{
 "arch": "amd64",
 "findings": [
  {
   "affects": [
    "seroval"
   ],
   "cvss": 9.8,
   "distro_severity": "critical",
   "fix_state": "fixed",
   "fixed_in": [
    "1.5.3"
   ],
   "id": "GHSA-mv8w-475r-vwqw",
   "severity": "critical",
   "title": "seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization",
   "url": "https://github.com/advisories/GHSA-mv8w-475r-vwqw"
  },
  {
   "affects": [
    "ip-address"
   ],
   "cvss": 7.7,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "10.3.1"
   ],
   "id": "GHSA-mwp4-54f8-5fhr",
   "severity": "high",
   "title": "ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass",
   "url": "https://github.com/advisories/GHSA-mwp4-54f8-5fhr"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 7.5,
   "distro_severity": "critical",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.19"
   ],
   "id": "GHSA-23hp-3jrh-7fpw",
   "severity": "high",
   "title": "node-tar: Decompression/parse DoS via unlimited input",
   "url": "https://github.com/advisories/GHSA-23hp-3jrh-7fpw"
  },
  {
   "affects": [
    "socket.io-parser"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "4.2.7"
   ],
   "id": "GHSA-2m8v-j782-fhvr",
   "severity": "high",
   "title": "Socket.IO: Zero-attachment Memory Exhaustion",
   "url": "https://github.com/advisories/GHSA-2m8v-j782-fhvr"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "8.5.0"
   ],
   "id": "GHSA-38rv-x7px-6hhq",
   "severity": "high",
   "title": "undici WebSocket client vulnerable to denial of service via cumulative fragment bypass",
   "url": "https://github.com/advisories/GHSA-38rv-x7px-6hhq"
  },
  {
   "affects": [
    "seroval"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.4.1"
   ],
   "id": "GHSA-3j22-8qj3-26mx",
   "severity": "high",
   "title": "Seroval affected by Denial of Service via Deeply Nested Objects",
   "url": "https://github.com/advisories/GHSA-3j22-8qj3-26mx"
  },
  {
   "affects": [
    "seroval"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.4.1"
   ],
   "id": "GHSA-3rxj-6cgf-8cfw",
   "severity": "high",
   "title": "seroval Affected by Remote Code Execution via JSON Deserialization",
   "url": "https://github.com/advisories/GHSA-3rxj-6cgf-8cfw"
  },
  {
   "affects": [
    "fast-uri"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.1.3"
   ],
   "id": "GHSA-4c8g-83qw-93j6",
   "severity": "high",
   "title": "fast-uri vulnerable to host confusion via failed IDN canonicalization",
   "url": "https://github.com/advisories/GHSA-4c8g-83qw-93j6"
  },
  {
   "affects": [
    "js-yaml"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.15.0"
   ],
   "id": "GHSA-52cp-r559-cp3m",
   "severity": "high",
   "title": "js-yaml: YAML merge-key chains can force quadratic CPU consumption",
   "url": "https://github.com/advisories/GHSA-52cp-r559-cp3m"
  },
  {
   "affects": [
    "js-yaml"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.15.1"
   ],
   "id": "GHSA-5p4m-2wfm-xmqj",
   "severity": "high",
   "title": "JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) \u2014 CVE-2026-59870 fix not backported",
   "url": "https://github.com/advisories/GHSA-5p4m-2wfm-xmqj"
  },
  {
   "affects": [
    "seroval"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.4.1"
   ],
   "id": "GHSA-66fc-rw6m-c2q6",
   "severity": "high",
   "title": "Seroval affected by Denial of Service via Array serialization",
   "url": "https://github.com/advisories/GHSA-66fc-rw6m-c2q6"
  },
  {
   "affects": [
    "fast-uri"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.1.5"
   ],
   "id": "GHSA-7p8r-x3mc-p8w7",
   "severity": "high",
   "title": "fast-uri vulnerable to host confusion via backslash authority introducer",
   "url": "https://github.com/advisories/GHSA-7p8r-x3mc-p8w7"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.18"
   ],
   "id": "GHSA-8x88-c5mf-7j5w",
   "severity": "high",
   "title": "node-tar: Negative tar entry size causes infinite loop in archive replace",
   "url": "https://github.com/advisories/GHSA-8x88-c5mf-7j5w"
  },
  {
   "affects": [
    "ws"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "8.21.0"
   ],
   "id": "GHSA-96hv-2xvq-fx4p",
   "severity": "high",
   "title": "ws: Memory exhaustion DoS from tiny fragments and data chunks",
   "url": "https://github.com/advisories/GHSA-96hv-2xvq-fx4p"
  },
  {
   "affects": [
    "find-my-way"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "9.7.0"
