
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
A GitHub-reviewed security advisory — not necessarily under active exploitation the way our CISA KEV advisories are, but a real, disclosed vulnerability in an open-source dependency.
Affected packages
Vulnerable: < 4.5.12
Patched in 4.5.12
Vulnerable: >= 4.6.0, < 4.6.5
Patched in 4.6.5
Vulnerable: >= 5.0.0, < 5.1.9
Patched in 5.1.9
Vulnerable: >= 5.2.0, < 5.2.14
Patched in 5.2.14
Vulnerable: >= 5.3.0, < 5.3.7
Patched in 5.3.7
Vulnerable: < 4.5.12
Patched in 4.5.12
Vulnerable: >= 4.6.0, < 4.6.5
Patched in 4.6.5
Vulnerable: >= 5.0.0, < 5.1.9
Patched in 5.1.9
Vulnerable: >= 5.2.0, < 5.2.14
Patched in 5.2.14
Vulnerable: >= 5.3.0, < 5.3.7
Patched in 5.3.7
Details
Talk to us about this
Find out whether this dependency (or others like it) is actually reachable in your codebase.
Get help patching, or building dependency-scanning into your pipeline going forward.
A secure code review or supply chain review finds this before an advisory does.