Front page — listed in the CISA KEV catalog: treat as actively exploited
No remedy — no published fix; upgrading cannot close these
Highest severity — CVSS base score 8.0 and above
Dispatch
Paramiko not properly checking authentication before processing other requests
9.8 / CVSS 3.x
Dispatch
Prototype Pollution in minimist
9.8 / CVSS 3.x
Dispatch
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
9 / CVSS 3.x
Dispatch
Paramiko Authentication Bypass vulnerability
8.8 / CVSS 3.x
Dispatch
node-fetch forwards secure headers to untrusted sites
8.8 / CVSS 3.x
Dispatch
jsonwebtoken unrestricted key type could lead to legacy keys usage
8.1 / CVSS 3.x
Latest dispatches — newest advisories in the dataset
Dispatch
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
0 / CVSS n/a
Dispatch
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
9 / CVSS 3.x
Dispatch
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
6.1 / CVSS 3.x
Dispatch
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
5.4 / CVSS 3.x
Dispatch
undici vulnerable to CRLF Injection via blob-like body 'type' property
4.2 / CVSS 3.x
Dispatch
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
5.9 / CVSS 3.x
Dispatch
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
4.8 / CVSS 3.x
Dispatch
undici vulnerable to downstream response desynchronization via retry interceptor
4.8 / CVSS 3.x
Dispatch
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
7.4 / CVSS 3.x
Dispatch
Next.js: Server-Side Request Forgery in Server Actions on custom servers
0 / CVSS n/a
Dispatch
Next.js: Cache confusion of response bodies for requests with bodies
0 / CVSS n/a
Dispatch
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
0 / CVSS n/a
Edition #82 — 16 packages tracked, 1 actively exploited, 1 without a fix. The newsroom →