   ],
   "id": "GHSA-c96f-x56v-gq3h",
   "severity": "high",
   "title": "find-my-way: DDoS with HTTP2",
   "url": "https://github.com/advisories/GHSA-c96f-x56v-gq3h"
  },
  {
   "affects": [
    "seroval"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.4.1"
   ],
   "id": "GHSA-hx9m-jf43-8ffr",
   "severity": "high",
   "title": "seroval affected by Denial of Service via RegExp serialization",
   "url": "https://github.com/advisories/GHSA-hx9m-jf43-8ffr"
  },
  {
   "affects": [
    "brace-expansion"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "2.1.3"
   ],
   "id": "GHSA-mh99-v99m-4gvg",
   "severity": "high",
   "title": "brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash",
   "url": "https://github.com/advisories/GHSA-mh99-v99m-4gvg"
  },
  {
   "affects": [
    "brace-expansion"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "5.0.8"
   ],
   "id": "GHSA-mh99-v99m-4gvg",
   "severity": "high",
   "title": "brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash",
   "url": "https://github.com/advisories/GHSA-mh99-v99m-4gvg"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.21"
   ],
   "id": "GHSA-r292-9mhp-454m",
   "severity": "high",
   "title": "node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection",
   "url": "https://github.com/advisories/GHSA-r292-9mhp-454m"
  },
  {
   "affects": [
    "brace-expansion"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "2.1.4"
   ],
   "id": "GHSA-rgw5-rvv9-x895",
   "severity": "high",
   "title": "brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation",
   "url": "https://github.com/advisories/GHSA-rgw5-rvv9-x895"
  },
  {
   "affects": [
    "brace-expansion"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "5.0.9"
   ],
   "id": "GHSA-rgw5-rvv9-x895",
   "severity": "high",
   "title": "brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation",
   "url": "https://github.com/advisories/GHSA-rgw5-rvv9-x895"
  },
  {
   "affects": [
    "fast-uri"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "3.1.4"
   ],
   "id": "GHSA-v2hh-gcrm-f6hx",
   "severity": "high",
   "title": "fast-uri vulnerable to host confusion via literal backslash authority delimiter",
   "url": "https://github.com/advisories/GHSA-v2hh-gcrm-f6hx"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "6.24.0"
   ],
   "id": "GHSA-v9p9-hfj2-hcw8",
   "severity": "high",
   "title": "Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation",
   "url": "https://github.com/advisories/GHSA-v9p9-hfj2-hcw8"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "6.24.0"
   ],
   "id": "GHSA-vrm6-8vpv-qv8q",
   "severity": "high",
   "title": "Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression",
   "url": "https://github.com/advisories/GHSA-vrm6-8vpv-qv8q"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "6.27.0"
   ],
   "id": "GHSA-vxpw-j846-p89q",
   "severity": "high",
   "title": "undici WebSocket client vulnerable to denial of service via fragment count bypass",
   "url": "https://github.com/advisories/GHSA-vxpw-j846-p89q"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "6.27.0"
   ],
   "id": "GHSA-vxpw-j846-p89q",
   "severity": "high",
   "title": "undici WebSocket client vulnerable to denial of service via fragment count bypass",
   "url": "https://github.com/advisories/GHSA-vxpw-j846-p89q"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 7.5,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "8.5.0"
   ],
   "id": "GHSA-vxpw-j846-p89q",
   "severity": "high",
   "title": "undici WebSocket client vulnerable to denial of service via fragment count bypass",
   "url": "https://github.com/advisories/GHSA-vxpw-j846-p89q"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 7.4,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "8.9.0"
   ],
   "id": "GHSA-4cwx-7wf7-3272",
   "severity": "high",
   "title": "undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives",
   "url": "https://github.com/advisories/GHSA-4cwx-7wf7-3272"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 7.4,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "8.5.0"
   ],
   "id": "GHSA-vmh5-mc38-953g",
   "severity": "high",
   "title": "undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent",
   "url": "https://github.com/advisories/GHSA-vmh5-mc38-953g"
  },
  {
   "affects": [
    "seroval"
   ],
   "cvss": 7.3,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "1.4.1"
   ],
