Confidential
Software composition assessment
20 components from cdx-mixed-ecosystems.json, assessed 30 Sept 2026, 21:20 UTC
| Prepared for | Example workspace |
|---|---|
| Prepared with | sbomtriage, report schema v1 |
| Inventory | cdx-mixed-ecosystems.json, CycloneDX JSON 1.5, made by syft 1.4.1 |
| Assessed | 30 Sept 2026, 21:20 UTC |
| Vulnerability data as of | 30 Sept 2026, 21:20 UTC |
| Reference | d022217c15f0c7a65b014e84c3283c09 |
| Classification | Confidential. Share with the people responsible for this software. |
| Integrity | d1388f1800c8985c73417d82fdd1818f5ba251ab253c41319fb7ff282cb0b37bSHA-256 of this report's JSON export. Anyone holding that file can check it matches with sha256sum. |
To keep a PDF, print this page and choose Save as PDF. The file opens offline and loads nothing from the network.
Executive summary
Applying all 19 upgrades clears 180 of them. 1 has no fix yet.
One square per finding in this assessment. 3 have a fix and a high chance of being exploited.
Every component declared in the inventory, matched against published advisories and ranked by exploitation evidence: CISA's Known Exploited list and FIRST's EPSS scores.
Whether vulnerable code runs in your deployment, components the inventory leaves out, and the rest of your security programme. It is not a certification.
An SBOM describes the software at the moment it was generated. This assessment matched every declared component against published advisories and ranked each finding by fixed, published rules. It did not run or inspect the software.
The inventory collection time was not recorded separately, so the assessment date does not prove the inventory is current.
One action per package, ordered by exploitation first and then severity. Each target is the lowest version that clears the most findings, checked against current advisories. It was not tested for compatibility with your application, so verify the deployed result with a fresh scan. Appendix A lists every finding each upgrade clears.
Upgrades that clear a Fix now finding: a fix exists and the vulnerability is known exploited or likely to be.
| # | Package | Upgrade | Tier | Clears | Exploit signal |
|---|---|---|---|---|---|
| 1 | django pypi | 3.2.0 → 5.2.17 major | Fix now | 37 | EPSS 73.6% |
| 2 | nokogiri gem | 1.11.0 → 1.19.4 minor | Fix now | 33 | EPSS 51.7% |
Upgrades whose most urgent finding is Fix soon: a moderate exploitation signal or high severity.
| # | Package | Upgrade | Tier | Clears | Exploit signal |
|---|---|---|---|---|---|
| 3 | rack gem | 2.2.3 → 2.2.23 patch | Fix soon | 32 | EPSS 35.4% |
| 4 | Newtonsoft.Json nuget | 12.0.3 → 13.0.1 major | Fix soon | 1 | EPSS 32.9% |
| 5 | ejs npm | 3.1.6 → 3.1.10 patch | Fix soon | 2 | EPSS 32.8% |
| 6 | System.Text.Encodings.Web nuget | 4.7.1 → 4.7.2 patch | Fix soon | 1 | EPSS 30.1% |
| 7 | lodash npm | 4.17.15 → 4.18.0 minor | Fix soon | 4 | EPSS 21.3% |
| 8 | requests pypi | 2.19.0 → 2.33.0 minor | Fix soon | 5 | EPSS 7.4% |
| 9 | pyyaml pypi | 5.3.1 → 5.4 minor | Fix soon | 1 | EPSS 6.0% |
| 10 | jinja2 pypi | 2.11.2 → 3.1.6 major | Fix soon | 5 | EPSS 3.5% |
| 11 | urllib3 pypi | 1.25.8 → 2.8.0 major | Fix soon | 11 | EPSS 3.3% |
| 12 | ws npm | 7.4.5 → 7.5.11 minor | Fix soon | 3 | EPSS 2.8% |
| 13 | smallvec cargo | 1.6.0 → 1.6.1 patch | Fix soon | 1 | EPSS 1.7% |
| 14 | golang.org/x/text golang | v0.3.7 → v0.39.0 minor | Fix soon | 2 | EPSS 1.5% |
| 15 | github.com/gin-gonic/gin golang | v1.6.3 → v1.9.1 minor | Fix soon | 3 | EPSS 1.3% |
| 16 | @babel/traverse npm | 7.20.0 → 7.23.2 minor | Fix soon | 1 | EPSS 0.5% |
| 18 | axios npm | 0.21.1 → 1.20.0 major | Fix soon | 24 | EPSS 8.5% |
| 19 | openssl cargo | 0.10.38 → 0.10.80 patch | Fix soon | 13 | EPSS 0.7% |
Upgrades with no sign of urgency. Worth doing with routine dependency updates.
| # | Package | Upgrade | Tier | Clears | Exploit signal |
|---|---|---|---|---|---|
| 17 | time cargo | 0.1.44 → 0.2.23 minor | Monitor | 1 | EPSS 1.6% |
Baseline assessment. A second saved scan is needed to show what changed.
0 upgrades were marked done, and 0 findings were ruled out by the account or by VEX. Marking an upgrade done is a declaration, not verified remediation.
No published version resolves these. Each needs a mitigation, a compensating control, a replacement component, or a recorded risk decision.
| Priority | Component and advisory | Fixed in | Evidence |
|---|---|---|---|
| No fix available 7.5 high EPSS 2.2% |
github.com/dgrijalva/jwt-go v3.2.0 CVE-2020-26160 cdx-mixed-ecosystems.json |
No published fix identified | Authorization bypass in github.com/dgrijalva/jwt-go CVSS 7.5 (high) via CVSS 3.1; No fixed version is available yet |
Annex I, Part II of Regulation (EU) 2024/2847 asks manufacturers to document the components in their products and handle vulnerabilities without delay. This table maps what this assessment evidences. It is a readiness view, not a conformity assessment, and nothing here makes a product compliant or certified.
