{"success":true,"data":{"threats":[{"id":"57eb179a-6e66-40a5-add9-291967e26a1e","slug":"cve-2026-107392","externalId":"CVE-2026-107392","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107392 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. Prior to 11.15.0, the DSF parser handles an unrecognized chunk by calling tokenizer.ignore without awaiting the returned promise and without first rejecting a chunk size smaller than the 12-byte chunk header. A crafted DSF input can produce a negative ignore length; with strtok3 10.3.5 or later, the resulting RangeError is detached from the parseBuffer promise and becomes an unhandled rejection under Node.js default behavior. The parse call can appear to resolve before the process crashes, bypassing per-parse try/catch handling. The demonstrated impact is availability loss only and requires the DSF parsing path. This issue is fixed in version 11.15.0.","cveId":"CVE-2026-107392","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.15.0"],"cwes":["CWE-248","CWE-400"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-8j4c-6x6g-rq3j","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/e7fc27a96e789d41ece41fdac590fc7618274a41","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2700","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.15.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-8j4c-6x6g-rq3j","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-8j4c-6x6g-rq3j","type":"advisory","title":"OSV GHSA-8j4c-6x6g-rq3j"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:33.707Z","addedAt":"2026-10-08T21:05:52.984Z","updatedAt":"2026-10-08T21:08:30.817Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107392","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107392","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-8J4C-6X6G-RQ3J"}]},{"id":"058f0d42-6c83-46b2-ac64-ab25a6feb0d3","slug":"cve-2026-107391","externalId":"CVE-2026-107391","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107391 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. In the public development revision introduced after 11.14.0, a development-branch regression in the MP4 stsd sample-description parser allows an attacker-controlled sample-entry size of zero to prevent the StsdAtom.get cursor from advancing while an attacker-controlled entry_count keeps the synchronous loop running. A crafted MP4-family input can block the Node.js event loop and grow the sample-description table until the process is terminated or exhausts memory. The vulnerable change was present on the public master branch but was not included in music-metadata 11.14.0 or any earlier npm release, and version 11.16.0 contains the fix. This issue is fixed in version 11.16.0.","cveId":"CVE-2026-107391","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.16.0"],"cwes":["CWE-400","CWE-835"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-f94x-6692-553q","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/90a7d52c69e921a0b019592d887acd97b1c8b8a5","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2734","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.16.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-f94x-6692-553q","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-f94x-6692-553q","type":"advisory","title":"OSV GHSA-f94x-6692-553q"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:33.530Z","addedAt":"2026-10-08T21:05:52.968Z","updatedAt":"2026-10-08T21:08:30.734Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107391","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107391","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-F94X-6692-553Q"}]},{"id":"c4f4e22a-cd59-4bb9-845d-b556f3c5c4ca","slug":"cve-2026-107389","externalId":"CVE-2026-107389","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107389 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the Matroska and WebM EBML parser decodes an attacker-controlled VINT element length and uses it for string-token or Uint8Array allocation before confirming that the leaf fits within its parent or available input. Crafted WebM, MKV, or MKA inputs can cause disproportionate allocations, out-of-memory denial of service, or, for a demonstrated parseFile path on Node.js 26.7.0, an uncatchable V8 fatal abort. The exact failure mode depends on the tokenizer, parser API, and runtime, but the affected leaf-length validation flaw is shared and has availability impact only. This issue is fixed in version 11.16.0.","cveId":"CVE-2026-107389","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.16.0"],"cwes":["CWE-789"],"tags":["nvd","status:awaiting-analysis","osv","osv:ghsa-5gfj-9q3v-qfp3","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/163f013364ac9fc8dd0c3987433cd065a615af58","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/commit/2d14dc1f7391a94235948a0b823155538f69b3df","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2735","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.16.