|
209 | 209 | <error |
210 | 210 | source="vulnerability_medium" |
211 | 211 | line="3" |
212 | | - message="Insecure dependency golang/stdlib@v1.21.4 (CVE-2026-32281: crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation) (update to 1.25.9)" |
| 212 | + message="Insecure dependency golang/stdlib@v1.21.4 (CVE-2026-32288: archive/tar: golang: Go's archive/tar package: Denial of Service via maliciously-crafted archive) (update to 1.25.9)" |
213 | 213 | severity="warning" |
214 | 214 | /> |
215 | 215 | <error |
216 | 216 | source="vulnerability_medium" |
217 | 217 | line="3" |
218 | | - message="Insecure dependency golang/stdlib@v1.21.4 (CVE-2026-32288: archive/tar: golang: Go's archive/tar package: Denial of Service via maliciously-crafted archive) (update to 1.25.9)" |
| 218 | + message="Insecure dependency golang/stdlib@v1.21.4 (CVE-2026-32289: html/template: golang: html/template: Cross-Site Scripting (XSS) via improper context and brace depth tracking in JS template literals) (update to 1.25.9)" |
219 | 219 | severity="warning" |
220 | 220 | /> |
221 | 221 | <error |
222 | 222 | source="vulnerability_medium" |
223 | 223 | line="3" |
224 | | - message="Insecure dependency golang/stdlib@v1.21.4 (CVE-2026-32289: html/template: golang: html/template: Cross-Site Scripting (XSS) via improper context and brace depth tracking in JS template literals) (update to 1.25.9)" |
| 224 | + message="Insecure dependency golang/stdlib@v1.21.4 (CVE-2025-22870: golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net) (update to 1.23.7)" |
| 225 | + severity="warning" |
| 226 | + /> |
| 227 | + <error |
| 228 | + source="vulnerability_medium" |
| 229 | + line="3" |
| 230 | + message="Insecure dependency golang/stdlib@v1.21.4 (CVE-2026-32282: golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root) (update to 1.25.9)" |
225 | 231 | severity="warning" |
226 | 232 | /> |
227 | 233 | </file> |
|
287 | 293 | message="Insecure dependency npm/axios@0.21.0 (CVE-2020-28168: nodejs-axios: allows an attacker to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address) (update to 0.21.1)" |
288 | 294 | severity="warning" |
289 | 295 | /> |
| 296 | + <error |
| 297 | + source="vulnerability_medium" |
| 298 | + line="14" |
| 299 | + message="Insecure dependency npm/axios@0.21.0 (CVE-2025-62718: axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization) (update to 0.31.0)" |
| 300 | + severity="warning" |
| 301 | + /> |
| 302 | + <error |
| 303 | + source="vulnerability_medium" |
| 304 | + line="14" |
| 305 | + message="Insecure dependency npm/axios@0.21.0 (CVE-2026-40175: axios: Axios: Remote Code Execution via Prototype Pollution escalation) (update to 0.31.0)" |
| 306 | + severity="warning" |
| 307 | + /> |
290 | 308 | <error |
291 | 309 | source="vulnerability_medium" |
292 | 310 | line="14" |
|
314 | 332 | message="Insecure dependency npm/axios@0.21.0 (CVE-2023-45857: axios: exposure of confidential data stored in cookies) (update to 0.28.0)" |
315 | 333 | severity="warning" |
316 | 334 | /> |
| 335 | + <error |
| 336 | + source="vulnerability_medium" |
| 337 | + line="5" |
| 338 | + message="Insecure dependency npm/axios@0.21.0 (CVE-2025-62718: axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization) (update to 0.31.0)" |
| 339 | + severity="warning" |
| 340 | + /> |
| 341 | + <error |
| 342 | + source="vulnerability_medium" |
| 343 | + line="5" |
| 344 | + message="Insecure dependency npm/axios@0.21.0 (CVE-2026-40175: axios: Axios: Remote Code Execution via Prototype Pollution escalation) (update to 0.31.0)" |
| 345 | + severity="warning" |
| 346 | + /> |
317 | 347 | <error |
318 | 348 | source="vulnerability_medium" |
319 | 349 | line="12" |
|
0 commit comments