| What Annex I, Part II asks for | Status | What this assessment shows |
|---|---|---|
| Identify and document the components contained in the product | Evidenced | 20 components documented from CycloneDX JSON. |
| A software bill of materials in a commonly used, machine-readable format | Evidenced | CycloneDX JSON, with 100% of components carrying a package identifier and version. |
| Identify vulnerabilities in those components | Evidenced | 181 findings, 0 of them on CISA's Known Exploited Vulnerabilities list. A KEV listing is an early signal that Article 14 reporting may apply. Whether a flaw is actively exploited in the product is a separate assessment. |
| Address and remediate vulnerabilities without delay | Partly evidenced | 19 upgrades recommended, clearing 180 findings. 1 have no available fix and need a mitigation or a documented risk decision. |
| Secure design, security updates and the rest of Annex I | Not covered | Outside what a dependency assessment can show. |
Appendix A
| Priority | Component and advisory | Fixed in | Evidence |
|---|---|---|---|
| Fix now 9.8 critical EPSS 73.6% |
django 3.2.0 CVE-2022-34265 cdx-mixed-ecosystems.json |
3.2.14 | Django `Trunc()` and `Extract()` database functions vulnerable to SQL Injection EPSS 73.6%: high probability of exploitation in the next 30 days; CVSS 9.8 (critical) via CVSS 3.1; Fixed in 3.2.14 |
| Fix now 7.5 high EPSS 62.6% |
django 3.2.0 CVE-2023-24580 cdx-mixed-ecosystems.json |
3.2.18 | Resource exhaustion in Django EPSS 62.6%: high probability of exploitation in the next 30 days; CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.18 |
| Fix now 7.5 high EPSS 51.7% |
nokogiri 1.11.0 CVE-2018-25032 cdx-mixed-ecosystems.json |
1.13.4 | Nokogiri affected by zlib's Out-of-bounds Write vulnerability EPSS 51.7%: high probability of exploitation in the next 30 days; CVSS 7.5 (high) via CVSS 3.1; Fixed in 1.13.4 |
| Fix soon 7.5 high EPSS 49.8% |
django 3.2.0 CVE-2023-46695 cdx-mixed-ecosystems.json |
3.2.23 | Django potential denial of service vulnerability in UsernameField on Windows EPSS 49.8%: moderate probability of exploitation; CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.23 |
| Fix soon 7.5 high EPSS 49.5% |
django 3.2.0 CVE-2022-23833 cdx-mixed-ecosystems.json |
3.2.12 | Infinite Loop in Django EPSS 49.5%: moderate probability of exploitation; CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.12 |
| Fix soon 7.5 high EPSS 47.4% |
django 3.2.0 CVE-2023-23969 cdx-mixed-ecosystems.json |
3.2.17 | Django contains Uncontrolled Resource Consumption via cached header EPSS 47.4%: moderate probability of exploitation; CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.17 |
| Fix soon 9.8 critical EPSS 44.4% |
django 3.2.0 CVE-2021-35042 cdx-mixed-ecosystems.json |
3.2.5 | SQL Injection in Django EPSS 44.4%: moderate probability of exploitation; CVSS 9.8 (critical) via CVSS 3.1; Fixed in 3.2.5 |
| Fix soon 5.3 medium EPSS 35.4% |
rack 2.2.3 CVE-2024-25126 cdx-mixed-ecosystems.json |
2.2.8.1 | Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial) EPSS 35.4%: moderate probability of exploitation; Fixed in 2.2.8.1 |
| Fix soon 7.5 high EPSS 32.9% |
Newtonsoft.Json 12.0.3 CVE-2024-21907 cdx-mixed-ecosystems.json |
13.0.1 | Improper Handling of Exceptional Conditions in Newtonsoft.Json EPSS 32.9%: moderate probability of exploitation; CVSS 7.5 (high) via CVSS 3.1; Fixed in 13.0.1 |
| Fix soon 9.8 critical EPSS 32.8% |
ejs 3.1.6 CVE-2022-29078 cdx-mixed-ecosystems.json |
3.1.7 | ejs template injection vulnerability EPSS 32.8%: moderate probability of exploitation; CVSS 9.8 (critical) via CVSS 3.1; Fixed in 3.1.7 |
| Fix soon 9.8 critical EPSS 30.1% |
System.Text.Encodings.Web 4.7.1 CVE-2021-26701 cdx-mixed-ecosystems.json |
4.7.2 | .NET Core Remote Code Execution Vulnerability EPSS 30.1%: moderate probability of exploitation; CVSS 9.8 (critical) via CVSS 3.1; Fixed in 4.7.2 |
| Fix soon 8.8 high EPSS 21.9% |
nokogiri 1.11.0 CVE-2021-3518 cdx-mixed-ecosystems.json |
1.11.4 | Nokogiri Implements libxml2 version vulnerable to use-after-free EPSS 21.9%: moderate probability of exploitation; CVSS 8.8 (high) via CVSS 3.1; Fixed in 1.11.4 |
| Fix soon 8.1 high EPSS 21.3% |
lodash 4.17.15 CVE-2021-23337 cdx-mixed-ecosystems.json |
4.17.21 | Command Injection in lodash EPSS 21.3%: moderate probability of exploitation; CVSS 8.1 (high) via CVSS 3.1; Fixed in 4.17.21 |
| Fix soon 9.1 critical EPSS 19.4% |
django 3.2.0 CVE-2025-64459 cdx-mixed-ecosystems.json |
4.2.26 | Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects. EPSS 19.4%: moderate probability of exploitation; CVSS 9.1 (critical) via CVSS 3.1; Fixed in 4.2.26 |
| Fix soon 9.8 critical EPSS 18.7% |
django 3.2.0 CVE-2022-28346 cdx-mixed-ecosystems.json |
3.2.13 | SQL Injection in Django EPSS 18.7%: moderate probability of exploitation; CVSS 9.8 (critical) via CVSS 3.1; Fixed in 3.2.13 |
| Fix soon 8.8 high EPSS 17.6% |
nokogiri 1.11.0 CVE-2021-30560 cdx-mixed-ecosystems.json |
1.13.2 | Nokogiri has vulnerable dependencies on libxml2 and libxslt EPSS 17.6%: moderate probability of exploitation; CVSS 8.8 (high) via CVSS 3.1; Fixed in 1.13.2 |
| Fix soon 8.6 high EPSS 17.0% |
nokogiri 1.11.0 CVE-2021-3517 cdx-mixed-ecosystems.json |
1.11.4 | Nokogiri contains libxml Out-of-bounds Write vulnerability EPSS 17.0%: moderate probability of exploitation; CVSS 8.6 (high) via CVSS 3.1; Fixed in 1.11.4 |
| Fix soon 7.1 high EPSS 16.8% |
django 3.2.0 CVE-2025-57833 cdx-mixed-ecosystems.json |
4.2.24 | Django is subject to SQL injection through its column aliases EPSS 16.8%: moderate probability of exploitation; CVSS 7.1 (high) via CVSS 3.1; Fixed in 4.2.24 |
