Skip to content

Commit c55e1c1

Browse files
vuln: update deps index.json (#1547)
Co-authored-by: Create or Update Pull Request Action <create-or-update-pull-request@users.noreply.github.com>
1 parent a76d920 commit c55e1c1

File tree

1 file changed

+59
-59
lines changed

1 file changed

+59
-59
lines changed

vuln/deps/index.json

Lines changed: 59 additions & 59 deletions
Original file line numberDiff line numberDiff line change
@@ -1,61 +1,61 @@
11
{
2-
"1": {
3-
"cve": [
4-
"CVE-2023-45853"
5-
],
6-
"description": "MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field.",
7-
"overview": "This CVE was created for MiniZip (part of zlib/contrib/minizip), which is not used by Node.js. Node.js uses zlib for compression but does not use the MiniZip component where this vulnerability exists.",
8-
"ref": "https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/205",
9-
"reason": "vulnerable_code_not_present"
10-
},
11-
"2": {
12-
"cve": [
13-
"CVE-2024-7535"
14-
],
15-
"description": "Inappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
16-
"overview": "This V8 vulnerability does not fall within Node.js's threat model. The vulnerable code path is not exposed through Node.js APIs and cannot be exploited in normal Node.js usage.",
17-
"ref": "https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/190",
18-
"reason": "vulnerable_code_not_in_execute_path"
19-
},
20-
"3": {
21-
"cve": [
22-
"CVE-2024-4761",
23-
"CVE-2024-4947",
24-
"CVE-2024-5274"
25-
],
26-
"description": "Out of bounds write in V8. Type Confusion in V8. Type confusion in V8 in Google Chrome.",
27-
"overview": "These V8 vulnerabilities do not fall within Node.js's threat model. The vulnerable code paths are not exposed through Node.js APIs.",
28-
"ref": "https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/191",
29-
"reason": "vulnerable_code_not_in_execute_path"
30-
},
31-
"4": {
32-
"cve": [
33-
"CVE-2024-3159",
34-
"CVE-2024-3156"
35-
],
36-
"description": "V8 vulnerabilities in JavaScript engine",
37-
"overview": "These V8 vulnerabilities do not affect Node.js. The vulnerable functionality is not exposed in Node.js's implementation.",
38-
"ref": "https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/184",
39-
"reason": "vulnerable_code_not_in_execute_path"
40-
},
41-
"5": {
42-
"cve": [
43-
"CVE-2024-13176"
44-
],
45-
"description": "OpenSSL security vulnerability",
46-
"overview": "This OpenSSL vulnerability does not affect Node.js. Node.js's usage of OpenSSL does not trigger the vulnerable code path.",
47-
"ref": "https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/201",
48-
"reason": "vulnerable_code_not_in_execute_path"
49-
},
50-
"6": {
51-
"cve": [
52-
"CVE-2025-9230",
53-
"CVE-2025-9231",
54-
"CVE-2025-9232"
55-
],
56-
"description": "OpenSSL security vulnerabilities",
57-
"overview": "These OpenSSL vulnerabilities do not affect Node.js. Node.js's usage of OpenSSL does not trigger the vulnerable code paths.",
58-
"ref": "https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/213",
59-
"reason": "vulnerable_code_not_in_execute_path"
60-
}
2+
"1": {
3+
"cve": [
4+
"CVE-2023-45853"
5+
],
6+
"description": "MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field.",
7+
"overview": "This CVE was created for MiniZip (part of zlib/contrib/minizip), which is not used by Node.js. Node.js uses zlib for compression but does not use the MiniZip component where this vulnerability exists.",
8+
"ref": "https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/205",
9+
"reason": "vulnerable_code_not_present"
10+
},
11+
"2": {
12+
"cve": [
13+
"CVE-2024-7535"
14+
],
15+
"description": "Inappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.",
16+
"overview": "This V8 vulnerability does not fall within Node.js's threat model. The vulnerable code path is not exposed through Node.js APIs and cannot be exploited in normal Node.js usage.",
17+
"ref": "https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/190",
18+
"reason": "vulnerable_code_not_in_execute_path"
19+
},
20+
"3": {
21+
"cve": [
22+
"CVE-2024-4761",
23+
"CVE-2024-4947",
24+
"CVE-2024-5274"
25+
],
26+
"description": "Out of bounds write in V8. Type Confusion in V8. Type confusion in V8 in Google Chrome.",
27+
"overview": "These V8 vulnerabilities do not fall within Node.js's threat model. The vulnerable code paths are not exposed through Node.js APIs.",
28+
"ref": "https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/191",
29+
"reason": "vulnerable_code_not_in_execute_path"
30+
},
31+
"4": {
32+
"cve": [
33+
"CVE-2024-3159",
34+
"CVE-2024-3156"
35+
],
36+
"description": "V8 vulnerabilities in JavaScript engine",
37+
"overview": "These V8 vulnerabilities do not affect Node.js. The vulnerable functionality is not exposed in Node.js's implementation.",
38+
"ref": "https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/184",
39+
"reason": "vulnerable_code_not_in_execute_path"
40+
},
41+
"5": {
42+
"cve": [
43+
"CVE-2024-13176"
44+
],
45+
"description": "OpenSSL security vulnerability",
46+
"overview": "This OpenSSL vulnerability does not affect Node.js. Node.js's usage of OpenSSL does not trigger the vulnerable code path.",
47+
"ref": "https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/201",
48+
"reason": "vulnerable_code_not_in_execute_path"
49+
},
50+
"6": {
51+
"cve": [
52+
"CVE-2025-9230",
53+
"CVE-2025-9231",
54+
"CVE-2025-9232"
55+
],
56+
"description": "OpenSSL security vulnerabilities",
57+
"overview": "These OpenSSL vulnerabilities do not affect Node.js. Node.js's usage of OpenSSL does not trigger the vulnerable code paths.",
58+
"ref": "https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/213",
59+
"reason": "vulnerable_code_not_in_execute_path"
60+
}
6161
}

0 commit comments

Comments
 (0)