Skip to main content

Vendor archive

npmjs CVEs

Beta · best-effort

16 CVEs tagged to vendor npmjs1 Critical, 12 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2022-25883

Published Jun 21, 2023

Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a ra…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7754

Published Oct 27, 2020

This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7408

Published Feb 22, 2018

An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g npm" command, and also announce…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3956

Published Jul 2, 2016

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with ar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1