| Fix soon 7.5 high EPSS 8.5% |
axios 0.21.1 CVE-2021-3749 cdx-mixed-ecosystems.json |
0.21.2 | axios Inefficient Regular Expression Complexity vulnerability CVSS 7.5 (high) via CVSS 3.1; Fixed in 0.21.2 |
| Fix soon 7.5 high EPSS 7.4% |
requests 2.19.0 CVE-2018-18074 cdx-mixed-ecosystems.json |
2.20.0 | Insufficiently Protected Credentials in Requests CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.20.0 |
| Fix soon 9.8 critical EPSS 6.0% |
pyyaml 5.3.1 CVE-2020-14343 cdx-mixed-ecosystems.json |
5.4 | Improper Input Validation in PyYAML CVSS 9.8 (critical) via CVSS 3.1; Fixed in 5.4 |
| Fix soon 7.5 high EPSS 5.3% |
django 3.2.0 CVE-2021-31542 cdx-mixed-ecosystems.json |
3.2.1 | Path Traversal in Django CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.1 |
| Fix soon 7.5 high EPSS 5.3% |
django 3.2.0 CVE-2021-33571 cdx-mixed-ecosystems.json |
3.2.4 | Django Access Control Bypass possibly leading to SSRF, RFI, and LFI attacks CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.4 |
| Fix soon 7.4 high EPSS 5.2% |
lodash 4.17.15 CVE-2020-8203 cdx-mixed-ecosystems.json |
4.17.19 | Prototype Pollution in lodash CVSS 7.4 (high) via CVSS 3.1; Fixed in 4.17.19 |
| Fix soon 7.5 high EPSS 3.5% |
nokogiri 1.11.0 CVE-2022-24836 cdx-mixed-ecosystems.json |
1.13.4 | Nokogiri Inefficient Regular Expression Complexity CVSS 7.5 (high) via CVSS 3.1; Fixed in 1.13.4 |
| Fix soon 7.5 high EPSS 3.3% |
urllib3 1.25.8 CVE-2021-33503 cdx-mixed-ecosystems.json |
1.26.5 | Catastrophic backtracking in URL authority parser when passed URL containing many @ characters CVSS 7.5 (high) via CVSS 3.1; Fixed in 1.26.5 |
| Fix soon 8.2 high EPSS 3.2% |
nokogiri 1.11.0 CVE-2022-29181 cdx-mixed-ecosystems.json |
1.13.6 | Nokogiri Improperly Handles Unexpected Data Type CVSS 8.2 (high) via CVSS 3.1; Fixed in 1.13.6 |
| Fix soon 7.5 high EPSS 3.0% |
django 3.2.0 CVE-2022-41323 cdx-mixed-ecosystems.json |
3.2.16 | Django denial-of-service vulnerability in internationalized URLs CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.16 |
| Fix soon 7.5 high EPSS 3.0% |
django 3.2.0 CVE-2023-36053 cdx-mixed-ecosystems.json |
3.2.20 | Django has regular expression denial of service vulnerability in EmailValidator/URLValidator CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.20 |
| Fix soon 7.5 high EPSS 3.0% |
urllib3 1.25.8 CVE-2026-21441 cdx-mixed-ecosystems.json |
2.6.3 | Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.6.3 |
| Fix soon 9.8 critical EPSS 2.9% |
django 3.2.0 CVE-2022-28347 cdx-mixed-ecosystems.json |
3.2.13 | SQL Injection in Django CVSS 9.8 (critical) via CVSS 3.1; Fixed in 3.2.13 |
| Fix soon 7.5 high EPSS 2.4% |
django 3.2.0 CVE-2021-45115 cdx-mixed-ecosystems.json |
3.2.11 | Denial-of-service in Django CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.11 |
| Fix soon 7.3 high EPSS 2.3% |
django 3.2.0 CVE-2021-44420 cdx-mixed-ecosystems.json |
3.2.10 | Potential bypass of an upstream access control based on URL paths in Django CVSS 7.3 (high) via CVSS 3.1; Fixed in 3.2.10 |
| Fix soon 7.5 high EPSS 2.1% |
rack 2.2.3 CVE-2022-30122 cdx-mixed-ecosystems.json |
2.2.3.1 | Denial of Service Vulnerability in Rack Multipart Parsing CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.3.1 |
| Fix soon 7.5 high EPSS 1.9% |
django 3.2.0 CVE-2025-64458 cdx-mixed-ecosystems.json |
4.2.26 | Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows CVSS 7.5 (high) via CVSS 3.1; Fixed in 4.2.26 |
| Fix soon 10.0 critical EPSS 1.9% |
rack 2.2.3 CVE-2022-30123 cdx-mixed-ecosystems.json |
2.2.3.1 | Possible shell escape sequence injection vulnerability in Rack CVSS 10.0 (critical) via CVSS 3.1; Fixed in 2.2.3.1 |
| Fix soon 7.5 high EPSS 1.9% |
django 3.2.0 CVE-2021-45116 cdx-mixed-ecosystems.json |
3.2.11 | Information disclosure in Django CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.11 |
| Fix soon 7.5 high EPSS 1.8% |
rack 2.2.3 CVE-2023-27530 cdx-mixed-ecosystems.json |
2.2.6.3 | Rack has possible DoS Vulnerability in Multipart MIME parsing CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.6.3 |
| Fix soon 7.5 high EPSS 1.8% |
axios 0.21.1 CVE-2026-25639 cdx-mixed-ecosystems.json |
0.30.3 | Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig CVSS 7.5 (high) via CVSS 3.1; Fixed in 0.30.3 |
| Fix soon 9.8 critical EPSS 1.7% |
smallvec 1.6.0 CVE-2021-25900 cdx-mixed-ecosystems.json |
1.6.1 | Buffer overflow in SmallVec::insert_many CVSS 9.8 (critical) via CVSS 3.1; Fixed in 1.6.1 |
| Fix soon 7.5 high EPSS 1.6% |
rack 2.2.3 CVE-2022-44570 cdx-mixed-ecosystems.json |
2.2.6.2 | Denial of service via header parsing in Rack CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.6.2 |
| Fix soon 7.5 high EPSS 1.5% |
golang.org/x/text v0.3.7 CVE-2022-32149 cdx-mixed-ecosystems.json |
0.3.8 | golang.org/x/text/language Denial of service via crafted Accept-Language header CVSS 7.5 (high) via CVSS 3.1; Fixed in 0.3.8 |
| Fix soon 7.5 high EPSS 1.5% |
nokogiri 1.11.0 CVE-2021-41098 cdx-mixed-ecosystems.json |
1.12.5 | Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby CVSS 7.5 (high) via CVSS 3.0; Fixed in 1.12.5 |
| Fix soon 9.8 critical EPSS 1.4% |
django 3.2.0 CVE-2023-31047 cdx-mixed-ecosystems.json |
3.2.19 | Django bypasses validation when using one form field to upload multiple files CVSS 9.8 (critical) via CVSS 3.1; Fixed in 3.2.19 |
| Fix soon 7.5 high EPSS 1.3% |
ws 7.4.5 CVE-2024-37890 cdx-mixed-ecosystems.json |
7.5.10 | ws affected by a DoS when handling a request with many HTTP headers CVSS 7.5 (high) via CVSS 3.1; Fixed in 7.5.10 |
