See the full list of npm packages compromised in the "SHA1-Hulud npm supply chain incident – Nov 2025" [View compromised packages].
Find out if you have vulnerabilities that put you at risk
Test your applications| VULNERABILITY | AFFECTS | TYPE | PUBLISHED |
|---|---|---|---|
| nghttp2-debugsource<0:1.33.0-5.el8_8 | rocky:8 | 7 Dec 2025 |
| nghttp2-debuginfo<0:1.33.0-5.el8_8 | rocky:8 | 7 Dec 2025 |
| libnghttp2-devel<0:1.33.0-5.el8_8 | rocky:8 | 7 Dec 2025 |
| libnghttp2-debuginfo<0:1.33.0-5.el8_8 | rocky:8 | 7 Dec 2025 |
| libnghttp2<0:1.33.0-5.el8_8 | rocky:8 | 7 Dec 2025 |
| nghttp2<0:1.33.0-5.el8_8 | rocky:8 | 6 Dec 2025 |
| nodejs-packaging-bundler<0:2021.06-4.module+el9.7.0+40025+0e0cf6b2 | rocky:9 | 5 Dec 2025 |
| nodejs-packaging<0:2021.06-4.module+el9.7.0+40017+f0db1785 | rocky:9 | 5 Dec 2025 |
| nodejs-nodemon<0:3.0.1-1.module+el9.7.0+40022+9ecc286c | rocky:9 | 5 Dec 2025 |
| trafficserver9<9.2.3-r0 | alpine:3.23 | 4 Dec 2025 |
| openjdk21<21.0.2_p13-r0 | alpine:3.23 | 4 Dec 2025 |
| netdata<1.43.2-r1 | alpine:3.23 | 4 Dec 2025 |
| jetty-runner<9.4.53.20231009-r0 | alpine:3.23 | 4 Dec 2025 |
| grpc<1.59.3-r0 | alpine:3.23 | 4 Dec 2025 |
| go<1.21.3-r0 | alpine:3.23 | 4 Dec 2025 |
| nginx<1.24.0-r12 | alpine:3.23 | 4 Dec 2025 |
| nghttp2<1.57.0-r0 | alpine:3.23 | 4 Dec 2025 |
| helm-4<4.0.1-r1 | chainguard:latest | 28 Nov 2025 |
| helm-3<3.19.2-r1 | chainguard:latest | 28 Nov 2025 |
| dnsdist* | ubuntu:22.04 | 27 Nov 2025 |
| h2o<2.2.5+dfsg2-3ubuntu0.1~esm1 | ubuntu:20.04 | 25 Nov 2025 |
| h2o<2.2.5+dfsg2-6.1ubuntu2+esm1 | ubuntu:22.04 | 25 Nov 2025 |
| golang-github-infrawatch-apputils<0.0.0 | rhel:10 | 7 Nov 2025 |
| golang-github-infrawatch-apputils<0.0.0 | rhel:10 | 7 Nov 2025 |
| python3-octavia-tests-tempest<0.0.0 | rhel:10 | 7 Nov 2025 |
| golang-github-infrawatch-apputils<0.0.0 | rhel:10 | 7 Nov 2025 |
| dotnet8<8.0.100-8.0.0-0ubuntu1 | ubuntu:25.10 | 22 Oct 2025 |
| eap7-hornetq-core-client<0:2.4.11-1.Final_redhat_00001.1.ep7.el7 | rhel:7 | 25 Sept 2025 |
| eap7-hornetq-commons<0:2.4.11-1.Final_redhat_00001.1.ep7.el7 | rhel:7 | 25 Sept 2025 |
| eap7-hornetq-jms-client<0:2.4.11-1.Final_redhat_00001.1.ep7.el7 | rhel:7 | 25 Sept 2025 |