   "id": "GHSA-hj76-42vx-jwp4",
   "severity": "high",
   "title": "seroval Affected by Prototype Pollution via JSON Deserialization",
   "url": "https://github.com/advisories/GHSA-hj76-42vx-jwp4"
  },
  {
   "affects": [
    "hono"
   ],
   "cvss": 7.1,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "4.12.25"
   ],
   "id": "GHSA-88fw-hqm2-52qc",
   "severity": "high",
   "title": "hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard",
   "url": "https://github.com/advisories/GHSA-88fw-hqm2-52qc"
  },
  {
   "affects": [
    "ip-address"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "10.2.1"
   ],
   "id": "GHSA-22jq-vg5j-6vgg",
   "severity": "medium",
   "title": "ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks",
   "url": "https://github.com/advisories/GHSA-22jq-vg5j-6vgg"
  },
  {
   "affects": [
    "ip-address"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "10.2.2"
   ],
   "id": "GHSA-4xrf-jv44-h6hh",
   "severity": "medium",
   "title": "ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks",
   "url": "https://github.com/advisories/GHSA-4xrf-jv44-h6hh"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.3.2"
   ],
   "id": "GHSA-h8r8-wccr-v5f2",
   "severity": "medium",
   "title": "DOMPurify is vulnerable to mutation-XSS via Re-Contextualization",
   "url": "https://github.com/advisories/GHSA-h8r8-wccr-v5f2"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.4.0"
   ],
   "id": "GHSA-v9jr-rg53-9pgp",
   "severity": "medium",
   "title": "DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback",
   "url": "https://github.com/advisories/GHSA-v9jr-rg53-9pgp"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 6.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.16"
   ],
   "id": "GHSA-vmf3-w455-68vh",
   "severity": "medium",
   "title": "node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)",
   "url": "https://github.com/advisories/GHSA-vmf3-w455-68vh"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 6.8,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.4.0"
   ],
   "id": "GHSA-crv5-9vww-q3g8",
   "severity": "medium",
   "title": "DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode",
   "url": "https://github.com/advisories/GHSA-crv5-9vww-q3g8"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 6.5,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.24.0"
   ],
   "id": "GHSA-2mjp-6q6p-2qxm",
   "severity": "medium",
   "title": "Undici has an HTTP Request/Response Smuggling issue",
   "url": "https://github.com/advisories/GHSA-2mjp-6q6p-2qxm"
  },
  {
   "affects": [
    "hono"
   ],
   "cvss": 6.5,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.12.27"
   ],
   "id": "GHSA-hvrm-45r6-mjfj",
   "severity": "medium",
   "title": "hono/jsx does not isolate context per request, leading to cross-request data disclosure",
   "url": "https://github.com/advisories/GHSA-hvrm-45r6-mjfj"
  },
  {
   "affects": [
    "hono"
   ],
   "cvss": 6.5,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.12.25"
   ],
   "id": "GHSA-rv63-4mwf-qqc2",
   "severity": "medium",
   "title": "hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`",
   "url": "https://github.com/advisories/GHSA-rv63-4mwf-qqc2"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 6.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.4.7"
   ],
   "id": "GHSA-76mc-f452-cxcm",
   "severity": "medium",
   "title": "DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`",
   "url": "https://github.com/advisories/GHSA-76mc-f452-cxcm"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 6.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.4.6"
   ],
   "id": "GHSA-hpcv-96wg-7vj8",
   "severity": "medium",
   "title": "DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks",
   "url": "https://github.com/advisories/GHSA-hpcv-96wg-7vj8"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 6.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.4.6"
   ],
   "id": "GHSA-r47g-fvhr-h676",
   "severity": "medium",
   "title": "DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM",
   "url": "https://github.com/advisories/GHSA-r47g-fvhr-h676"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 6.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.3.2"
   ],
   "id": "GHSA-v2wj-7wpq-c8vv",
   "severity": "medium",
   "title": "DOMPurify contains a Cross-site Scripting vulnerability",
   "url": "https://github.com/advisories/GHSA-v2wj-7wpq-c8vv"