| Fix soon 7.1 high EPSS 1.3% |
github.com/gin-gonic/gin v1.6.3 CVE-2020-28483 cdx-mixed-ecosystems.json |
1.7.7 | Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin CVSS 7.1 (high) via CVSS 3.1; Fixed in 1.7.7 |
| Fix soon 8.1 high EPSS 1.2% |
urllib3 1.25.8 CVE-2023-43804 cdx-mixed-ecosystems.json |
1.26.17 | `Cookie` HTTP header isn't stripped on cross-origin redirects CVSS 8.1 (high) via CVSS 3.1; Fixed in 1.26.17 |
| Fix soon 7.5 high EPSS 1.2% |
rack 2.2.3 CVE-2025-46727 cdx-mixed-ecosystems.json |
2.2.14 | Rack has an Unbounded-Parameter DoS in Rack::QueryParser CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.14 |
| Fix soon 7.5 high EPSS 1.1% |
rack 2.2.3 CVE-2025-27610 cdx-mixed-ecosystems.json |
2.2.13 | Local File Inclusion in Rack::Static CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.13 |
| Fix soon 7.0 high EPSS 1.0% |
axios 0.21.1 CVE-2026-44495 cdx-mixed-ecosystems.json |
0.31.1 | axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge CVSS 7.0 (high) via CVSS 3.1; Fixed in 0.31.1 |
| Fix soon 7.5 high EPSS 1.0% |
axios 0.21.1 CVE-2026-42039 cdx-mixed-ecosystems.json |
0.31.1 | Axios: unbounded recursion in toFormData causes DoS via deeply nested request data CVSS 7.5 (high) via CVSS 3.1; Fixed in 0.31.1 |
| Fix soon 7.5 high EPSS 1.0% |
axios 0.21.1 CVE-2026-44496 cdx-mixed-ecosystems.json |
0.32.0 | Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection CVSS 7.5 (high) via CVSS 3.1; Fixed in 0.32.0 |
| Fix soon 7.5 high EPSS 0.9% |
ws 7.4.5 CVE-2026-48779 cdx-mixed-ecosystems.json |
7.5.11 | ws: Memory exhaustion DoS from tiny fragments and data chunks CVSS 7.5 (high) via CVSS 3.1; Fixed in 7.5.11 |
| Fix soon 7.5 high EPSS 0.9% |
rack 2.2.3 CVE-2025-61770 cdx-mixed-ecosystems.json |
2.2.19 | Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion) CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.19 |
| Fix soon 7.5 high EPSS 0.9% |
rack 2.2.3 CVE-2025-61772 cdx-mixed-ecosystems.json |
2.2.19 | Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion) CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.19 |
| Fix soon 7.4 high EPSS 0.9% |
axios 0.21.1 CVE-2026-42033 cdx-mixed-ecosystems.json |
0.31.1 | Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking CVSS 7.4 (high) via CVSS 3.1; Fixed in 0.31.1 |
| Fix soon 8.8 high EPSS 0.9% |
django 3.2.0 CVE-2022-36359 cdx-mixed-ecosystems.json |
3.2.15 | Django vulnerable to Reflected File Download attack CVSS 8.8 (high) via CVSS 3.1; Fixed in 3.2.15 |
| Fix soon 8.6 high EPSS 0.8% |
axios 0.21.1 CVE-2026-44492 cdx-mixed-ecosystems.json |
0.32.0 | axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718) CVSS 8.6 (high) via CVSS 3.1; Fixed in 0.32.0 |
| Fix soon — high EPSS 0.8% |
axios 0.21.1 CVE-2025-27152 cdx-mixed-ecosystems.json |
0.30.0 | axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL Published severity: high; numeric CVSS score unavailable; Fixed in 0.30.0 |
| Fix soon 7.5 high EPSS 0.8% |
axios 0.21.1 CVE-2026-44486 cdx-mixed-ecosystems.json |
0.32.0 | Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection CVSS 7.5 (high) via CVSS 3.1; Fixed in 0.32.0 |
| Fix soon — high EPSS 0.8% |
axios 0.21.1 CVE-2026-44487 cdx-mixed-ecosystems.json |
0.32.0 | Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter Published severity: high; numeric CVSS score unavailable; Fixed in 0.32.0 |
| Fix soon — high EPSS 0.7% |
urllib3 1.25.8 CVE-2025-66418 cdx-mixed-ecosystems.json |
2.6.0 | urllib3 allows an unbounded number of links in the decompression chain Published severity: high; numeric CVSS score unavailable; Fixed in 2.6.0 |
| Fix soon — high EPSS 0.7% |
urllib3 1.25.8 CVE-2025-66471 cdx-mixed-ecosystems.json |
2.6.0 | urllib3 streaming API improperly handles highly compressed data Published severity: high; numeric CVSS score unavailable; Fixed in 2.6.0 |
| Fix soon 7.5 high EPSS 0.7% |
rack 2.2.3 CVE-2026-22860 cdx-mixed-ecosystems.json |
2.2.22 | Rack has a Directory Traversal via Rack:Directory CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.22 |
| Fix soon 7.5 high EPSS 0.7% |
rack 2.2.3 CVE-2026-34829 cdx-mixed-ecosystems.json |
2.2.23 | Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.23 |
| Fix soon 7.5 high EPSS 0.6% |
rack 2.2.3 CVE-2025-61919 cdx-mixed-ecosystems.json |
2.2.20 | Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.20 |
| Fix soon 7.2 high EPSS 0.6% |
axios 0.21.1 CVE-2026-42043 cdx-mixed-ecosystems.json |
0.31.1 | Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0 CVSS 7.2 (high) via CVSS 3.1; Fixed in 0.31.1 |
| Fix soon 7.5 high EPSS 0.6% |
rack 2.2.3 CVE-2025-59830 cdx-mixed-ecosystems.json |
2.2.18 | Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.18 |
| Fix soon 7.5 high EPSS 0.6% |
rack 2.2.3 CVE-2025-61771 cdx-mixed-ecosystems.json |
2.2.19 | Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion) CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.19 |
| Fix soon 7.8 high EPSS 0.5% |
jinja2 2.11.2 CVE-2024-56326 cdx-mixed-ecosystems.json |
3.1.5 | Jinja has a sandbox breakout through indirect reference to format method CVSS 7.8 (high) via CVSS 3.1; Fixed in 3.1.5 |
| Fix soon 9.3 critical EPSS 0.5% |
traverse 7.20.0 CVE-2023-45133 cdx-mixed-ecosystems.json |
7.23.2 | Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code CVSS 9.3 (critical) via CVSS 3.1; Fixed in 7.23.2 |
| Fix soon 7.5 high EPSS 0.5% |
rack 2.2.3 CVE-2026-34785 cdx-mixed-ecosystems.json |
2.2.23 | Rack::Static prefix matching can expose unintended files under the static root CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.23 |
