{"grype_matches":[{"artifact":{"id":"8eb994576ac287e7","cpes":["cpe:2.3:a:http-cache-semantics_project:http-cache-semantics:4.2.0:*:*:*:*:node.js:*:*"],"name":"http-cache-semantics","purl":"pkg:npm/http-cache-semantics@4.2.0","type":"npm","version":"4.2.0","language":"javascript","licenses":["BSD-2-Clause"],"locations":[{"path":"/opt/bitnami/node/lib/node_modules/npm/node_modules/http-cache-semantics/package.json","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/node/lib/node_modules/npm/node_modules/http-cache-semantics/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-ch52-4w7c-c8xp","versionConstraint":"<=4.2.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"http-cache-semantics","version":"4.2.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-ch52-4w7c-c8xp","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93748","cwe":"CWE-524","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93748","date":"2026-10-08","epss":0.00531,"percentile":0.43107}],"risk":0.41418,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-93748","https://github.com/kornelski/http-cache-semantics/issues/56","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L425-L441","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L603-L623","https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-user-cache-disclosure-via-max-stale"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-ch52-4w7c-c8xp","description":"http-cache-semantics max-stale handling can disclose cross-user cached responses"},"relatedVulnerabilities":[{"id":"CVE-2026-93748","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93748","cwe":"CWE-524","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93748","date":"2026-10-08","epss":0.00531,"percentile":0.43107}],"urls":["https://github.com/kornelski/http-cache-semantics","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L425-L441","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L603-L623","https://github.com/kornelski/http-cache-semantics/issues/56","https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-user-cache-disclosure-via-max-stale"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93748","description":"http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons."}]},{"artifact":{"id":"python","cpes":["cpe:2.3:*:python:python:3.14.8:*:*:*:*:*:*:*"],"name":"python","purl":"pkg:bitnami/python@3.14.8-2?arch=amd64&distro=photon-5","type":"bitnami","version":"3.14.8-2","language":"","licenses":["PSF-2.0","PSF-2.0"],"locations":[{"path":"/opt/bitnami/python/.spdx-python.spdx","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/python/.spdx-python.spdx","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.10.22"},"type":"exact-direct-match","found":{"vulnerabilityID":"BIT-python-2026-87910","versionConstraint":"<3.10.22||>=3.11.0,<3.11.17||>=3.12.0,<3.12.15||>=3.13.0,<3.13.16||>=3.14.0 (bitnami)"},"matcher":"bitnami-matcher","searchedBy":{"package":{"name":"python","version":"3.14.8-2"},"language":"","namespace":"bitnami"}}],"vulnerability":{"id":"BIT-python-2026-87910","fix":{"state":"fixed","versions":["3.10.22","3.11.17","3.12.15","3.13.16"],"available":[{"date":"2026-09-17","kind":"advisory","version":"3.10.22"},{"date":"2026-09-17","kind":"advisory","version":"3.11.17"},{"date":"2026-09-17","kind":"advisory","version":"3.12.15"},{"date":"2026-09-17","kind":"advisory","version":"3.13.16"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.344005,"urls":["https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","https://nvd.nist.gov/vuln/detail/CVE-2026-87910","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3"],"severity":"Medium","namespace":"bitnami","advisories":[],"dataSource":"http://www.openwall.com/lists/oss-security/2026/09/11/8","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"23b480e61fc6e948","cpes":["cpe:2.3:a:nodejs:undici:6.28.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.28.0","type":"npm","version":"6.28.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/opt/bitnami/node/lib/node_modules/npm/node_modules/undici/package.json","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/node/lib/node_modules/npm/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rfgv-xxqx-mfg5","versionConstraint":">=6.7.0,<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.28.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rfgv-xxqx-mfg5","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19534","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-19534","cwe":"CWE-252","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-19534","date":"2026-10-08","epss":0.00394,"percentile":0.31457}],"risk":0.29550000000000004,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5","https://nvd.nist.gov/vuln/detail/CVE-2026-19534","https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5","https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728","https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rfgv-xxqx-mfg5","description":"undici vulnerable to Denial of Service via unrequested WebSocket subprotocol"},"relatedVulnerabilities":[{"id":"CVE-2026-19534","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19534","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-19534","cwe":"CWE-252","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-19534","date":"2026-10-08","epss":0.00394,"percentile":0.31457}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19534","description":"undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]},{"artifact":{"id":"82968d107994d1f1","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.9:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.9","type":"npm","version":"5.0.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/opt/bitnami/node/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/node/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6j4f-fj2g-mc7p","versionConstraint":">=4.0.0,<5.0.10 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-6j4f-fj2g-mc7p","fix":{"state":"fixed","versions":["5.0.10"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p","https://nvd.nist.gov/vuln/detail/CVE-2026-102276","https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6j4f-fj2g-mc7p","description":"brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102276","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"urls":["https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102276","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns containing many comma-separated brace groups trigger the recursive path, while the large array triggers the argument-array path without deep recursion. These paths cause recursive and argument-array native stack exhaustion before max or maxLength can limit output, potentially terminating the Node.js process in a process-terminating denial of service. This issue is fixed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10."