  },
  {
   "affects": [
    "hono"
   ],
   "cvss": 6.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.12.27"
   ],
   "id": "GHSA-w62v-xxxg-mg59",
   "severity": "medium",
   "title": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility",
   "url": "https://github.com/advisories/GHSA-w62v-xxxg-mg59"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 6.1,
   "distro_severity": "low",
   "fix_state": "not-fixed",
   "fixed_in": [],
   "id": "GHSA-x4vx-rjvf-j5p4",
   "severity": "medium",
   "title": "DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects",
   "url": "https://github.com/advisories/GHSA-x4vx-rjvf-j5p4"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 6.0,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.4.0"
   ],
   "id": "GHSA-h7mw-gpvr-xq4m",
   "severity": "medium",
   "title": "DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)",
   "url": "https://github.com/advisories/GHSA-h7mw-gpvr-xq4m"
  },
  {
   "affects": [
    "@hono/node-server"
   ],
   "cvss": 5.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "1.19.15"
   ],
   "id": "GHSA-frvp-7c67-39w9",
   "severity": "medium",
   "title": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)",
   "url": "https://github.com/advisories/GHSA-frvp-7c67-39w9"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 5.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.23.0"
   ],
   "id": "GHSA-g9mf-h72j-4rw9",
   "severity": "medium",
   "title": "Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion",
   "url": "https://github.com/advisories/GHSA-g9mf-h72j-4rw9"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 5.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "8.9.0"
   ],
   "id": "GHSA-jr45-8vmc-qm54",
   "severity": "medium",
   "title": "undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives",
   "url": "https://github.com/advisories/GHSA-jr45-8vmc-qm54"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 5.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.27.0"
   ],
   "id": "GHSA-p88m-4jfj-68fv",
   "severity": "medium",
   "title": "undici vulnerable to HTTP header injection via Set-Cookie percent-decoding",
   "url": "https://github.com/advisories/GHSA-p88m-4jfj-68fv"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 5.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.27.0"
   ],
   "id": "GHSA-p88m-4jfj-68fv",
   "severity": "medium",
   "title": "undici vulnerable to HTTP header injection via Set-Cookie percent-decoding",
   "url": "https://github.com/advisories/GHSA-p88m-4jfj-68fv"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 5.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "8.5.0"
   ],
   "id": "GHSA-p88m-4jfj-68fv",
   "severity": "medium",
   "title": "undici vulnerable to HTTP header injection via Set-Cookie percent-decoding",
   "url": "https://github.com/advisories/GHSA-p88m-4jfj-68fv"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 5.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "8.5.0"
   ],
   "id": "GHSA-pr7r-676h-xcf6",
   "severity": "medium",
   "title": "undici vulnerable to cross-user information disclosure via shared cache whitespace bypass",
   "url": "https://github.com/advisories/GHSA-pr7r-676h-xcf6"
  },
  {
   "affects": [
    "hono"
   ],
   "cvss": 5.9,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.12.25"
   ],
   "id": "GHSA-wwfh-h76j-fc44",
   "severity": "medium",
   "title": "hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)",
   "url": "https://github.com/advisories/GHSA-wwfh-h76j-fc44"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.4.0"
   ],
   "id": "GHSA-39q2-94rc-95cp",
   "severity": "medium",
   "title": "DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation",
   "url": "https://github.com/advisories/GHSA-39q2-94rc-95cp"
  },
  {
   "affects": [
    "brace-expansion"
   ],
   "cvss": 5.3,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "2.1.2"
   ],
   "id": "GHSA-3jxr-9vmj-r5cp",
   "severity": "medium",
   "title": "brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups",
   "url": "https://github.com/advisories/GHSA-3jxr-9vmj-r5cp"
  },
  {
   "affects": [
    "brace-expansion"
   ],
   "cvss": 5.3,
   "distro_severity": "high",
   "fix_state": "fixed",
   "fixed_in": [
    "5.0.7"
   ],
   "id": "GHSA-3jxr-9vmj-r5cp",
   "severity": "medium",
   "title": "brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups",