| Fix soon 7.5 high EPSS 0.5% |
nokogiri 1.11.0 CVE-2026-79770 cdx-mixed-ecosystems.json |
1.19.3 | Nokogiri CSS selector tokenizer has regular expression backtracking CVSS 7.5 (high) via CVSS 3.1; Fixed in 1.19.3 |
| Fix soon 7.5 high EPSS 0.5% |
rack 2.2.3 CVE-2026-34230 cdx-mixed-ecosystems.json |
2.2.23 | Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.23 |
| Fix soon 7.4 high EPSS 0.4% |
axios 0.21.1 CVE-2026-42035 cdx-mixed-ecosystems.json |
0.31.1 | Axios: Header Injection via Prototype Pollution CVSS 7.4 (high) via CVSS 3.1; Fixed in 0.31.1 |
| Fix soon — high EPSS 0.3% |
openssl 0.10.38 CVE-2026-41676 cdx-mixed-ecosystems.json |
0.10.78 | rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1 Published severity: high; numeric CVSS score unavailable; Fixed in 0.10.78 |
| Fix soon — high EPSS 0.3% |
openssl 0.10.38 CVE-2026-41898 cdx-mixed-ecosystems.json |
0.10.78 | rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer Published severity: high; numeric CVSS score unavailable; Fixed in 0.10.78 |
| Fix soon — high EPSS 0.3% |
openssl 0.10.38 CVE-2026-41678 cdx-mixed-ecosystems.json |
0.10.78 | rust-openssl has incorrect bounds assertion in aes key wrap Published severity: high; numeric CVSS score unavailable; Fixed in 0.10.78 |
| Fix soon — high EPSS 0.2% |
openssl 0.10.38 CVE-2026-42327 cdx-mixed-ecosystems.json |
0.10.79 | rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs Published severity: high; numeric CVSS score unavailable; Fixed in 0.10.79 |
| Fix soon 8.6 high EPSS — |
nokogiri 1.11.0 CVE-2022-50999 cdx-mixed-ecosystems.json |
1.13.5 | Integer Overflow or Wraparound in libxml2 affects Nokogiri CVSS 8.6 (high) via CVSS 3.1; Fixed in 1.13.5 |
| Fix soon 7.8 high EPSS — |
nokogiri 1.11.0 CVE-2025-71406 cdx-mixed-ecosystems.json |
1.18.4 | Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs CVSS 7.8 (high) via CVSS 3.1; Fixed in 1.18.4 |
| Fix soon 7.5 high EPSS — |
nokogiri 1.11.0 GHSA-gx8x-g87m-h5q6 cdx-mixed-ecosystems.json |
1.13.4 | Denial of Service (DoS) in Nokogiri on JRuby CVSS 7.5 (high) via CVSS 3.1; Fixed in 1.13.4 |
| Fix soon 7.5 high EPSS — |
nokogiri 1.11.0 GHSA-v6gp-9mmm-c6p5 cdx-mixed-ecosystems.json |
1.13.4 | Out-of-bounds Write in zlib affects Nokogiri CVSS 7.5 (high) via CVSS 3.1; Fixed in 1.13.4 |
| Fix soon — high EPSS — |
nokogiri 1.11.0 CVE-2022-51000 cdx-mixed-ecosystems.json |
1.13.2 | Vulnerable dependencies in Nokogiri Published severity: high; numeric CVSS score unavailable; Fixed in 1.13.2 |
| Fix soon — high EPSS — |
urllib3 1.25.8 CVE-2026-97689 cdx-mixed-ecosystems.json |
2.8.0 | urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory Published severity: high; numeric CVSS score unavailable; Fixed in 2.8.0 |
| Fix soon — critical EPSS — |
nokogiri 1.11.0 GHSA-353f-x4gh-cqq8 cdx-mixed-ecosystems.json |
1.18.9 | Nokogiri patches vendored libxml2 to resolve multiple CVEs Published severity: critical; numeric CVSS score unavailable; Fixed in 1.18.9 |
| Fix soon — high EPSS — |
openssl 0.10.38 GHSA-6hcf-g6gr-hhcr cdx-mixed-ecosystems.json |
0.10.48 | `openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference Published severity: high; numeric CVSS score unavailable; Fixed in 0.10.48 |
| Fix soon — high EPSS — |
openssl 0.10.38 GHSA-9qwg-crg9-m2vc cdx-mixed-ecosystems.json |
0.10.48 | `openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read Published severity: high; numeric CVSS score unavailable; Fixed in 0.10.48 |
| Monitor 5.3 medium EPSS 7.3% |
lodash 4.17.15 CVE-2020-28500 cdx-mixed-ecosystems.json |
4.17.21 | Regular Expression Denial of Service (ReDoS) in lodash Fixed in 4.17.21 |
| Monitor 5.3 medium EPSS 3.5% |
jinja2 2.11.2 CVE-2020-28493 cdx-mixed-ecosystems.json |
2.11.3 | Regular Expression Denial of Service (ReDoS) in Jinja2 Fixed in 2.11.3 |
| Monitor 5.9 medium EPSS 3.5% |
nokogiri 1.11.0 CVE-2021-3537 cdx-mixed-ecosystems.json |
1.11.4 | Nokogiri Implements libxml2 version vulnerable to null pointer dereferencing Fixed in 1.11.4 |
| Monitor 6.1 medium EPSS 3.4% |
django 3.2.0 CVE-2022-22818 cdx-mixed-ecosystems.json |
3.2.12 | Cross-site Scripting in Django Fixed in 3.2.12 |
| Monitor 6.1 medium EPSS 3.2% |
django 3.2.0 CVE-2021-32052 cdx-mixed-ecosystems.json |
3.2.2 | Header injection possible in Django Fixed in 3.2.2 |
| Monitor 6.1 medium EPSS 3.0% |
requests 2.19.0 CVE-2023-32681 cdx-mixed-ecosystems.json |
2.31.0 | Unintended leak of Proxy-Authorization header in requests Fixed in 2.31.0 |
| Monitor 5.3 medium EPSS 2.8% |
ws 7.4.5 CVE-2021-32640 cdx-mixed-ecosystems.json |
7.4.6 | ReDoS in Sec-Websocket-Protocol header Fixed in 7.4.6 |
| Monitor 4.9 medium EPSS 2.7% |
django 3.2.0 CVE-2021-33203 cdx-mixed-ecosystems.json |
3.2.4 | Path Traversal in Django Fixed in 3.2.4 |
| Monitor 5.3 medium EPSS 2.4% |
django 3.2.0 CVE-2021-45452 cdx-mixed-ecosystems.json |
3.2.11 | Directory-traversal in Django Fixed in 3.2.11 |
| Monitor 6.5 medium EPSS 2.3% |
urllib3 1.25.8 CVE-2020-26137 cdx-mixed-ecosystems.json |
1.25.9 | CRLF injection in urllib3 Fixed in 1.25.9 |
| Monitor — low EPSS 2.0% |
rack 2.2.3 CVE-2024-26146 cdx-mixed-ecosystems.json |
2.2.8.1 | Rack Header Parsing leads to Possible Denial of Service Vulnerability Fixed in 2.2.8.1 |
| Monitor 5.3 medium EPSS 1.9% |
django 3.2.0 CVE-2024-27351 cdx-mixed-ecosystems.json |
3.2.25 | Regular expression denial-of-service in Django Fixed in 3.2.25 |
| Monitor 6.5 medium EPSS 1.8% |
lodash 4.17.15 CVE-2025-13465 cdx-mixed-ecosystems.json |
4.17.23 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` Fixed in 4.17.23 |
| Monitor 6.2 medium EPSS 1.6% |