}]},{"artifact":{"id":"82968d107994d1f1","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.9:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.9","type":"npm","version":"5.0.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/opt/bitnami/node/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/node/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qhr7-859c-m2p7","versionConstraint":">=4.0.0,<5.0.11 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-qhr7-859c-m2p7","fix":{"state":"fixed","versions":["5.0.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7","https://nvd.nist.gov/vuln/detail/CVE-2026-102278","https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qhr7-859c-m2p7","description":"brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102278","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-08","epss":0.0035,"percentile":0.26598}],"urls":["https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102278","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11."}]},{"artifact":{"id":"2356f4705916c657","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.5.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.5.0","type":"npm","version":"10.5.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/opt/bitnami/node/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/node/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.5.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2vr4-cq9g-pvrc","versionConstraint":">=10.2.0,<=10.5.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.5.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-2vr4-cq9g-pvrc","fix":{"state":"fixed","versions":["10.5.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"10.5.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101910","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101910","date":"2026-10-08","epss":0.00386,"percentile":0.3054}],"risk":0.22967,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-2vr4-cq9g-pvrc","https://nvd.nist.gov/vuln/detail/CVE-2026-101910","https://github.com/beaugunderson/ip-address/commit/ab3dc88bcf5374344168a2ba075ca7ac4ff257f8","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2vr4-cq9g-pvrc","description":"ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass"},"relatedVulnerabilities":[{"id":"CVE-2026-101910","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101910","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101910","date":"2026-10-08","epss":0.00386,"percentile":0.3054}],"urls":["https://github.com/beaugunderson/ip-address/commit/ab3dc88bcf5374344168a2ba075ca7ac4ff257f8","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-2vr4-cq9g-pvrc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101910","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48. Applications that combine isPrivate, isLoopback, and isLinkLocal for a trust-boundary decision can treat an internal IPv4 destination encoded through that range as external. Exploitation depends on a server network using an operator-selected NAT64 prefix within the local-use range. A successful bypass can cross the intended network trust boundary. This issue is fixed in version 10.5.1."}]},{"artifact":{"id":"23b480e61fc6e948","cpes":["cpe:2.3:a:nodejs:undici:6.28.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.28.0","type":"npm","version":"6.28.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/opt/bitnami/node/lib/node_modules/npm/node_modules/undici/package.json","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/node/lib/node_modules/npm/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3wwx-pv8p-q78v","versionConstraint":">=6.25.0,<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.28.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-3wwx-pv8p-q78v","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85024","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-85024","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v","https://nvd.nist.gov/vuln/detail/CVE-2026-85024","https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c","https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6","https://github.com/nodejs/undici/commit/63cf698b611fecc6ee0a17b185b930051e4b982f","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3wwx-pv8p-q78v","description":"undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression"},"relatedVulnerabilities":[{"id":"CVE-2026-85024","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85024","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-85024","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85024","description":"undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]},{"artifact":{"id":"2356f4705916c657","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.5.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.5.0","type":"npm","version":"10.5.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/opt/bitnami/node/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/node/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.5.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rpw4-54j3-4h4q","versionConstraint":"<=10.5.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.5.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rpw4-54j3-4h4q","fix":{"state":"fixed","versions":["10.5.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"10.5.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101913","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101913","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101913","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"risk":0.21809,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-rpw4-54j3-4h4q","https://nvd.nist.gov/vuln/detail/CVE-2026-101913","https://github.com/beaugunderson/ip-address/commit/d03e960c7cc3179ef25c8a44b4f94dd499625546","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rpw4-54j3-4h4q","description":"ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts"},"relatedVulnerabilities":[{"id":"CVE-2026-101913","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101913","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101913","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101913","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"urls":["https://github.com/beaugunderson/ip-address/commit/d03e960c7cc3179ef25c8a44b4f94dd499625546","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-rpw4-54j3-4h4q"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101913","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the complete fe80::/10 IPv6 link-local range. An attacker-controlled address elsewhere in fe80::/10 can therefore pass a trust-boundary check that relies on isLinkLocal. The same address is identified as link-local by getType and getScope, exposing the inconsistent classification. A successful bypass can reach an on-link host outside the intended trust boundary. This issue is fixed in version 10.5.1."