   "url": "https://github.com/advisories/GHSA-3jxr-9vmj-r5cp"
  },
  {
   "affects": [
    "hono"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.12.34"
   ],
   "id": "GHSA-54fx-42gc-7vw4",
   "severity": "medium",
   "title": "Hono: Algorithmic Complexity DoS in Language Middleware",
   "url": "https://github.com/advisories/GHSA-54fx-42gc-7vw4"
  },
  {
   "affects": [
    "@opentelemetry/core"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "2.8.0"
   ],
   "id": "GHSA-8988-4f7v-96qf",
   "severity": "medium",
   "title": "OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation",
   "url": "https://github.com/advisories/GHSA-8988-4f7v-96qf"
  },
  {
   "affects": [
    "hono"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.12.34"
   ],
   "id": "GHSA-8j4g-w8fx-2239",
   "severity": "medium",
   "title": "Hono: ReDoS in CORS middleware via Access-Control-Request-Headers",
   "url": "https://github.com/advisories/GHSA-8j4g-w8fx-2239"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.3.2"
   ],
   "id": "GHSA-cj63-jhhr-wcxv",
   "severity": "medium",
   "title": "DOMPurify USE_PROFILES prototype pollution allows event handlers",
   "url": "https://github.com/advisories/GHSA-cj63-jhhr-wcxv"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.3.2"
   ],
   "id": "GHSA-cjmm-f4jc-qw8r",
   "severity": "medium",
   "title": "DOMPurify ADD_ATTR predicate skips URI validation",
   "url": "https://github.com/advisories/GHSA-cjmm-f4jc-qw8r"
  },
  {
   "affects": [
    "protobufjs"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "7.6.3"
   ],
   "id": "GHSA-f38q-mgvj-vph7",
   "severity": "medium",
   "title": "protobufjs : Schema-derived names can shadow runtime-significant properties",
   "url": "https://github.com/advisories/GHSA-f38q-mgvj-vph7"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.17"
   ],
   "id": "GHSA-gvwx-54wh-qm9j",
   "severity": "medium",
   "title": "node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records",
   "url": "https://github.com/advisories/GHSA-gvwx-54wh-qm9j"
  },
  {
   "affects": [
    "js-yaml"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.15.0"
   ],
   "id": "GHSA-h67p-54hq-rp68",
   "severity": "medium",
   "title": "JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases",
   "url": "https://github.com/advisories/GHSA-h67p-54hq-rp68"
  },
  {
   "affects": [
    "protobufjs"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "7.6.5"
   ],
   "id": "GHSA-j3f2-48v5-ccww",
   "severity": "medium",
   "title": "protobufjs: Denial of Service via infinite loop in .proto option parsing",
   "url": "https://github.com/advisories/GHSA-j3f2-48v5-ccww"
  },
  {
   "affects": [
    "hono"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.12.25"
   ],
   "id": "GHSA-j6c9-x7qj-28xf",
   "severity": "medium",
   "title": "hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice",
   "url": "https://github.com/advisories/GHSA-j6c9-x7qj-28xf"
  },
  {
   "affects": [
    "tar"
   ],
   "cvss": 5.3,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "7.5.18"
   ],
   "id": "GHSA-w8wr-v893-vjvp",
   "severity": "medium",
   "title": "node-tar: Process crash via PAX numeric path type confusion",
   "url": "https://github.com/advisories/GHSA-w8wr-v893-vjvp"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 5.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.4.13"
   ],
   "id": "GHSA-55q2-fjhq-7xh7",
   "severity": "medium",
   "title": "DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS",
   "url": "https://github.com/advisories/GHSA-55q2-fjhq-7xh7"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 5.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.4.11"
   ],
   "id": "GHSA-cmwh-pvxp-8882",
   "severity": "medium",
   "title": "DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)",
   "url": "https://github.com/advisories/GHSA-cmwh-pvxp-8882"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 5.1,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "3.4.7"
   ],
   "id": "GHSA-rp9w-3fw7-7cwq",
   "severity": "medium",
   "title": "DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content",
   "url": "https://github.com/advisories/GHSA-rp9w-3fw7-7cwq"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 4.8,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.28.0"
   ],
   "id": "GHSA-8xcm-r25x-g524",
   "severity": "medium",
