
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Server-side Request Forgery (SSRF)
next is a react framework.
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in the Image Optimization remote fetch, which resolves and requests an allowlisted remote URL without constraining the address that name resolves to, so a host permitted by images.remotePatterns can direct the fetch at an internal address. An attacker can make the server issue requests to private network addresses and read the responses back through the image endpoint, by controlling the DNS records of a host that matches an allowlist entry so the name resolves to that internal address at fetch time. This requires images.remotePatterns to be configured with at least one host whose DNS entries the attacker controls or can influence, so applications with no images.remotePatterns configured are unaffected.
Data Amplification
httpx2 is a The next generation HTTP client.
Affected versions of this package are vulnerable to Data Amplification in the default transport's response decompression, which inflates each network read of up to 64 KiB completely into a single intermediate allocation before yielding any decompressed bytes, across the gzip, deflate, brotli, and zstandard encodings. An attacker can exhaust the client's memory and terminate the process by serving a compressed response at a ratio reaching 1032:1, so each chunk read expands to roughly 64 MiB in one allocation. This requires the application to fetch responses from a server the attacker controls or can influence, which puts webhook receivers, link unfurlers, crawlers, fetchers reachable through SSRF, and redirect followers in scope.
Cross-site Scripting (XSS)
org.webjars.npm:dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG.
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in _sanitizeElements and _sanitizeAttributes in src/purify.ts, which invoke _handleHookDetachedNode only after the beforeSanitizeElements and uponSanitizeElement hooks, so a non-root node removed by an afterSanitizeElements or afterSanitizeAttributes hook keeps its descendants' event handlers armed, and the post-walk neutralization pass covers only entries in DOMPurify.removed, which excludes hook-detached nodes. An attacker can execute script in the page origin under the victim's session by supplying markup with a non-root wrapper whose descendants carry on* handlers, such as an <img onerror>, so a queued resource event fires on the detached subtree after the synchronous sanitize() call has returned. This requires the application to call sanitize() with IN_PLACE: true on a live node and to register a node-removing afterSanitizeElements or afterSanitizeAttributes hook, so callers using the default returning mode or no such hooks are unaffected.
Note: This is a bypass of the fix for the vulnerability described in CVE-2026-75838.
Recent vulnerabilities disclosed by Snyk
- M
Cross-site Scripting (XSS) in nice-select2 (npm)- C
Malicious Package in cacheutilskit (npm)- C
Malicious Package in byteutilsbox (npm)- C
Malicious Package in streamlyx (npm)- H
Directory Traversal in zip-lib (npm)
Snyk security
researchers
have disclosed
3506
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




