Skip to content

[VANTA] [VULNERABILITY] <MEDIUM> CVE-2025-62718, CVE-2026-40175, CVE-2026-67312 and others, fix before 2026-11-02 #37

Description

@marco-commercelayer

Important

CLOSE THE ISSUE ONLY IF YOU PLAN TO DEPLOY THE FIX BEFORE THE DEADLINE IN THE TITLE.

DO NOT MANUALLY MODIFY THE ISSUE TITLE OR TEXT BODY.

npm-axios >= 1.0.0, < 1.15.0 CODE_REPOSITORY/examples CVE-2026-40175 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs

npm-axios >= 1.0.0, < 1.15.0 CODE_REPOSITORY/examples CVE-2025-62718 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs

npm-axios >= 1.0.0, < 1.18.0 CODE_REPOSITORY/examples CVE-2026-67312 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs

npm-axios >= 1.0.0, < 1.18.0 CODE_REPOSITORY/examples CVE-2026-67313 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs

npm-axios >= 1.0.0, < 1.18.0 CODE_REPOSITORY/examples CVE-2026-67316 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs

npm-axios >= 1.0.0, < 1.18.0 CODE_REPOSITORY/examples CVE-2026-67319 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-react-router >= 6.4.0, < 7.18.0 CVE-2026-53666 MEDIUM

npm-react-router >= 6.4.0, < 7.18.0 CODE_REPOSITORY/examples CVE-2026-53666 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-next >= 10.0.0, < 14.2.7 CVE-2024-47831 MEDIUM

npm-next >= 10.0.0, < 14.2.7 CODE_REPOSITORY/examples CVE-2024-47831 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-next >= 10.0.0, < 15.5.10 CVE-2025-59471 MEDIUM

npm-next >= 10.0.0, < 15.5.10 CODE_REPOSITORY/examples CVE-2025-59471 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-h3 <= 1.15.8 GHSA-72gr-qfp7-vwhw MEDIUM

npm-h3 <= 1.15.8 CODE_REPOSITORY/examples GHSA-72gr-qfp7-vwhw MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-next >= 10.0.0, < 15.5.16 CVE-2026-44577 MEDIUM

npm-next >= 10.0.0, < 15.5.16 CODE_REPOSITORY/examples CVE-2026-44577 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-@hono/node-server >= 2.0.0, < 2.0.5 GHSA-frvp-7c67-39w9 MEDIUM

npm-@hono/node-server >= 2.0.0, < 2.0.5 CODE_REPOSITORY/examples GHSA-frvp-7c67-39w9 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-next >= 14.2.0, < 15.5.16 CVE-2026-44576 MEDIUM

npm-next >= 14.2.0, < 15.5.16 CODE_REPOSITORY/examples CVE-2026-44576 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-postcss < 8.4.31 CVE-2023-44270 MEDIUM

npm-postcss < 8.4.31 CODE_REPOSITORY/examples CVE-2023-44270 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-micromatch < 4.0.8 CVE-2024-4067 MEDIUM

npm-micromatch < 4.0.8 CODE_REPOSITORY/examples CVE-2024-4067 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-next >= 13.0.0, < 13.5.8 CVE-2024-56332 MEDIUM

npm-next >= 13.0.0, < 13.5.8 CODE_REPOSITORY/examples CVE-2024-56332 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-next >= 14.0.0, < 14.2.21 CVE-2024-56332 MEDIUM

npm-next >= 14.0.0, < 14.2.21 CODE_REPOSITORY/examples CVE-2024-56332 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-h3 < 1.15.9 GHSA-4hxc-9384-m385 MEDIUM

npm-h3 < 1.15.9 CODE_REPOSITORY/examples GHSA-4hxc-9384-m385 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-qs >= 6.11.1, <= 6.15.1 CVE-2026-8723 MEDIUM

npm-qs >= 6.11.1, <= 6.15.1 CODE_REPOSITORY/examples CVE-2026-8723 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-joi < 17.13.4 CVE-2026-48038 MEDIUM

npm-joi < 17.13.4 CODE_REPOSITORY/examples CVE-2026-48038 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-morgan >= 1.2.0, <= 1.10.1 CVE-2026-5078 MEDIUM