   "title": "undici vulnerable to downstream response desynchronization via retry interceptor",
   "url": "https://github.com/advisories/GHSA-8xcm-r25x-g524"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 4.8,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.28.0"
   ],
   "id": "GHSA-8xcm-r25x-g524",
   "severity": "medium",
   "title": "undici vulnerable to downstream response desynchronization via retry interceptor",
   "url": "https://github.com/advisories/GHSA-8xcm-r25x-g524"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 4.8,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "8.9.0"
   ],
   "id": "GHSA-8xcm-r25x-g524",
   "severity": "medium",
   "title": "undici vulnerable to downstream response desynchronization via retry interceptor",
   "url": "https://github.com/advisories/GHSA-8xcm-r25x-g524"
  },
  {
   "affects": [
    "hono"
   ],
   "cvss": 4.8,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.12.34"
   ],
   "id": "GHSA-f23p-vx2j-j53r",
   "severity": "medium",
   "title": "Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure",
   "url": "https://github.com/advisories/GHSA-f23p-vx2j-j53r"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 4.8,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.28.0"
   ],
   "id": "GHSA-v3r7-h72x-cjcm",
   "severity": "medium",
   "title": "undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields",
   "url": "https://github.com/advisories/GHSA-v3r7-h72x-cjcm"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 4.8,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.28.0"
   ],
   "id": "GHSA-v3r7-h72x-cjcm",
   "severity": "medium",
   "title": "undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields",
   "url": "https://github.com/advisories/GHSA-v3r7-h72x-cjcm"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 4.8,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "8.9.0"
   ],
   "id": "GHSA-v3r7-h72x-cjcm",
   "severity": "medium",
   "title": "undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields",
   "url": "https://github.com/advisories/GHSA-v3r7-h72x-cjcm"
  },
  {
   "affects": [
    "hono"
   ],
   "cvss": 4.8,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.12.25"
   ],
   "id": "GHSA-wgpf-jwqj-8h8p",
   "severity": "medium",
   "title": "hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest",
   "url": "https://github.com/advisories/GHSA-wgpf-jwqj-8h8p"
  },
  {
   "affects": [
    "hono"
   ],
   "cvss": 4.8,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "4.12.27"
   ],
   "id": "GHSA-xgm2-5f3f-mvvc",
   "severity": "medium",
   "title": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication",
   "url": "https://github.com/advisories/GHSA-xgm2-5f3f-mvvc"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 4.6,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.24.0"
   ],
   "id": "GHSA-4992-7rv2-5pvq",
   "severity": "medium",
   "title": "Undici has CRLF Injection in undici via `upgrade` option",
   "url": "https://github.com/advisories/GHSA-4992-7rv2-5pvq"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 4.2,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.28.0"
   ],
   "id": "GHSA-m8rv-5g2x-5cg5",
   "severity": "medium",
   "title": "undici vulnerable to CRLF Injection via blob-like body 'type' property",
   "url": "https://github.com/advisories/GHSA-m8rv-5g2x-5cg5"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 4.2,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "6.28.0"
   ],
   "id": "GHSA-m8rv-5g2x-5cg5",
   "severity": "medium",
   "title": "undici vulnerable to CRLF Injection via blob-like body 'type' property",
   "url": "https://github.com/advisories/GHSA-m8rv-5g2x-5cg5"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 4.2,
   "distro_severity": "medium",
   "fix_state": "fixed",
   "fixed_in": [
    "8.9.0"
   ],
   "id": "GHSA-m8rv-5g2x-5cg5",
   "severity": "medium",
   "title": "undici vulnerable to CRLF Injection via blob-like body 'type' property",
   "url": "https://github.com/advisories/GHSA-m8rv-5g2x-5cg5"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 3.7,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "6.27.0"
   ],
   "id": "GHSA-35p6-xmwp-9g52",
   "severity": "low",
   "title": "undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse",
   "url": "https://github.com/advisories/GHSA-35p6-xmwp-9g52"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 3.7,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "6.27.0"