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-5gfj-9q3v-qfp3","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-5gfj-9q3v-qfp3","type":"advisory","title":"OSV GHSA-5gfj-9q3v-qfp3"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:33.190Z","addedAt":"2026-10-08T21:05:52.914Z","updatedAt":"2026-10-08T21:08:30.863Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107389","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107389","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-5GFJ-9Q3V-QFP3"}]},{"id":"43a625d7-28ac-491d-8004-2e7bc4f38e3f","slug":"cve-2026-107388","externalId":"CVE-2026-107388","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107388 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the ID3v2 parser trusts the syncsafe tag-size field and allocates the complete tag body before checking whether the input contains the declared bytes. A truncated file containing only an ID3v2 header can request an allocation approaching 268 MiB; the allocation succeeds, the subsequent read reaches end of stream, the EndOfStreamError is caught internally, and the caller receives a normal metadata object. This issue is fixed in version 11.16.0.","cveId":"CVE-2026-107388","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.16.0"],"cwes":["CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-jjpr-9cvf-cq55","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/b033db675b913a9dba1d29135ec3c10eae7095a7","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2743","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.16.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-jjpr-9cvf-cq55","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-jjpr-9cvf-cq55","type":"advisory","title":"OSV GHSA-jjpr-9cvf-cq55"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:01.683Z","addedAt":"2026-10-08T19:33:17.007Z","updatedAt":"2026-10-08T21:08:30.703Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107388","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107388","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-JJPR-9CVF-CQ55"}]},{"id":"9c90aa17-2b67-433b-85d6-bd6a13643ed7","slug":"cve-2026-107387","externalId":"CVE-2026-107387","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107387 — music-metadata is a metadata parser for audio and video media files.","description":"music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the APEv2 parser reads an attacker-controlled tag-item size and allocates a Uint8Array for a binary item before proving that the declared item fits in the remaining tag or file data. A small crafted APE file can therefore trigger a disproportionate allocation, including through cover-art items, and repeated or concurrent parsing can exhaust process memory. The demonstrated impact is availability loss only. This issue is fixed in version 11.16.0.","cveId":"CVE-2026-107387","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"music-metadata","affectedVersions":["pkg:npm/music-metadata < 11.16.0"],"cwes":["CWE-789"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-53v6-4h7p-p4gj","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Borewit/music-metadata/commit/b3bf52cb6021b046f33ba47583e19ab8f10dd235","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/pull/2744","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/releases/tag/v11.16.0","type":"other","title":"OSV web"},{"url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-53v6-4h7p-p4gj","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-53v6-4h7p-p4gj","type":"advisory","title":"OSV GHSA-53v6-4h7p-p4gj"},{"url":"https://github.com/Borewit/music-metadata","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:01.517Z","addedAt":"2026-10-08T19:33:16.996Z","updatedAt":"2026-10-08T21:08:30.899Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107387","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107387","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-53V6-4H7P-P4GJ"}]},{"id":"f46d72ca-29ef-48d8-baca-994a00dd2546","slug":"cve-2026-107385","externalId":"CVE-2026-107385","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107385 — MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases.","description":"MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, text-protocol escaping always prefixes quotes with a backslash and does not honor the session's NO_BACKSLASH_ESCAPES mode, including in Connection.escape(). When that mode is enabled, the backslash is an ordinary character, so an attacker-controlled placeholder value can close the SQL string literal and inject arbitrary SQL with the application's database privileges. The vulnerable configuration may be enabled server-wide, through connector initialization options, or with an application-issued SET sql_mode; execute() and batch() use binary protocols and are not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.","cveId":"CVE-2026-107385","cvssScore":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","severity":"high","vendor":"npm","product":"mariadb","affectedVersions":["pkg:npm/mariadb < 3.2.5","pkg:npm/mariadb >= 3.3.0, < 3.3.4","pkg:npm/mariadb >= 3.4.0, < 3.4.7","pkg:npm/mariadb >= 3.5.0-rc.0, < 3.5.4"],"cwes":["CWE-89"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-r3rv-jm3r-62q2","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/6995c8cf8e51b2ad055de63dcaa4094eebbef5ce","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/7670d90949307e735c0ae148d80b3776478a599d","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/95886df9fa0cca991e2be339caa6c3979be61553","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/e5a9d732d9574177749488336319b73074072779","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.4","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.4.7","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-r3rv-jm3r-62q2","type":"other","title":"OSV