Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-55699

pnpm: reserved bin name deletes PNPM_HOME during global remove_CVE-2026-55699

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a mal...

pnpm pnpm < 10.34.2 CVE
MEDIUM 6.5 CVE-2026-55180

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run_CVE-2026-55180

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnp...

pnpm pnpm < 10.34.2 CVE
MEDIUM 6.9 CVE-2026-54679

jq: potential integer overflow in jvp_string_append_CVE-2026-54679

jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causi...

jqlang jq < 1.8.2 CVE
MEDIUM 6.8 CVE-2026-50573

pnpm: Unsafe default behavior breaks integrity check_CVE-2026-50573

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting tha...

pnpm pnpm < 10.33.4 CVE
MEDIUM 6.8 CVE-2026-50021

pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field_CVE-2026-50021

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is a...

pnpm pnpm < 10.34.0 CVE
MEDIUM 6.9 CVE-2026-50017

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry_CVE-2026-50017

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a ...

pnpm pnpm < 10.33.4 CVE
MEDIUM 6.4 CVE-2026-50014

pnpm: Git Fetch Argument Injection via Lockfile resolution.commit_CVE-2026-50014

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- s...

pnpm pnpm < 10.33.4 CVE
MEDIUM 4.8 CVE-2026-48995

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile_CVE-2026-48995

pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will in...

pnpm pnpm < 10.33.4 CVE
MEDIUM 6.8 CVE-2026-47770

jq: stack overflow in deep structural equality_CVE-2026-47770

jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on j...

jqlang jq < 1.8.2 CVE
MEDIUM 4.8 CVE-2026-56788

RTKLIB 2.4.3 – Out-of-bounds Read via Negative Array Index in getcodepri_CVE-2026-56788

RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RINEX observation codes, allo...

tomojitakasu RTKLIB CVE