npm-morgan >= 1.2.0, <= 1.10.1 CODE_REPOSITORY/examples CVE-2026-5078 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-@hono/node-server >= 2.0.0, <= 2.0.9 CVE-2026-73565 MEDIUM

npm-@hono/node-server >= 2.0.0, <= 2.0.9 CODE_REPOSITORY/examples CVE-2026-73565 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-hono < 4.12.34 CVE-2026-69207 MEDIUM

npm-hono < 4.12.34 CODE_REPOSITORY/examples CVE-2026-69207 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-hono >= 4.12.0, < 4.12.34 CVE-2026-71848 MEDIUM

npm-hono >= 4.12.0, < 4.12.34 CODE_REPOSITORY/examples CVE-2026-71848 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-axios < 0.31.0 CVE-2026-40175 MEDIUM

npm-axios < 0.31.0 CODE_REPOSITORY/examples CVE-2026-40175 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-axios < 0.31.0 CVE-2025-62718 MEDIUM

npm-axios < 0.31.0 CODE_REPOSITORY/examples CVE-2025-62718 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-hono >= 4.3.3, < 4.12.27 CVE-2026-59897 MEDIUM

npm-hono >= 4.3.3, < 4.12.27 CODE_REPOSITORY/examples CVE-2026-59897 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-hono >= 3.8.0, < 4.12.34 CVE-2026-71850 MEDIUM

npm-hono >= 3.8.0, < 4.12.34 CODE_REPOSITORY/examples CVE-2026-71850 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-next >= 13.4.0, < 15.5.16 CVE-2026-44581 MEDIUM

npm-next >= 13.4.0, < 15.5.16 CODE_REPOSITORY/examples CVE-2026-44581 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-nanoid < 3.3.8 CVE-2024-55565 MEDIUM

npm-nanoid < 3.3.8 CODE_REPOSITORY/examples CVE-2024-55565 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-yaml >= 2.0.0, < 2.8.3 CVE-2026-33532 MEDIUM

npm-yaml >= 2.0.0, < 2.8.3 CODE_REPOSITORY/examples CVE-2026-33532 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-qs < 6.14.1 CVE-2025-15284 MEDIUM

npm-qs < 6.14.1 CODE_REPOSITORY/examples CVE-2025-15284 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-next >= 9.5.0, < 15.5.13 CVE-2026-29057 MEDIUM

npm-next >= 9.5.0, < 15.5.13 CODE_REPOSITORY/examples CVE-2026-29057 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-next >= 10.0.0, < 15.5.14 CVE-2026-27980 MEDIUM

npm-next >= 10.0.0, < 15.5.14 CODE_REPOSITORY/examples CVE-2026-27980 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-follow-redirects <= 1.15.11 GHSA-r4q5-vmmm-2653 MEDIUM

npm-follow-redirects <= 1.15.11 CODE_REPOSITORY/examples GHSA-r4q5-vmmm-2653 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-axios >= 1.7.0, < 1.18.0 CVE-2026-67317 MEDIUM

npm-axios >= 1.7.0, < 1.18.0 CODE_REPOSITORY/examples CVE-2026-67317 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-axios < 0.33.0 CVE-2026-67316 MEDIUM

npm-axios < 0.33.0 CODE_REPOSITORY/examples CVE-2026-67316 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-axios >= 0.8.0, < 0.33.0 CVE-2026-67319 MEDIUM

npm-axios >= 0.8.0, < 0.33.0 CODE_REPOSITORY/examples CVE-2026-67319 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-next >= 15.5.0, < 15.5.21 CVE-2026-64644 MEDIUM

npm-next >= 15.5.0, < 15.5.21 CODE_REPOSITORY/examples CVE-2026-64644 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-react-router >= 6.0.0, < 7.18.0 CVE-2026-53669 MEDIUM

npm-react-router >= 6.0.0, < 7.18.0 CODE_REPOSITORY/examples CVE-2026-53669 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-postcss <= 8.5.22 CVE-2026-69153 MEDIUM

npm-postcss <= 8.5.22 CODE_REPOSITORY/examples CVE-2026-69153 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-decode-uri-component <= 0.4.2 CVE-2026-45822 MEDIUM