web"},{"url":"https://hackerone.com/reports/3889197","type":"other","title":"OSV web"},{"url":"https://jira.mariadb.org/browse/CONJS-368","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-r3rv-jm3r-62q2","type":"advisory","title":"OSV GHSA-r3rv-jm3r-62q2"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:01.170Z","addedAt":"2026-10-08T19:33:16.972Z","updatedAt":"2026-10-08T21:08:30.672Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107385","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107385","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-R3RV-JM3R-62Q2"}]},{"id":"aa26568f-1f21-419c-a95a-c3cd2d47466d","slug":"cve-2026-107384","externalId":"CVE-2026-107384","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107384 — MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases.","description":"MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are expanded into a SQL SET clause without being processed by escapeId. An attacker-controlled key containing a backtick can close the quoted identifier and cause the remainder of the key to be interpreted as SQL. This can update columns the application did not intend to expose and can append arbitrary SQL with the database user's privileges. The option is disabled by default, and serialized-object handling used when it is disabled is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.","cveId":"CVE-2026-107384","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"npm","product":"mariadb","affectedVersions":["pkg:npm/mariadb >= 3.2.0, < 3.2.5","pkg:npm/mariadb >= 3.3.0, < 3.3.4","pkg:npm/mariadb >= 3.4.0, < 3.4.7","pkg:npm/mariadb >= 3.5.0-rc.0, < 3.5.4"],"cwes":["CWE-89"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-v6pj-gxxw-phfw","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/144b8f4ef29539a9fb4b75d972b9dcdac4088b4e","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/6743b2f4a89b074268b44c650170767f35e1fb5d","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/8eb450972ff0f3826d7d45c071a42240798bc826","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/b9b04ec82a60b2caf2b0c038259ca9aff5d7014a","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.4","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.4.7","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-v6pj-gxxw-phfw","type":"other","title":"OSV web"},{"url":"https://hackerone.com/reports/3889198","type":"other","title":"OSV web"},{"url":"https://jira.mariadb.org/browse/CONJS-369","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-v6pj-gxxw-phfw","type":"advisory","title":"OSV GHSA-v6pj-gxxw-phfw"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:00.990Z","addedAt":"2026-10-08T19:33:16.960Z","updatedAt":"2026-10-08T21:08:30.618Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107384","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107384","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-V6PJ-GXXW-PHFW"}]},{"id":"8b76b828-b35b-4d05-b9a4-f45ae2f9d960","slug":"cve-2026-107383","externalId":"CVE-2026-107383","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107383 — MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases.","description":"MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation from each ring's numeric length before confirming that the ring is an array. A malformed non-array ring can therefore reserve bytes that the writing loop skips, and the connector sends the full buffer through execute() or batch(), disclosing uninitialized Node.js heap data into a database value. The persisted data can include other users' content, session material, database credentials, or TLS key material and may propagate to backups and replicas. The text-protocol query() path is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.","cveId":"CVE-2026-107383","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":"npm","product":"mariadb","affectedVersions":["pkg:npm/mariadb < 3.2.5","pkg:npm/mariadb >= 3.3.0, < 3.3.4","pkg:npm/mariadb >= 3.4.0, < 3.4.7","pkg:npm/mariadb >= 3.5.0-rc.0, < 3.5.4"],"cwes":["CWE-200"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-48qf-xh34-q73r","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/2314c03b785db482599d2befd06f4992e5fc46b3","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/a4aa048b57dc47309b80e5cc25a4a8eedb32fd9f","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/b2ca628864b0fc2e3e94ea96910f6b693ad5bd30","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/faa27d1b2b7753a54000f586d5148089b60d1284","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.4","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.4.7","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-48qf-xh34-q73r","type":"other","title":"OSV web"},{"url":"https://jira.mariadb.org/browse/CONJS-367","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-48qf-xh34-q73r","type":"advisory","title":"OSV