time 0.1.44 CVE-2020-26235 cdx-mixed-ecosystems.json |
0.2.0 | Segmentation fault in time Fixed in 0.2.0 |
| Monitor — low EPSS 1.6% |
rack 2.2.3 CVE-2022-44572 cdx-mixed-ecosystems.json |
2.2.6.1 | Denial of service via multipart parsing in Rack Fixed in 2.2.6.1 |
| Monitor — low EPSS 1.6% |
rack 2.2.3 CVE-2024-26141 cdx-mixed-ecosystems.json |
2.2.8.1 | Rack has possible DoS Vulnerability with Range Header Fixed in 2.2.8.1 |
| Monitor 5.9 medium EPSS 1.6% |
django 3.2.0 CVE-2024-24680 cdx-mixed-ecosystems.json |
3.2.24 | Django denial-of-service attack in the intcomma template filter Fixed in 3.2.24 |
| Monitor 5.3 medium EPSS 1.5% |
django 3.2.0 CVE-2023-41164 cdx-mixed-ecosystems.json |
3.2.21 | Django Denial of service vulnerability in django.utils.encoding.uri_to_iri Fixed in 3.2.21 |
| Monitor — low EPSS 1.5% |
rack 2.2.3 CVE-2022-44571 cdx-mixed-ecosystems.json |
2.2.6.1 | Denial of Service Vulnerability in Rack Content-Disposition parsing Fixed in 2.2.6.1 |
| Monitor 4.8 medium EPSS 1.3% |
axios 0.21.1 CVE-2026-40175 cdx-mixed-ecosystems.json |
0.31.0 | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain Fixed in 0.31.0 |
| Monitor 5.9 medium EPSS 1.2% |
django 3.2.0 CVE-2023-43665 cdx-mixed-ecosystems.json |
3.2.22 | Django Denial-of-service in django.utils.text.Truncator Fixed in 3.2.22 |
| Monitor 4.8 medium EPSS 1.2% |
axios 0.21.1 CVE-2025-62718 cdx-mixed-ecosystems.json |
0.31.0 | Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF Fixed in 0.31.0 |
| Monitor 6.5 medium EPSS 1.2% |
rack 2.2.3 CVE-2025-25184 cdx-mixed-ecosystems.json |
2.2.11 | Possible Log Injection in Rack::CommonLogger Fixed in 2.2.11 |
| Monitor 4.4 medium EPSS 1.1% |
urllib3 1.25.8 CVE-2024-37891 cdx-mixed-ecosystems.json |
1.26.19 | urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects Fixed in 1.26.19 |
| Monitor — low EPSS 1.1% |
rack 2.2.3 CVE-2023-27539 cdx-mixed-ecosystems.json |
2.2.6.4 | Possible Denial of Service Vulnerability in Rack's header parsing Fixed in 2.2.6.4 |
| Monitor 5.3 medium EPSS 1.0% |
requests 2.19.0 CVE-2024-47081 cdx-mixed-ecosystems.json |
2.32.4 | Requests vulnerable to .netrc credentials leak via malicious URLs Fixed in 2.32.4 |
| Monitor 5.4 medium EPSS 1.0% |
jinja2 2.11.2 CVE-2024-34064 cdx-mixed-ecosystems.json |
3.1.4 | Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter Fixed in 3.1.4 |
| Monitor 5.6 medium EPSS 0.9% |
github.com/gin-gonic/gin v1.6.3 CVE-2023-26125 cdx-mixed-ecosystems.json |
1.9.0 | Improper input validation in github.com/gin-gonic/gin Fixed in 1.9.0 |
| Monitor 5.4 medium EPSS 0.9% |
jinja2 2.11.2 CVE-2024-22195 cdx-mixed-ecosystems.json |
3.1.3 | Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter Fixed in 3.1.3 |
| Monitor 4.8 medium EPSS 0.8% |
axios 0.21.1 CVE-2026-42041 cdx-mixed-ecosystems.json |
0.31.1 | Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy Fixed in 0.31.1 |
| Monitor 3.7 low EPSS 0.8% |
django 3.2.0 CVE-2024-45231 cdx-mixed-ecosystems.json |
4.2.16 | Django allows enumeration of user e-mail addresses Fixed in 4.2.16 |
| Monitor 5.3 medium EPSS 0.8% |
django 3.2.0 CVE-2026-15830 cdx-mixed-ecosystems.json |
5.2.17 | Django GeoDjango vulnerable to denial of service through deeply nested geometry collections Fixed in 5.2.17 |
| Monitor — medium EPSS 0.8% |
rack 2.2.3 CVE-2025-27111 cdx-mixed-ecosystems.json |
2.2.12 | Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection Fixed in 2.2.12 |
| Monitor 4.0 medium EPSS 0.8% |
django 3.2.0 CVE-2025-48432 cdx-mixed-ecosystems.json |
4.2.22 | Django Improper Output Neutralization for Logs vulnerability Fixed in 4.2.22 |
| Monitor — medium EPSS 0.7% |
openssl 0.10.38 CVE-2025-24898 cdx-mixed-ecosystems.json |
0.10.70 | rust-openssl ssl::select_next_proto use after free Fixed in 0.10.70 |
| Monitor 4.0 medium EPSS 0.6% |
ejs 3.1.6 CVE-2024-33883 cdx-mixed-ecosystems.json |
3.1.10 | ejs lacks certain pollution protection Fixed in 3.1.10 |
| Monitor 6.5 medium EPSS 0.6% |
axios 0.21.1 CVE-2023-45857 cdx-mixed-ecosystems.json |
0.28.0 | Axios Cross-Site Request Forgery Vulnerability Fixed in 0.28.0 |
| Monitor 5.8 medium EPSS 0.6% |
rack 2.2.3 CVE-2025-61780 cdx-mixed-ecosystems.json |
2.2.20 | Rack has a Possible Information Disclosure Vulnerability Fixed in 2.2.20 |
| Monitor 4.2 medium EPSS 0.5% |
urllib3 1.25.8 CVE-2023-45803 cdx-mixed-ecosystems.json |
1.26.18 | urllib3's request body not stripped after redirect from 303 status changes request method to GET Fixed in 1.26.18 |
| Monitor — medium EPSS 0.5% |
jinja2 2.11.2 CVE-2025-27516 cdx-mixed-ecosystems.json |
3.1.6 | Jinja2 vulnerable to sandbox breakout through attr filter selecting format method Fixed in 3.1.6 |
| Monitor 4.3 medium EPSS 0.5% |
github.com/gin-gonic/gin v1.6.3 CVE-2023-29401 cdx-mixed-ecosystems.json |
1.9.1 | Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function Fixed in 1.9.1 |
| Monitor 5.3 medium EPSS 0.5% |
axios 0.21.1 CVE-2026-42034 cdx-mixed-ecosystems.json |
0.31.1 | Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0 Fixed in 0.31.1 |
| Monitor 5.3 medium EPSS 0.5% |
axios 0.21.1 CVE-2026-42036 cdx-mixed-ecosystems.json |
0.31.1 | Axios: HTTP adapter streamed responses bypass maxContentLength Fixed in 0.31.1 |
| Monitor — unknown EPSS 0.5% |
golang.org/x/text v0.3.7 CVE-2026-56852 cdx-mixed-ecosystems.json |
0.39.0 | Infinite loop on invalid input in golang.org/x/text No severity score published for this advisory; Fixed in 0.39.0 |
| Monitor 5.3 medium EPSS 0.5% |
urllib3 1.25.8 CVE-2025-50181 cdx-mixed-ecosystems.json |
2.5.0 | urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation Fixed in 2.5.0 |
| Monitor 5.3 medium EPSS 0.5% |
rack 2.2.3 CVE-2026-34826 cdx-mixed-ecosystems.json |
2.2.23 | Rack's multipart byte range processing allows denial of service via excessive overlapping ranges Fixed in 2.2.23 |
| Monitor — low EPSS 0.5% |
nokogiri 1.11.0 CVE-2026-57434 cdx-mixed-ecosystems.json |
1.19.4 | Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes Fixed in 1.19.4 |
| Monitor — low EPSS 0.5% |
nokogiri 1.11.0 CVE-2026-57435 cdx-mixed-ecosystems.json |
1.19.4 | Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=` Fixed in 1.19.4 |
| Monitor 4.8 medium EPSS 0.4% |
django 3.2.0 CVE-2026-53877 cdx-mixed-ecosystems.json |
5.2.16 | Django: GDALRaster may over-read heap memory when constructed from bytes Fixed in 5.2.16 |
| Monitor 3.1 low EPSS 0.4% |
django 3.2.0 CVE-2026-48587 cdx-mixed-ecosystems.json |
5.2.15 | Django: has_vary_header may expose cached responses when Vary values contain whitespace Fixed in 5.2.15 |
| Monitor 3.1 low EPSS 0.4% |
django 3.2.0 CVE-2026-48588 cdx-mixed-ecosystems.json |
5.2.16 | Django: cache middleware may expose private responses when unrelated request cookies are present Fixed in 5.2.16 |
| Monitor 3.1 low EPSS 0.4% |
django 3.2.0 CVE-2026-8404 cdx-mixed-ecosystems.json |
5.2.15 | Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling Fixed in 5.2.15 |
| Monitor — medium EPSS 0.4% |
nokogiri 1.11.0 CVE-2026-57235 cdx-mixed-ecosystems.json |
1.19.4 | Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]` Fixed in 1.19.4 |
| Monitor — low EPSS 0.4% |
nokogiri 1.11.0 CVE-2026-57236 cdx-mixed-ecosystems.json |
1.19.4 | Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception Fixed in 1.19.4 |
| Monitor — medium EPSS 0.4% |
axios 0.21.1 CVE-2026-67316 cdx-mixed-ecosystems.json |
0.33.0 | Axios: Prototype pollution gadgets can alter axios request construction Fixed in 0.33.0 |
| Monitor 5.3 medium EPSS 0.4% |
nokogiri 1.11.0 CVE-2026-79771 cdx-mixed-ecosystems.json |
1.19.3 | Nokogiri XSLT transform has a memory leak Fixed in 1.19.3 |
| Monitor 4.8 medium EPSS 0.4% |
axios 0.21.1 CVE-2026-44490 cdx-mixed-ecosystems.json |
0.32.0 | axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions Fixed in 0.32.0 |
| Monitor — low EPSS 0.4% |
nokogiri 1.11.0 CVE-2026-57436 cdx-mixed-ecosystems.json |
1.19.4 | Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type Fixed in 1.19.4 |
| Monitor — low EPSS 0.4% |
nokogiri 1.11.0 CVE-2026-57437 cdx-mixed-ecosystems.json |
1.19.4 | Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime Fixed in 1.19.4 |
| Monitor 5.9 medium EPSS 0.4% |
rack 2.2.3 CVE-2026-34830 cdx-mixed-ecosystems.json |
2.2.23 | Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect Fixed in 2.2.23 |
| Monitor 6.8 medium EPSS 0.4% |
axios 0.21.1 CVE-2026-42038 cdx-mixed-ecosystems.json |
0.31.1 | Axios: no_proxy bypass via IP alias allows SSRF Fixed in 0.31.1 |
| Monitor 5.3 medium EPSS 0.3% |
nokogiri 1.11.0 CVE-2026-79772 cdx-mixed-ecosystems.json |
1.19.1 | Nokogiri does not check the return value from xmlC14NExecute Fixed in 1.19.1 |
| Monitor 5.6 medium EPSS 0.3% |
requests 2.19.0 CVE-2024-35195 cdx-mixed-ecosystems.json |
2.32.0 | Requests `Session` object does not verify requests after making first request with verify=False Fixed in 2.32.0 |
| Monitor 5.3 medium EPSS 0.3% |
urllib3 1.25.8 CVE-2026-44431 cdx-mixed-ecosystems.json |
2.7.0 | urllib3: Sensitive headers forwarded across origins in proxied low-level redirects Fixed in 2.7.0 |
| Monitor 5.3 medium EPSS 0.3% |
rack 2.2.3 CVE-2026-34763 cdx-mixed-ecosystems.json |
2.2.23 | Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory Fixed in 2.2.23 |
| Monitor 6.1 medium EPSS 0.3% |
django 3.2.0 CVE-2026-53878 cdx-mixed-ecosystems.json |
5.2.16 | Django: DomainNameValidator permits newline characters that may enable HTTP header injection Fixed in 5.2.16 |
| Monitor 5.3 medium EPSS 0.3% |
rack 2.2.3 CVE-2026-34786 cdx-mixed-ecosystems.json |
2.2.23 | Rack:: Static header_rules bypass via URL-encoded paths Fixed in 2.2.23 |
| Monitor 5.4 medium EPSS 0.3% |
axios 0.21.1 CVE-2026-42042 cdx-mixed-ecosystems.json |
0.31.1 | Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion Fixed in 0.31.1 |
| Monitor — medium EPSS 0.3% |
axios 0.21.1 CVE-2026-67319 cdx-mixed-ecosystems.json |
0.33.0 | Axios: Nested axios option objects can consume polluted prototype values Fixed in 0.33.0 |
| Monitor — low EPSS 0.3% |
openssl 0.10.38 CVE-2026-41677 cdx-mixed-ecosystems.json |
0.10.78 | rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length Fixed in 0.10.78 |
| Monitor 3.1 low EPSS 0.3% |
django 3.2.0 CVE-2026-6873 cdx-mixed-ecosystems.json |
5.2.15 | Django: signed cookies are vulnerable to salt namespace collisions Fixed in 5.2.15 |
| Monitor 5.4 medium EPSS 0.3% |
rack 2.2.3 CVE-2026-25500 cdx-mixed-ecosystems.json |
2.2.22 | Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href Fixed in 2.2.22 |
| Monitor 5.3 medium EPSS 0.3% |
rack 2.2.3 CVE-2026-26961 cdx-mixed-ecosystems.json |
2.2.23 | Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass. Fixed in 2.2.23 |
| Monitor 3.7 low EPSS 0.3% |
axios 0.21.1 CVE-2026-42040 cdx-mixed-ecosystems.json |
0.31.1 | Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams Fixed in 0.31.1 |
| Monitor 4.8 medium EPSS 0.2% |
rack 2.2.3 CVE-2026-34831 cdx-mixed-ecosystems.json |
2.2.23 | Rack has Content-Length mismatch in Rack::Files error responses Fixed in 2.2.23 |
| Monitor 4.2 medium EPSS 0.2% |
rack 2.2.3 CVE-2025-32441 cdx-mixed-ecosystems.json |
2.2.14 | Rack session gets restored after deletion Fixed in 2.2.14 |
