See the full list of npm packages compromised in the "SHA1-Hulud npm supply chain incident – Nov 2025" [View compromised packages].
Find out if you have vulnerabilities that put you at risk
Test your applications| VULNERABILITY | AFFECTS | TYPE | PUBLISHED |
|---|---|---|---|
| antirez/redis[8.2.0,8.2.3) | Unmanaged (C/C++) | 7 Nov 2025 |
| python[,3.9.25)[3.10.0a1,] | Unmanaged (C/C++) | 7 Nov 2025 |
| quickjs-ng/quickjs[,0.11.0) | Unmanaged (C/C++) | 6 Nov 2025 |
| bellard/quickjs[0,] | Unmanaged (C/C++) | 6 Nov 2025 |
| libarchive[0,] | Unmanaged (C/C++) | 6 Nov 2025 |
| lasso[,2.9.0) | Unmanaged (C/C++) | 6 Nov 2025 |
| lasso[,2.9.0) | Unmanaged (C/C++) | 6 Nov 2025 |
| lasso[,2.9.0) | Unmanaged (C/C++) | 6 Nov 2025 |
| lasso[,2.9.0) | Unmanaged (C/C++) | 6 Nov 2025 |
| BrianPugh/tamp[,1.10.3) | Unmanaged (C/C++) | 5 Nov 2025 |
| elog_project[0,] | Unmanaged (C/C++) | 5 Nov 2025 |
| elog_project[0,] | Unmanaged (C/C++) | 5 Nov 2025 |
| elog_project[0,] | Unmanaged (C/C++) | 5 Nov 2025 |
| raspberrypi/rpi-imager[,2.0.0-rc3) | Unmanaged (C/C++) | 4 Nov 2025 |
| lighttpd[1.4.80, 1.4.81) | Unmanaged (C/C++) | 4 Nov 2025 |
| vtk/vtk[0,] | Unmanaged (C/C++) | 31 Oct 2025 |
| vtk/vtk[0,] | Unmanaged (C/C++) | 31 Oct 2025 |
| vtk/vtk[0,] | Unmanaged (C/C++) | 31 Oct 2025 |
| vtk/vtk[0,] | Unmanaged (C/C++) | 31 Oct 2025 |
| pdns-recursor[,4.9.9)[5.0.0, 5.0.9)[5.1.0, 5.1.2) | Unmanaged (C/C++) | 31 Oct 2025 |
| dnsdist[1.9.0,1.9.4) | Unmanaged (C/C++) | 31 Oct 2025 |
| dnsdist[,1.3.3) | Unmanaged (C/C++) | 31 Oct 2025 |
| pdns-recursor[3.5-rc1,3.6.4)[3.7.0-rc1,3.7.3) | Unmanaged (C/C++) | 31 Oct 2025 |
| nasa/CryptoLib[,1.4.2) | Unmanaged (C/C++) | 31 Oct 2025 |
| gimp[,3.0.6) | Unmanaged (C/C++) | 31 Oct 2025 |
| gimp[,3.0.6) | Unmanaged (C/C++) | 31 Oct 2025 |
| gimp[,3.0.6) | Unmanaged (C/C++) | 31 Oct 2025 |
| gimp[,3.0.6) | Unmanaged (C/C++) | 31 Oct 2025 |
| gegl[,0.4.64) | Unmanaged (C/C++) | 31 Oct 2025 |
| gimp[,3.0.6) | Unmanaged (C/C++) | 31 Oct 2025 |