GHSA-48qf-xh34-q73r"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:00.783Z","addedAt":"2026-10-08T19:33:16.949Z","updatedAt":"2026-10-08T21:08:30.923Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107383","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107383","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-48QF-XH34-Q73R"}]},{"id":"b1254390-ff69-4601-bfd4-96d2baac21b5","slug":"cve-2026-107382","externalId":"CVE-2026-107382","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107382 — MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases.","description":"MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.3.0 until 3.5.4, the zero-configuration TLS fingerprint-validation path calls Ed25519PasswordAuth.hash() through Authentication.validateFingerPrint, but Ed25519PasswordAuth.hash() references a seed identifier that is not in scope. Exposure requires a MariaDB server reached over TCP, TLS enabled with ssl: true or an ssl object whose rejectUnauthorized value is not false, a password set, no ssl.ca configured, and client_ed25519 negotiated as the authentication plugin. Under those conditions, a legitimate server, malicious server, or network attacker presenting a self-signed certificate can reach this path and cause a synchronous ReferenceError to escape the socket data handler. Under Node.js default uncaught-exception behavior, the client process terminates, causing denial of service. Configurations using a provided CA, rejectUnauthorized: false, another authentication plugin, or a Unix socket do not reach this vulnerable path. This issue is fixed in version 3.5.4.","cveId":"CVE-2026-107382","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"mariadb","affectedVersions":["pkg:npm/mariadb >= 3.3.0, < 3.5.4"],"cwes":["CWE-248"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-cx2f-j9fh-8g68","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/784ca3d757194a05f202d84b0c762321e76a7915","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4","type":"other","title":"OSV web"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-cx2f-j9fh-8g68","type":"other","title":"OSV web"},{"url":"https://hackerone.com/reports/3835450","type":"advisory","title":"security-advisories@github.com"},{"url":"https://jira.mariadb.org/browse/CONJS-356","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-cx2f-j9fh-8g68","type":"advisory","title":"OSV GHSA-cx2f-j9fh-8g68"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-nodejs","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:17:00.590Z","addedAt":"2026-10-08T19:33:16.935Z","updatedAt":"2026-10-08T21:08:30.761Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107382","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107382","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-CX2F-J9FH-8G68"}]},{"id":"419355fc-3322-47ea-a552-30b27c35b5b0","slug":"cve-2026-107375","externalId":"CVE-2026-107375","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107375 — JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures.","description":"JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. From 7.0.0 until 9.4.0, reactive applications generated with Spring WebFlux, Spring Data R2DBC, and a SQL database pass the attacker-controlled sort request parameter from paginated entity-list endpoints into createOrderByFields in generators/spring-boot/generators/data-relational/templates/src/main/java/package/repository/EntityManager_reactive.java.ejs. The generated code renders these properties into the SQL ORDER BY clause without validation or quoting, and the R2DBC simple query protocol can execute additional statements separated by semicolons. A normal authenticated user can consequently read sensitive tables, modify or delete data, or drop tables, while non-reactive JPA applications and NoSQL backends are outside this root cause. This issue is fixed in 9.4.0.","cveId":"CVE-2026-107375","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"npm","product":"generator-jhipster","affectedVersions":["pkg:npm/generator-jhipster >= 7.0.0, < 9.4.0"],"cwes":["CWE-89"],"tags":["nvd","status:received","osv","osv:ghsa-r223-96jv-q533","ecosystem:npm","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/jhipster/generator-jhipster/commit/f6f1579581da8db0d1b8bd28dd473b56951c83af","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/jhipster/generator-jhipster/releases/tag/v9.4.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/jhipster/generator-jhipster/security/advisories/GHSA-r223-96jv-q533","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-r223-96jv-q533","type":"advisory","title":"OSV GHSA-r223-96jv-q533"},{"url":"https://github.com/jhipster/generator-jhipster","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:21.883Z","addedAt":"2026-10-08T18:39:31.882Z","updatedAt":"2026-10-08T23:06:38.786Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107375","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107375","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-R223-96JV-Q533"}]},{"id":"1719d490-1708-41aa-9470-56f0200cf46e","slug":"cve-2026-107303","externalId":"CVE-2026-107303","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107303 — JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures.","description":"JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generated applications can persist attacker-controlled Blob data and companion ContentType values, return them through generated REST endpoints, and pass them to the generated openFile helper in generators/client/generators/common/templates/src/main/webapp/app/shared/jhipster/data-utils.ts.ejs. The helper uses the returned ContentType as the browser Blob MIME type and opens an object URL, so a normal authenticated user with write access to a Blob-bearing entity can store active HTML or SVG content that may execute under the application origin when a privileged user opens it. Exploitability depends on the generated application's content security policy and target-browser Blob behavior. This issue is fixed in generator-jhipster 9.4.0 and react-jhipster 1.1.0.","cveId":"CVE-2026-107303","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N","severity":"high","vendor":"npm","product":"generator-jhipster","affectedVersions":["pkg:npm/generator-jhipster < 9.4.0","pkg:npm/react-jhipster < 1.1.0"],"cwes":["CWE-79"],"tags":["nvd","status:received","osv","osv:ghsa-9ffp-22j7-56r2","ecosystem:npm","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/jhipster/generator-jhipster/commit/efe95edd4dedc3379735094936439410a51ce3d9","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/jhipster/generator-jhipster/pull/34807","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/jhipster/generator-jhipster/releases/tag/v9.4.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/jhipster/generator-jhipster/security/advisories/GHSA-9ffp-22j7-56r2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-9ffp-22j7-56r2","type":"advisory","title":"OSV GHSA-9ffp-22j7-56r2"},{"url":"https://github.com/jhipster/generator-jhipster","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:19.277Z","addedAt":"2026-10-08T18:39:31.817Z","updatedAt":"2026-10-08T23:06:38.635Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107303","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107303","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-9FFP-22J7-56R2"}]},{"id":"43257d2d-921c-466f-a335-271306681238","slug":"cve-2026-107302","externalId":"CVE-2026-107302","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107302 — msgpack5 is a msgpack v5 implementation for node.js and the browser.","description":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore causes a checked out-of-bounds buffer read and throws RangeError instead of IncompleteBufferError, which can unexpectedly terminate a request, stream, or worker in applications that wait for additional bytes after IncompleteBufferError. There is no adjacent-memory disclosure because the buffer implementation checks bounds. This issue is fixed in version 6.1.0.","cveId":"CVE-2026-107302","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"npm","product":"msgpack5","affectedVersions":["pkg:npm/msgpack5 < 6.1.0"],"cwes":["CWE-125"],"tags":["nvd","status:received","osv","osv:ghsa-8f34-f56x-9xph","ecosystem:npm","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mcollina/msgpack5/commit/15443a1f2aa682a6aa37f1705ac628de5b866ad1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-8f34-f56x-9xph","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-8f34-f56x-9xph","type":"advisory","title":"OSV GHSA-8f34-f56x-9xph"},{"url":"https://github.com/mcollina/msgpack5","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:19.100Z","addedAt":"2026-10-08T18:39:31.810Z","updatedAt":"2026-10-08T21:05:51.562Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107302","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107302","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-8F34-F56X-9XPH"}]},{"id":"88fcaa88-8305-4752-bc2d-d5f056656282","slug":"mal-2026-17701","externalId":"MAL-2026-17701","source":"OSV","sourceType":"osv","type":"vulnerability","title":"Malicious code in @kxafunc/xbails (npm)","description":"---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (629c665fbfef767c56d24af935d38312f7aa88d1c71d9dfb8c427192e54add0b)\npackage.json aliases the `libsignal` dependency to `npm:@bellaxchuu/libsignal-node@latest` — a non-standard publisher pinned to the mutable `latest` dist-tag with no version pin, no integrity check, and no hash. On every install, npm resolves this alias to whatever bytes `@bellaxchuu/libsignal-node` currently publishes, and the resolved module is loaded by `lib/Signal/libsignal.js` and `lib/Utils/crypto.js`, providing the Signal end-to-end cryptographic primitives (SessionCipher, SessionBuilder, ProtocolAddress, SessionRecord) with access to identity keys, prekeys, and plaintext messages. Whoever controls that upstream package name can push arbitrary code into every installer at any time, executing inside the Signal E2E encrypt/decrypt path. This is an off-registry-style trust relationship: the manifest itself constitutes the exposure, independent of what the current contents of the alias target happen to be.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":"npm","product":"@kxafunc/xbails","affectedVersions":["pkg:npm/%40kxafunc/xbails 0.0.8"],"cwes":[],"tags":["osv","osv:mal-2026-17701","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/MAL-2026-17701","type":"advisory","title":"OSV MAL-2026-17701"},{"url":"https://www.npmjs.com/package/@kxafunc/xbails/v/0.0.8","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:47:11.000Z","addedAt":"2026-10-08T18:42:41.732Z","updatedAt":"2026-10-08T18:42:41.732Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"OSV","url":"https://osv.dev/vulnerability/MAL-2026-17701"}]},{"id":"6256fc40-a5db-4afe-a317-24c4cd23a6c3","slug":"mal-2026-17700","externalId":"MAL-2026-17700","source":"OSV","sourceType":"osv","type":"vulnerability","title":"Malicious code in dransay (npm)","description":"---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (46d06d0ce82913346840f676660d67f9838f48511e58eef793bfe7c52091071f)\ndransay@99.0.0 declares a `preinstall` lifecycle script that runs `node beacon.js`, which performs a DNS lookup and HTTPS GET against a hardcoded Interactsh (`oast.site`) collaborator subdomain (`db3klhbi6i9hark1kegg174t38h33b6wt.oast.site`) on every `npm install`. The outbound request discloses the installer's source IP, DNS resolver IP, hostname-derived data, and timestamp to a third-party collaborator host unrelated to any first-party publisher. The package name and implausibly high version (99.0.0) are consistent with a dependency-confusion probe targeting an internal package name. The README self-labels the package as a benign dependency-confusion proof-of-concept; the self-label does not change the behavior — install-time, non-consensual outbound network I/O to a researcher-controlled OAST host that collects installer network identity.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":"npm","product":"dransay","affectedVersions":["pkg:npm/dransay 99.0.0"],"cwes":[],"tags":["osv","osv:mal-2026-17700","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/MAL-2026-17700","type":"advisory","title":"OSV MAL-2026-17700"},{"url":"https://www.npmjs.com/package/dransay/v/99.0.0","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:23:01.000Z","addedAt":"2026-10-08T18:42:41.831Z","updatedAt":"2026-10-08T18:42:41.831Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"OSV","url":"https://osv.dev/vulnerability/MAL-2026-17700"}]},{"id":"2dd8a366-40a4-489d-9987-792b785f0ce4","slug":"cve-2026-107301","externalId":"CVE-2026-107301","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107301 — msgpack5 is a msgpack v5 implementation for node.js and the browser.","description":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a __proto__ key can then replace the decoded object's prototype, potentially changing inherited properties or downstream behavior, although Object.prototype is not modified globally. This issue is fixed in version 6.1.0.","cveId":"CVE-2026-107301","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","severity":"medium","vendor":"npm","product":"msgpack5","affectedVersions":["pkg:npm/msgpack5 < 6.1.0"],"cwes":["CWE-1321"],"tags":["nvd","status:received","osv","osv:ghsa-8hq7-ggx2-cc6m","ecosystem:npm","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mcollina/msgpack5/commit/20e82600ac9462e679c8a45e5723315f21e2c774","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-8hq7-ggx2-cc6m","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-8hq7-ggx2-cc6m","type":"advisory","title":"OSV GHSA-8hq7-ggx2-cc6m"},{"url":"https://github.com/mcollina/msgpack5","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:16.143Z","addedAt":"2026-10-08T18:39:31.759Z","updatedAt":"2026-10-08T21:05:51.469Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107301","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107301","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-8HQ7-GGX2-CC6M"}]},{"id":"fb8cf4cf-9165-40f5-8348-b258e4da2e57","slug":"cve-2026-107300","externalId":"CVE-2026-107300","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107300 — msgpack5 is a msgpack v5 implementation for node.js and the browser.","description":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.","cveId":"CVE-2026-107300","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"npm","product":"msgpack5","affectedVersions":["pkg:npm/msgpack5 < 6.1.0"],"cwes":["CWE-674"],"tags":["nvd","status:received","osv","osv:ghsa-5x5g-h9x8-2fh9","ecosystem:npm","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mcollina/msgpack5/commit/77fbef144d05def5d16fc22c37caa64c0a7efeba","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-5x5g-h9x8-2fh9","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-5x5g-h9x8-2fh9","type":"advisory","title":"OSV GHSA-5x5g-h9x8-2fh9"},{"url":"https://github.com/mcollina/msgpack5","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:16.000Z","addedAt":"2026-10-08T18:39:31.752Z","updatedAt":"2026-10-08T21:05:51.450Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107300","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107300","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-5X5G-H9X8-2FH9"}]},{"id":"f2eabdbb-c92b-47c3-9ceb-f8111bebf1a9","slug":"cve-2026-107299","externalId":"CVE-2026-107299","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107299 — msgpack5 is a msgpack v5 implementation for node.js and the browser.","description":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data remains buffered while the decoder waits for bytes that cannot make the value valid, allowing a remote peer to exhaust memory. This issue is fixed in version 6.1.0.","cveId":"CVE-2026-107299","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"msgpack5","affectedVersions":["pkg:npm/msgpack5 < 6.1.0"],"cwes":["CWE-228"],"tags":["nvd","status:received","osv","osv:ghsa-26wq-p25c-j6fv","ecosystem:npm","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mcollina/msgpack5/commit/85da345bf1acc18ca441741e5cf4aa0ed0d69314","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-26wq-p25c-j6fv","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-26wq-p25c-j6fv","type":"advisory","title":"OSV GHSA-26wq-p25c-j6fv"},{"url":"https://github.com/mcollina/msgpack5","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:15.850Z","addedAt":"2026-10-08T18:39:31.745Z","updatedAt":"2026-10-08T21:05:51.406Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107299","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107299","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-26WQ-P25C-J6FV"}]},{"id":"617ee614-85b3-4e60-a2bb-82bd13592aa9","slug":"cve-2026-107298","externalId":"CVE-2026-107298","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107298 — msgpack5 is a msgpack v5 implementation for node.js and the browser.","description":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers that exhaust the JavaScript call stack and interrupt a process, worker, or request handler. This issue is fixed in version 6.1.0.","cveId":"CVE-2026-107298","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"medium","vendor":"npm","product":"msgpack5","affectedVersions":["pkg:npm/msgpack5 < 6.1.0"],"cwes":["CWE-674"],"tags":["nvd","status:received","osv","osv:ghsa-24ch-f2g6-9hhh","ecosystem:npm","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mcollina/msgpack5/commit/1e2b5874e555dd7c99417f64788a03b0590bb102","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-24ch-f2g6-9hhh","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-24ch-f2g6-9hhh","type":"advisory","title":"OSV GHSA-24ch-f2g6-9hhh"},{"url":"https://github.com/mcollina/msgpack5","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:15.703Z","addedAt":"2026-10-08T18:39:31.738Z","updatedAt":"2026-10-08T21:05:51.305Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107298","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107298","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-24CH-F2G6-9HHH"}]},{"id":"73c988d9-ad13-4046-8491-58f80a4b1744","slug":"cve-2026-107297","externalId":"CVE-2026-107297","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107297 — msgpack5 is a msgpack v5 implementation for node.js and the browser.","description":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elements to be decoded repeatedly, producing quadratic CPU use and blocking the event loop. This issue is fixed in version 6.1.0.","cveId":"CVE-2026-107297","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"npm","product":"msgpack5","affectedVersions":["pkg:npm/msgpack5 < 6.1.0"],"cwes":["CWE-407"],"tags":["nvd","status:received","osv","osv:ghsa-gcx5-hxj7-gpqq","ecosystem:npm","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mcollina/msgpack5/commit/e4827641d3105e295cbbd56e9c5389978547eab4","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-gcx5-hxj7-gpqq","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-gcx5-hxj7-gpqq","type":"advisory","title":"OSV GHSA-gcx5-hxj7-gpqq"},{"url":"https://github.com/mcollina/msgpack5","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:15.550Z","addedAt":"2026-10-08T18:39:31.730Z","updatedAt":"2026-10-08T21:05:51.280Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107297","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107297","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-GCX5-HXJ7-GPQQ"}]},{"id":"91e98c7c-a66c-4808-86da-b5dbd59ecb16","slug":"cve-2026-107296","externalId":"CVE-2026-107296","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107296 — msgpack5 is a msgpack v5 implementation for node.js and the browser.","description":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse encoded input for integrity checks, logging, or later processing can observe silently corrupted data, while positive integers and other MessagePack value types are unaffected. This issue is fixed in version 6.1.0.","cveId":"CVE-2026-107296","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"low","vendor":"npm","product":"msgpack5","affectedVersions":["pkg:npm/msgpack5 < 6.1.0"],"cwes":["CWE-471"],"tags":["nvd","status:received","osv","osv:ghsa-qw35-55vc-rhgj","ecosystem:npm","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mcollina/msgpack5/commit/82b70393a824e1088a45a377548d1d9ab82faf91","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-qw35-55vc-rhgj","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-qw35-55vc-rhgj","type":"advisory","title":"OSV GHSA-qw35-55vc-rhgj"},{"url":"https://github.com/mcollina/msgpack5","type":"vendor","title":"OSV package"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:15.390Z","addedAt":"2026-10-08T18:39:31.723Z","updatedAt":"2026-10-08T21:05:51.244Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107296","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107296","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-QW35-55VC-RHGJ"}]}],"pagination":{"page":1,"limit":20,"total":8629,"totalPages":432,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:44:00.545Z","durationMs":65,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":["ecosystem:npm"],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}