/GHSA-qwww-vcr4-c8h2"
|
0
|
|
cve="CVE-2026-67213"
instance="gaeko-ui"
job="npm_audit"
package="nanoid"
patched_versions=">=3.3.18"
recommendation="Upgrade to version 3.3.18 or later"
severity="high"
title="nanoid: custom generators can loop indefinitely when size is zero"
url="https://github.com/advisories/GHSA-2v37-7h3g-55p8"
|
5.9
|