Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-54024

LibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Instance Missing File Size Limits_CVE-2026-54024

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-11171 (commit bb58a2d0) added ...

danny-avila LibreChat < 0.8.4-rc1 CVE
MEDIUM 6 CVE-2026-6291

Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryption_CVE-2026-6291

Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key transport, wolfSSL returned...

wolfSSL wolfSSL 3.9.10 CVE
MEDIUM 6.3 CVE-2026-6094

Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData_CVE-2026-6094

Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-su...

wolfSSL wolfSSL 5.8.0 CVE
MEDIUM 6 CVE-2026-6091

Partial-chain verification accepts untrusted intermediate as trust anchor_CVE-2026-6091

Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certificate rather than a truste...

wolfSSL wolfSSL 5.7.4 CVE
MEDIUM 6.5 CVE-2026-55699

pnpm: reserved bin name deletes PNPM_HOME during global remove_CVE-2026-55699

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a mal...

pnpm pnpm < 10.34.2 CVE
MEDIUM 6.5 CVE-2026-55180

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run_CVE-2026-55180

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnp...

pnpm pnpm < 10.34.2 CVE
MEDIUM 6.9 CVE-2026-54679

jq: potential integer overflow in jvp_string_append_CVE-2026-54679

jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causi...

jqlang jq < 1.8.2 CVE
MEDIUM 6.8 CVE-2026-50573

pnpm: Unsafe default behavior breaks integrity check_CVE-2026-50573

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting tha...

pnpm pnpm < 10.33.4 CVE
MEDIUM 6.8 CVE-2026-50021

pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field_CVE-2026-50021

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is a...

pnpm pnpm < 10.34.0 CVE
MEDIUM 6.9 CVE-2026-50017

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry_CVE-2026-50017

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a ...

pnpm pnpm < 10.33.4 CVE