See the full list of npm packages compromised in the "SHA1-Hulud npm supply chain incident – Nov 2025" [View compromised packages].
Find out if you have vulnerabilities that put you at risk
Test your applications| VULNERABILITY | AFFECTS | TYPE | PUBLISHED |
|---|---|---|---|
| mongodb/mongo-bi-connector-odbc-driver[,1.4.7) | Unmanaged (C/C++) | 24 Oct 2025 |
| fontforge/fontforge[,20251009) | Unmanaged (C/C++) | 24 Oct 2025 |
| fontforge/fontforge[,20251009) | Unmanaged (C/C++) | 24 Oct 2025 |
| libsoup[0,] | Unmanaged (C/C++) | 24 Oct 2025 |
| unbound[,1.24.1) | Unmanaged (C/C++) | 24 Oct 2025 |
| bind[,9.18.41)[,9.20.15)[,9.21.14) | Unmanaged (C/C++) | 24 Oct 2025 |
| bind[,9.18.41)[,9.20.15)[,9.21.14) | Unmanaged (C/C++) | 24 Oct 2025 |
| bind[,9.18.31)[9.20.0,9.20.15)[9.21.0,9.21.14) | Unmanaged (C/C++) | 24 Oct 2025 |
| openjdk[,8.0.471)[11.0.0,11.0.29)[17.0.0,17.0.17)[21.0.0,21.0.9)[25.0.0,25.0.1) | Unmanaged (C/C++) | 24 Oct 2025 |
| openwrt[,24.10.4) | Unmanaged (C/C++) | 23 Oct 2025 |
| openwrt[,24.10.4) | Unmanaged (C/C++) | 23 Oct 2025 |
| openjdk[,8.0.471)[11.0.0,11.0.29)[17.0.0,17.0.17)[21.0.0,21.0.9)[25.0.0,25.0.1) | Unmanaged (C/C++) | 22 Oct 2025 |
| openjdk[,21.0.9)[25.0.0,25.0.1) | Unmanaged (C/C++) | 22 Oct 2025 |
| Mbed-TLS/TF-PSA-Crypto[,1.0.0) | Unmanaged (C/C++) | 22 Oct 2025 |
| armmbed/mbedtls[,3.6.5) | Unmanaged (C/C++) | 22 Oct 2025 |
| bambulab/BambuStudio[,2.3.0) | Unmanaged (C/C++) | 22 Oct 2025 |
| geographiclib/geographiclib[,2.5.2) | Unmanaged (C/C++) | 22 Oct 2025 |
| wolfSSL/wolfssh[,1.4.21) | Unmanaged (C/C++) | 22 Oct 2025 |
| wolfSSL/wolfssh[,1.4.21) | Unmanaged (C/C++) | 22 Oct 2025 |
| triton-inference-server/server[,2.58.0) | Unmanaged (C/C++) | 21 Oct 2025 |
| triton-inference-server/server[2.39.0,2.46.0) | Unmanaged (C/C++) | 21 Oct 2025 |
| armmbed/mbedtls[,3.6.5) | Unmanaged (C/C++) | 21 Oct 2025 |
| triton-inference-server/server[,2.58.0) | Unmanaged (C/C++) | 21 Oct 2025 |
| triton-inference-server/server[,2.59.1) | Unmanaged (C/C++) | 21 Oct 2025 |
| triton-inference-server/server[,2.58.0) | Unmanaged (C/C++) | 21 Oct 2025 |
| triton-inference-server/server[,2.59.1) | Unmanaged (C/C++) | 21 Oct 2025 |
| warmcat/libwebsockets[0,] | Unmanaged (C/C++) | 21 Oct 2025 |
| warmcat/libwebsockets[0,] | Unmanaged (C/C++) | 21 Oct 2025 |
| warmcat/libwebsockets[0,] | Unmanaged (C/C++) | 21 Oct 2025 |
| warmcat/libwebsockets[0,] | Unmanaged (C/C++) | 21 Oct 2025 |