npm-decode-uri-component <= 0.4.2 CODE_REPOSITORY/examples CVE-2026-45822 MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs
FIXED npm-express < 4.20.0 CVE-2024-43796 LOW

npm-express < 4.20.0 CODE_REPOSITORY/examples CVE-2024-43796 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-serve-static < 1.16.0 CVE-2024-43800 LOW

npm-serve-static < 1.16.0 CODE_REPOSITORY/examples CVE-2024-43800 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-send < 0.19.0 CVE-2024-43799 LOW

npm-send < 0.19.0 CODE_REPOSITORY/examples CVE-2024-43799 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-postcss-selector-parser >= 6.1.0, < 6.1.3 CVE-2026-9358 LOW

npm-postcss-selector-parser >= 6.1.0, < 6.1.3 CODE_REPOSITORY/examples CVE-2026-9358 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-next >= 0.9.9, < 14.2.24 CVE-2025-32421 LOW

npm-next >= 0.9.9, < 14.2.24 CODE_REPOSITORY/examples CVE-2025-32421 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-@auth0/nextjs-auth0 >= 4.9.0, < 4.13.0 CVE-2025-67716 LOW

npm-@auth0/nextjs-auth0 >= 4.9.0, < 4.13.0 CODE_REPOSITORY/examples CVE-2025-67716 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-qs >= 6.7.0, <= 6.14.1 CVE-2026-2391 LOW

npm-qs >= 6.7.0, <= 6.14.1 CODE_REPOSITORY/examples CVE-2026-2391 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-next >= 13.4.6, < 15.5.16 CVE-2026-44582 LOW

npm-next >= 13.4.6, < 15.5.16 CODE_REPOSITORY/examples CVE-2026-44582 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-body-parser < 1.20.6 CVE-2026-12590 LOW

npm-body-parser < 1.20.6 CODE_REPOSITORY/examples CVE-2026-12590 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-hono >= 4.7.0, < 4.12.34 CVE-2026-71849 LOW

npm-hono >= 4.7.0, < 4.12.34 CODE_REPOSITORY/examples CVE-2026-71849 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-@babel/core <= 7.29.0 CVE-2026-49356 LOW

npm-@babel/core <= 7.29.0 CODE_REPOSITORY/examples CVE-2026-49356 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-brace-expansion >= 2.0.0, <= 2.0.1 CVE-2025-5889 LOW

npm-brace-expansion >= 2.0.0, <= 2.0.1 CODE_REPOSITORY/examples CVE-2025-5889 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-brace-expansion >= 1.0.0, <= 1.1.11 CVE-2025-5889 LOW

npm-brace-expansion >= 1.0.0, <= 1.1.11 CODE_REPOSITORY/examples CVE-2025-5889 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-esbuild >= 0.27.3, < 0.28.1 GHSA-g7r4-m6w7-qqqr LOW

npm-esbuild >= 0.27.3, < 0.28.1 CODE_REPOSITORY/examples GHSA-g7r4-m6w7-qqqr LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-next >= 0.9.9, < 13.4.20-canary.13 CVE-2023-46298 LOW

npm-next >= 0.9.9, < 13.4.20-canary.13 CODE_REPOSITORY/examples CVE-2023-46298 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-es5-ext >= 0.10.0, < 0.10.63 CVE-2024-27088 LOW

npm-es5-ext >= 0.10.0, < 0.10.63 CODE_REPOSITORY/examples CVE-2024-27088 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-cookie < 0.7.0 CVE-2024-47764 LOW

npm-cookie < 0.7.0 CODE_REPOSITORY/examples CVE-2024-47764 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-next >= 13.0, < 14.2.30 CVE-2025-48068 LOW

npm-next >= 13.0, < 14.2.30 CODE_REPOSITORY/examples CVE-2025-48068 LOW remediate by: 2026-12-02T14:05:20.740Z

Related URLs
FIXED npm-@humanfs/node < 0.16.8 GHSA-p498-v437-472g MEDIUM

npm-@humanfs/node < 0.16.8 CODE_REPOSITORY/examples GHSA-p498-v437-472g MEDIUM remediate by: 2026-11-02T14:05:20.177Z

Related URLs

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions