| GHSA-35jp-ww65-95wh CVE-2026-44494 | axios@1.13.5 | 高 | 1.16.0 | axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` |
| GHSA-3g43-6gmg-66jw CVE-2026-44495 | axios@1.13.5 | 高 | 1.15.2 | axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge |
| GHSA-6chq-wfr3-2hj9 CVE-2026-42035 | axios@1.13.5 | 高 | 1.15.1 | Axios: Header Injection via Prototype Pollution |
| GHSA-777c-7fjr-54vf CVE-2026-44488 | axios@1.13.5 | 高 | 1.16.0 | Allocation of Resources Without Limits or Throttling in Axios |
| GHSA-hfxv-24rg-xrqf CVE-2026-44496 | axios@1.13.5 | 高 | 1.16.0 | Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection |
| GHSA-j5f8-grm9-p9fc CVE-2026-44486 | axios@1.13.5 | 高 | 1.16.0 | Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection |
| GHSA-p92q-9vqr-4j8v CVE-2026-44487 | axios@1.13.5 | 高 | 1.16.0 | Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter |
| GHSA-pf86-5x62-jrwf CVE-2026-42033 | axios@1.13.5 | 高 | 1.15.1 | Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking |
| GHSA-pmwg-cvhr-8vh7 CVE-2026-42043 | axios@1.13.5 | 高 | 1.15.1 | Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0 |
| GHSA-q8qp-cvcw-x6jj CVE-2026-42264 | axios@1.13.5 | 高 | 1.15.2 | Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking |
| GHSA-3jxr-9vmj-r5cp CVE-2026-13149 | brace-expansion@1.1.12 | 高 | 5.0.7 | brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups |
| GHSA-mh99-v99m-4gvg CVE-2026-14257 | brace-expansion@1.1.12 | 高 | 5.0.8 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash |
| GHSA-rgw5-rvv9-x895 CVE-2026-69152 | brace-expansion@1.1.12 | 高 | 1.1.18 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| GHSA-4c8g-83qw-93j6 CVE-2026-13676 | fast-uri@3.1.0 | 高 | 4.0.1 | fast-uri vulnerable to host confusion via failed IDN canonicalization |
| GHSA-7p8r-x3mc-p8w7 CVE-2026-18446 | fast-uri@3.1.0 | 高 | 2.4.4 | fast-uri vulnerable to host confusion via backslash authority introducer |
| GHSA-q3j6-qgpj-74h6 CVE-2026-6321 | fast-uri@3.1.0 | 高 | 3.1.1 | fast-uri vulnerable to path traversal via percent-encoded dot segments |
| GHSA-v2hh-gcrm-f6hx CVE-2026-16221 | fast-uri@3.1.0 | 高 | 2.4.3 | fast-uri vulnerable to host confusion via literal backslash authority delimiter |
| GHSA-v39h-62p7-jpjc CVE-2026-6322 | fast-uri@3.1.0 | 高 | 3.1.2 | fast-uri vulnerable to host confusion via percent-encoded authority delimiters |
| GHSA-247c-9743-5963 CVE-2025-32442 | fastify@5.7.4 | 高 | 5.8.5 | Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header |
| GHSA-2g4f-4pwh-qvx6 CVE-2025-69873 | ajv@8.17.1 | 中 | 8.18.0 | ajv has ReDoS when using `$data` option |
| GHSA-3p68-rc4w-qgx5 CVE-2025-62718 | axios@1.13.5 | 中 | 1.15.0 | Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF |
| GHSA-3w6x-2g7m-8v23 CVE-2026-42044 | axios@1.13.5 | 中 | 1.15.2 | Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` |
| GHSA-42h9-826w-cgv3 CVE-2026-67313 | axios@1.13.5 | 中 | 0.33.0 | Axios: Excessive recursion in formDataToJSON can cause denial of service |
| GHSA-445q-vr5w-6q77 CVE-2026-42037 | axios@1.13.5 | 中 | 1.15.1 | Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream |
| GHSA-5c9x-8gcm-mpgx CVE-2026-42034 | axios@1.13.5 | 中 | 1.15.1 | Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0 |
| GHSA-62hf-57xw-28j9 CVE-2026-42039 | axios@1.13.5 | 中 | 1.15.1 | Axios: unbounded recursion in toFormData causes DoS via deeply nested request data |
| GHSA-7q8q-rj6j-mhjq CVE-2026-67319 | axios@1.13.5 | 中 | 0.33.0 | Axios: Nested axios option objects can consume polluted prototype values |
| GHSA-898c-q2cr-xwhg CVE-2026-44490 | axios@1.13.5 | 中 | 1.16.0 | axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions |
| GHSA-fvcv-3m26-pcqx CVE-2026-40175 | axios@1.13.5 | 中 | 1.15.0 | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain |
| GHSA-jqh4-m9w3-8hp9 CVE-2026-67317 | axios@1.13.5 | 中 | 1.18.0 | Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength` |
| GHSA-m7pr-hjqh-92cm CVE-2026-42038 | axios@1.13.5 | 中 | 1.15.1 | Axios: no_proxy bypass via IP alias allows SSRF |
| GHSA-mmx7-hfxf-jppx CVE-2026-67316 | axios@1.13.5 | 中 | 1.18.0 | Axios: Prototype pollution gadgets can alter axios request construction |
| GHSA-mwf2-3pr3-8698 CVE-2026-67318 | axios@1.13.5 | 中 | 1.18.0 | Axios: HTTP/2 streamed uploads bypass `maxBodyLength` |
| GHSA-pmv8-rq9r-6j72 CVE-2026-67312 | axios@1.13.5 | 中 | 0.33.0 | Axios: Deep formToJSON Key Recursion Can Cause Denial of Service |
| GHSA-vf2m-468p-8v99 CVE-2026-42036 | axios@1.13.5 | 中 | 1.15.1 | Axios: HTTP adapter streamed responses bypass maxContentLength |
| GHSA-w9j2-pvgh-6h63 CVE-2026-42041 | axios@1.13.5 | 中 | 1.15.1 | Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy |
| GHSA-xx6v-rp6x-q39c CVE-2026-42042 | axios@1.13.5 | 中 | 1.15.1 | Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion |
| GHSA-f886-m6hf-6m8v CVE-2026-33750 | brace-expansion@1.1.12 | 中 | 5.0.5 | brace-expansion: Zero-step sequence causes process hang and memory exhaustion |
| GHSA-444r-cwp2-x5xf CVE-2026-3635 | fastify@5.7.4 | 中 | 5.8.3 | fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections |
| GHSA-xhjh-pmcv-23jw CVE-2026-42040 | axios@1.13.5 | 低 | 1.15.1 | Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams |
| GHSA-573f-x89g-hqp9 | fastify@5.7.4 | unknown | — | |
| GHSA-c96f-x56v-gq3h | find-my-way@9.4.0 | unknown | — | |
| GHSA-r4q5-vmmm-2653 | follow-redirects@1.15.11 | unknown | — | |
| GHSA-hmw2-7cc7-3qxx | form-data@4.0.5 | unknown | — | |
| GHSA-52cp-r559-cp3m | js-yaml@4.1.1 | unknown | — | |
| GHSA-5p4m-2wfm-xmqj | js-yaml@4.1.1 | unknown | — | |
| GHSA-h67p-54hq-rp68 | js-yaml@4.1.1 | unknown | — | |
| GHSA-23c5-xmqv-rm74 | minimatch@3.1.2 | unknown | — | |
| GHSA-3ppc-4f35-3m26 | minimatch@3.1.2 | unknown | — | |
| GHSA-7r86-cg39-jmmj | minimatch@3.1.2 | unknown | — | |
| GHSA-23hp-3jrh-7fpw | tar@6.2.1 | unknown | — | |
| GHSA-34x7-hfp2-rc4v | tar@6.2.1 | unknown | — | |
| GHSA-83g3-92jg-28cx | tar@6.2.1 | unknown | — | |
| GHSA-8qq5-rm4j-mr97 | tar@6.2.1 | unknown | — | |
| GHSA-8x88-c5mf-7j5w | tar@6.2.1 | unknown | — | |
| GHSA-9ppj-qmqm-q256 | tar@6.2.1 | unknown | — | |
| GHSA-gvwx-54wh-qm9j | tar@6.2.1 | unknown | — | |
| GHSA-qffp-2rhf-9h96 | tar@6.2.1 | unknown | — | |
| GHSA-r292-9mhp-454m | tar@6.2.1 | unknown | — | |
| GHSA-r6q2-hw4h-h46w | tar@6.2.1 | unknown | — | |
| GHSA-vmf3-w455-68vh | tar@6.2.1 | unknown | — | |
| GHSA-w8wr-v893-vjvp | tar@6.2.1 | unknown | — | |
| GHSA-2mjp-6q6p-2qxm | undici@7.21.0 | unknown | — | |
| GHSA-35p6-xmwp-9g52 | undici@7.21.0 | unknown | — | |
| GHSA-4992-7rv2-5pvq | undici@7.21.0 | unknown | — | |
| GHSA-4cwx-7wf7-3272 | undici@7.21.0 | unknown | — | |
| GHSA-8xcm-r25x-g524 | undici@7.21.0 | unknown | — | |
| GHSA-f269-vfmq-vjvj | undici@7.21.0 | unknown | — | |
| GHSA-g8m3-5g58-fq7m | undici@7.21.0 | unknown | — | |
| GHSA-jr45-8vmc-qm54 | undici@7.21.0 | unknown | — | |
| GHSA-m8rv-5g2x-5cg5 | undici@7.21.0 | unknown | — | |
| GHSA-p88m-4jfj-68fv | undici@7.21.0 | unknown | — | |
| GHSA-phc3-fgpg-7m6h | undici@7.21.0 | unknown | — | |
| GHSA-pr7r-676h-xcf6 | undici@7.21.0 | unknown | — | |
| GHSA-v3r7-h72x-cjcm | undici@7.21.0 | unknown | — | |
| GHSA-v9p9-hfj2-hcw8 | undici@7.21.0 | unknown | — | |
| GHSA-vrm6-8vpv-qv8q | undici@7.21.0 | unknown | — | |
| GHSA-vxpw-j846-p89q | undici@7.21.0 | unknown | — | |
| GHSA-48c2-rrv3-qjmp | yaml@1.10.2 | unknown | — | |