}]},{"artifact":{"id":"a3f3380090c52bef","cpes":["cpe:2.3:a:postcss-selector-parser:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector-parser:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector_parser:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector_parser:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss:postcss-selector-parser:7.1.4:*:*:*:*:*:*:*","cpe:2.3:a:postcss:postcss_selector_parser:7.1.4:*:*:*:*:*:*:*"],"name":"postcss-selector-parser","purl":"pkg:npm/postcss-selector-parser@7.1.4","type":"npm","version":"7.1.4","language":"javascript","licenses":["MIT"],"locations":[{"path":"/opt/bitnami/node/lib/node_modules/npm/node_modules/postcss-selector-parser/package.json","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/node/lib/node_modules/npm/node_modules/postcss-selector-parser/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.1.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rj75-hqrm-r3gf","versionConstraint":"<7.1.6 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"postcss-selector-parser","version":"7.1.4"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rj75-hqrm-r3gf","fix":{"state":"fixed","versions":["7.1.6"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"7.1.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104844","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-104844","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104844","date":"2026-10-08","epss":0.00394,"percentile":0.31424}],"risk":0.21473,"urls":["https://github.com/postcss/postcss-selector-parser/security/advisories/GHSA-rj75-hqrm-r3gf","https://nvd.nist.gov/vuln/detail/CVE-2026-104844","https://github.com/postcss/postcss-selector-parser/commit/62b191792df0a0bc56062e5a875bc74aae2a51cd","https://github.com/postcss/postcss-selector-parser/releases/tag/7.1.6"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rj75-hqrm-r3gf","description":"PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-104844","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104844","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-104844","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104844","date":"2026-10-08","epss":0.00394,"percentile":0.31424}],"urls":["https://github.com/postcss/postcss-selector-parser/commit/62b191792df0a0bc56062e5a875bc74aae2a51cd","https://github.com/postcss/postcss-selector-parser/releases/tag/7.1.6","https://github.com/postcss/postcss-selector-parser/security/advisories/GHSA-rj75-hqrm-r3gf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104844","description":"PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior to 7.1.6, src/parser.js splitWord() can receive a flat selector as one word token carrying many class or ID indexes because period and hash characters are not tokenizer word delimiters. The uniqs() deduplication and per-index class and ID membership checks repeatedly scan the class and ID index arrays, while a separate Sass-interpolation filtering pass also performs repeated linear scanning. Together, these passes make parsing quadratic in the number of indexes and allow a crafted selector to occupy a synchronous parser thread. The maxNestingDepth guard does not mitigate the issue because the hostile selector can have zero nesting depth. Only consumers that synchronously parse untrusted selectors in an exposed request path are affected; ordinary build-time parsing of trusted sources is not affected. This issue is fixed in version 7.1.6."}]},{"artifact":{"id":"2356f4705916c657","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.5.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.5.0","type":"npm","version":"10.5.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/opt/bitnami/node/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/node/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j6r3-76f7-8jcv","versionConstraint":"<=10.7.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.5.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-j6r3-76f7-8jcv","fix":{"state":"fixed","versions":["10.7.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101912","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101912","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101912","date":"2026-10-08","epss":0.0037,"percentile":0.28846}],"risk":0.20904999999999999,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-j6r3-76f7-8jcv","https://nvd.nist.gov/vuln/detail/CVE-2026-101912","https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j6r3-76f7-8jcv","description":"ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range"},"relatedVulnerabilities":[{"id":"CVE-2026-101912","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101912","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101912","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101912","date":"2026-10-08","epss":0.0037,"percentile":0.28846}],"urls":["https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-j6r3-76f7-8jcv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101912","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings without validating that both operands use the same IP family. A cross-family containment check whose leading address bits match makes the masked strings compare equal even though IPv4 and IPv6 do not share an address space. An allowlist or denylist decision can therefore classify an address outside the intended range as contained. This issue is fixed in version 10.7.1."}]},{"artifact":{"id":"2356f4705916c657","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.5.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.5.0","type":"npm","version":"10.5.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/opt/bitnami/node/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/node/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h3mg-xc3c-68pw","versionConstraint":"<=10.7.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.5.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-h3mg-xc3c-68pw","fix":{"state":"fixed","versions":["10.7.