   ],
   "id": "GHSA-35p6-xmwp-9g52",
   "severity": "low",
   "title": "undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse",
   "url": "https://github.com/advisories/GHSA-35p6-xmwp-9g52"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 3.7,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "8.5.0"
   ],
   "id": "GHSA-35p6-xmwp-9g52",
   "severity": "low",
   "title": "undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse",
   "url": "https://github.com/advisories/GHSA-35p6-xmwp-9g52"
  },
  {
   "affects": [
    "hono"
   ],
   "cvss": 3.7,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "4.12.34"
   ],
   "id": "GHSA-79qm-7rj5-m7r9",
   "severity": "low",
   "title": "Hono: Proxy Helper does not remove response headers listed in the `Connection` header",
   "url": "https://github.com/advisories/GHSA-79qm-7rj5-m7r9"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 3.7,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "6.27.0"
   ],
   "id": "GHSA-g8m3-5g58-fq7m",
   "severity": "low",
   "title": "undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching",
   "url": "https://github.com/advisories/GHSA-g8m3-5g58-fq7m"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 3.7,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "6.27.0"
   ],
   "id": "GHSA-g8m3-5g58-fq7m",
   "severity": "low",
   "title": "undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching",
   "url": "https://github.com/advisories/GHSA-g8m3-5g58-fq7m"
  },
  {
   "affects": [
    "undici"
   ],
   "cvss": 3.7,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "8.5.0"
   ],
   "id": "GHSA-g8m3-5g58-fq7m",
   "severity": "low",
   "title": "undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching",
   "url": "https://github.com/advisories/GHSA-g8m3-5g58-fq7m"
  },
  {
   "affects": [
    "body-parser"
   ],
   "cvss": 3.7,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "2.3.0"
   ],
   "id": "GHSA-v422-hmwv-36x6",
   "severity": "low",
   "title": "body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement",
   "url": "https://github.com/advisories/GHSA-v422-hmwv-36x6"
  },
  {
   "affects": [
    "@babel/core"
   ],
   "cvss": 3.2,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "7.29.6"
   ],
   "id": "GHSA-4x5r-pxfx-6jf8",
   "severity": "low",
   "title": "@babel/core: Arbitrary File Read via sourceMappingURL Comment",
   "url": "https://github.com/advisories/GHSA-4x5r-pxfx-6jf8"
  },
  {
   "affects": [
    "diff"
   ],
   "cvss": 2.7,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "8.0.3"
   ],
   "id": "GHSA-73rr-hh4g-fpgx",
   "severity": "low",
   "title": "jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch",
   "url": "https://github.com/advisories/GHSA-73rr-hh4g-fpgx"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 2.1,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "3.4.12"
   ],
   "id": "GHSA-c2j3-45gr-mqc4",
   "severity": "low",
   "title": "DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.",
   "url": "https://github.com/advisories/GHSA-c2j3-45gr-mqc4"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 2.1,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "3.4.9"
   ],
   "id": "GHSA-vxr8-fq34-vvx9",
   "severity": "low",
   "title": "DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output",
   "url": "https://github.com/advisories/GHSA-vxr8-fq34-vvx9"
  },
  {
   "affects": [
    "dompurify"
   ],
   "cvss": 2.0,
   "distro_severity": "low",
   "fix_state": "fixed",
   "fixed_in": [
    "3.4.8"
   ],
   "id": "GHSA-gvmj-g25r-r7wr",
   "severity": "low",
   "title": "DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes",
   "url": "https://github.com/advisories/GHSA-gvmj-g25r-r7wr"
  }
 ],
 "findings_changed_at": "2026-08-25T19:11:11Z",
 "image": "opencode",
 "inputs": {
  "sbom_sha256": "ee1ed251cec8e5d03bc327396937b33809ebf950a63fb49591e3d95ae4b411e6"
 },
 "platform_digest": "sha256:6f5ab32bab1dda702d563a5816dacdab86f66abbd788c4bb24457c7fe8805dc6",
 "project": "opencode",
 "receipt_sha256": "3d0f3f394bfee8d4f1ff541d5d104a70b789b14fa36cb89850f7ee52ef358070",
 "scanner": "grype",
 "severity_counts": {
  "critical": 1,
  "high": 30,
  "low": 13,
  "medium": 54,
  "unknown": 0
 },
 "suppressed": [],
 "version": "1.18.23",
 "vex_applied": [
  "opencode-1.18.23-amd64.vex.json",
  "opencode-1.18.23-amd64.ubuntu-vex.json"
 ]
}
