Description
Know CVEs in pinned versions found package-lock file that is not git ignored. NPM Package needs to be reviewed and updated.
Server (apps/OpenSignServer)
CVE
Severity
Advisory
Description
GHSA-9q82-xgwf-vj6h
Moderate
@apollo/server
Browser bug bypasses XS-Search (read-only CSRF) prevention
CVE-2026-40895
High (CVSS 7.5)
follow-redirects
Custom auth headers (X-API-Key, etc.) leak on cross-domain redirect
CVE-2026-41907
Moderate
uuid
Missing buffer bounds check in v3/v5/v6 allows out-of-bounds write
CVE-2026-45736
Moderate
ws
Uninitialized memory disclosure via TypedArray in websocket.close()
CVE-2026-48779
High (CVSS 7.5)
ws
Memory exhaustion DoS from tiny fragments and data chunks
CVE-2026-25547
High
brace-expansion
DoS via unbounded brace range expansion exhausting CPU and memory
CVE-2026-45149
High
brace-expansion
max option applied too late, allowing ~505MB allocation on small input
CVE-2026-42338
Moderate
ip-address
XSS in Address6 HTML-emitting methods (group, link, spanAll)
Server (apps/OpenSignServer)
Reactions are currently unavailable
You can’t perform that action at this time.
Server (apps/OpenSignServer)
Server (apps/OpenSignServer)