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101911","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101911","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101911","date":"2026-10-08","epss":0.00301,"percentile":0.20955}],"risk":0.170065,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-h3mg-xc3c-68pw","https://nvd.nist.gov/vuln/detail/CVE-2026-101911","https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134","https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h3mg-xc3c-68pw","description":"ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process"},"relatedVulnerabilities":[{"id":"CVE-2026-101911","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101911","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101911","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101911","date":"2026-10-08","epss":0.00301,"percentile":0.20955}],"urls":["https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134","https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-h3mg-xc3c-68pw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101911","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid characters through RE_BAD_CHARACTERS into large diagnostics. Material impact occurs only when an application accepts a very large attacker-controlled field and passes it to Address6 parsing without an earlier length bound. Common URL and header limits, and common body-parser defaults, generally constrain the effect; common defaults typically exclude 32 MiB fields. Megabyte-scale fields can cause a synchronous stall and high transient memory use, approximately 16 MiB can trigger an invalid string length exception, and process termination occurs at approximately 32 MiB. The affected entry points include Address6.isValid and construction paths that reach parse. This issue is fixed in version 10.7.1."}]},{"artifact":{"id":"82968d107994d1f1","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.9:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.9","type":"npm","version":"5.0.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/opt/bitnami/node/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/node/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q2hr-2g5m-vwhr","versionConstraint":">=4.0.0,<5.0.12 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-q2hr-2g5m-vwhr","fix":{"state":"fixed","versions":["5.0.12"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-08","epss":0.00301,"percentile":0.20956}],"risk":0.15501500000000001,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr","https://nvd.nist.gov/vuln/detail/CVE-2026-102277","https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q2hr-2g5m-vwhr","description":"brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-102277","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-08","epss":0.00301,"percentile":0.20956}],"urls":["https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102277","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12."}]},{"artifact":{"id":"python","cpes":["cpe:2.3:*:python:python:3.14.8:*:*:*:*:*:*:*"],"name":"python","purl":"pkg:bitnami/python@3.14.8-2?arch=amd64&distro=photon-5","type":"bitnami","version":"3.14.8-2","language":"","licenses":["PSF-2.0","PSF-2.0"],"locations":[{"path":"/opt/bitnami/python/.spdx-python.spdx","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/python/.spdx-python.spdx","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.15.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"BIT-python-2026-12345","versionConstraint":"<3.15.0 (bitnami)"},"matcher":"bitnami-matcher","searchedBy":{"package":{"name":"python","version":"3.14.8-2"},"language":"","namespace":"bitnami"}}],"vulnerability":{"id":"BIT-python-2026-12345","fix":{"state":"fixed","versions":["3.15.0"],"available":[{"date":"2026-10-05","kind":"advisory","version":"3.15.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.0981,"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","https://nvd.nist.gov/vuln/detail/CVE-2026-12345"],"severity":"Medium","namespace":"bitnami","advisories":[],"dataSource":"http://www.openwall.com/lists/oss-security/2026/09/29/40","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"23b480e61fc6e948","cpes":["cpe:2.3:a:nodejs:undici:6.28.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.28.0","type":"npm","version":"6.28.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/opt/bitnami/node/lib/node_modules/npm/node_modules/undici/package.json","layerID":"sha256:86795d7582e59822dd400852c53f9967c737e9c3dc188bae90b509c35331fe40","accessPath":"/opt/bitnami/node/lib/node_modules/npm/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r53p-7pc4-xj5r","versionConstraint":"<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.28.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-r53p-7pc4-xj5r","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18540","cwe":"CWE-444","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-18540","date":"2026-10-08","epss":0.00239,"percentile":0.13769}],"risk":0.080065,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r","https://nvd.nist.gov/vuln/detail/CVE-2026-18540","https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329","https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95","https://github.com/nodejs/undici/commit/ce31bc824b578008faae5d3350da66c1b5f71548","https://hackerone.com/reports/3900104","https://hackerone.com/reports/3900615","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"Low","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r53p-7pc4-xj5r","description":"undici vulnerable to downstream response splitting via retry interceptor"},"relatedVulnerabilities":[{"id":"CVE-2026-18540","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18540","cwe":"CWE-444","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-18540","date":"2026-10-08","epss":0.00239,"percentile":0.13769}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18540","description":"undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. This happens when an upstream server delivers part of a body without a trustworthy resume checkpoint, for example a non-success response whose headers were already sent or a partial-content response with an unusable content range, then closes the connection and answers the resumed range request with more bytes. As a result the response body can be longer than the Content-Length that the application observes. An application that relays such a response to a downstream HTTP/1.1 peer without normalizing the framing can emit a body that exceeds the forwarded Content-Length, and the excess bytes can be interpreted as the start of a following response, which enables downstream response splitting or desynchronization. Exploitation requires an attacker-controlled upstream server and an application that forwards the response through a framing-sensitive path. This affects undici versions before 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]}],"grade":"C","score":"69.00","as_of":"2026-10-09T22:26:48.843Z","grype_db_version":"2026-10-09T06:32:32.000Z"}