| Monitor 4.5 medium EPSS 0.2% |
openssl 0.10.38 CVE-2023-53159 cdx-mixed-ecosystems.json |
0.10.55 | `openssl` `X509VerifyParamRef::set_host` buffer over-read Fixed in 0.10.55 |
| Monitor 2.6 low EPSS 0.2% |
nokogiri 1.11.0 CVE-2026-57234 cdx-mixed-ecosystems.json |
1.19.4 | Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247 Fixed in 1.19.4 |
| Monitor 5.5 medium EPSS 0.2% |
requests 2.19.0 CVE-2026-25645 cdx-mixed-ecosystems.json |
2.33.0 | Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function Fixed in 2.33.0 |
| Monitor — medium EPSS 0.2% |
openssl 0.10.38 CVE-2026-44662 cdx-mixed-ecosystems.json |
0.10.79 | rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding Fixed in 0.10.79 |
| Monitor — low EPSS 0.1% |
nokogiri 1.11.0 CVE-2026-57438 cdx-mixed-ecosystems.json |
1.19.4 | Nokogiri: Possible Use-After-Free in XInclude Processing Fixed in 1.19.4 |
| Monitor 6.5 medium EPSS — |
openssl 0.10.38 GHSA-q445-7m23-qrmw cdx-mixed-ecosystems.json |
0.10.66 | openssl's `MemBio::get_buf` has undefined behavior with empty buffers Fixed in 0.10.66 |
| Monitor 6.5 medium EPSS — |
nokogiri 1.11.0 GHSA-xxx9-3xcr-gjj3 cdx-mixed-ecosystems.json |
1.13.4 | XML Injection in Xerces Java affects Nokogiri Fixed in 1.13.4 |
| Monitor — medium EPSS — |
nokogiri 1.11.0 CVE-2021-47996 cdx-mixed-ecosystems.json |
1.11.4 | Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12 Fixed in 1.11.4 |
| Monitor — medium EPSS — |
nokogiri 1.11.0 CVE-2022-50998 cdx-mixed-ecosystems.json |
1.13.9 | Update bundled libxml2 to v2.10.3 to resolve multiple CVEs Fixed in 1.13.9 |
| Monitor — medium EPSS — |
nokogiri 1.11.0 CVE-2023-54354 cdx-mixed-ecosystems.json |
1.14.3 | Nokogiri updates packaged libxml2 to v2.10.4 to resolve multiple CVEs Fixed in 1.14.3 |
| Monitor — low EPSS — |
nokogiri 1.11.0 CVE-2024-58377 cdx-mixed-ecosystems.json |
1.16.5 | Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459 Fixed in 1.16.5 |
| Monitor — medium EPSS — |
nokogiri 1.11.0 CVE-2024-58378 cdx-mixed-ecosystems.json |
1.15.6 | Nokogiri update packaged libxml2 to v2.12.5 to resolve CVE-2024-25062 Fixed in 1.15.6 |
| Monitor — low EPSS — |
nokogiri 1.11.0 CVE-2025-71346 cdx-mixed-ecosystems.json |
1.18.8 | Nokogiri updates packaged libxml2 to v2.13.8 to resolve CVE-2025-32414 and CVE-2025-32415 Fixed in 1.18.8 |
| Monitor — low EPSS — |
nokogiri 1.11.0 CVE-2025-71407 cdx-mixed-ecosystems.json |
1.18.3 | Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171 Fixed in 1.18.3 |
| Monitor — medium EPSS — |
openssl 0.10.38 GHSA-3gxf-9r58-2ghg cdx-mixed-ecosystems.json |
0.10.48 | `openssl` `X509NameBuilder::build` returned object is not thread safe Fixed in 0.10.48 |
| Monitor — medium EPSS — |
openssl 0.10.38 GHSA-xphf-cx8h-7q9g cdx-mixed-ecosystems.json |
0.10.60 | `openssl` `X509StoreRef::objects` is unsound Fixed in 0.10.60 |
| No fix available 7.5 high EPSS 2.2% |
github.com/dgrijalva/jwt-go v3.2.0 CVE-2020-26160 cdx-mixed-ecosystems.json |
No published fix identified | Authorization bypass in github.com/dgrijalva/jwt-go CVSS 7.5 (high) via CVSS 3.1; No fixed version is available yet |
Appendix B
The full inventory, including components that could not be analysed. A component with no usable package URL is a blind spot, not a clean result.
| Component | Version | Ecosystem | Depth | Analysed | Findings |
|---|---|---|---|---|---|
| lodash | 4.17.15 | npm | unknown | yes | 4 |
| axios | 0.21.1 | npm | unknown | yes | 24 |
| ejs | 3.1.6 | npm | unknown | yes | 2 |
| ws | 7.4.5 | npm | unknown | yes | 3 |
| traverse | 7.20.0 | npm | unknown | yes | 1 |
| django | 3.2.0 | pypi | unknown | yes | 37 |
| pyyaml | 5.3.1 | pypi | unknown | yes | 1 |
| requests | 2.19.0 | pypi | unknown | yes | 5 |
| urllib3 | 1.25.8 | pypi | unknown | yes | 11 |
| jinja2 | 2.11.2 | pypi | unknown | yes | 5 |
| github.com/gin-gonic/gin | v1.6.3 | golang | unknown | yes | 3 |
| golang.org/x/text | v0.3.7 | golang | unknown | yes | 2 |
| github.com/dgrijalva/jwt-go | v3.2.0 | golang | unknown | yes | 1 |
| openssl | 0.10.38 | cargo | unknown | yes | 13 |
| time | 0.1.44 | cargo | unknown | yes | 1 |
| smallvec | 1.6.0 | cargo | unknown | yes | 1 |
| Newtonsoft.Json | 12.0.3 | nuget | unknown | yes | 1 |
| System.Text.Encodings.Web | 4.7.1 | nuget | unknown | yes | 1 |
| rack | 2.2.3 | gem | unknown | yes | 32 |
| nokogiri | 1.11.0 | gem | unknown | yes | 33 |
Appendix C
Declarations supplied by the inventory, not independently verified license conclusions. No license policy was applied to this review. Missing declarations and compound expressions need review, and no legal compliance is implied.
| Component | Declared license | Review status |
|---|---|---|
| lodash | MIT | Declared |
| axios | MIT | Declared |
| ejs | Apache-2.0 | Declared |
| ws | MIT | Declared |
| traverse | MIT | Declared |
| django | BSD-3-Clause | Declared |
| pyyaml | MIT | Declared |
| requests | Apache-2.0 | Declared |
| urllib3 | MIT | Declared |
| jinja2 | BSD-3-Clause | Declared |
| github.com/gin-gonic/gin | MIT | Declared |
| golang.org/x/text | BSD-3-Clause | Declared |
| github.com/dgrijalva/jwt-go | MIT | Declared |
| openssl | Apache-2.0 | Declared |
| time | MIT | Declared |
| smallvec | MIT | Declared |
| Newtonsoft.Json | MIT | Declared |
| System.Text.Encodings.Web | MIT | Declared |
| rack | MIT | Declared |
| nokogiri | MIT | Declared |
Appendix D
For this assessment: Fix-now actions (-16), Fix-soon actions (-20), No published severity.
| Source | Status | Data date | Version | Note |
|---|---|---|---|---|
| OSV.dev vulnerability database | available | 2026-09-30T21:20:10.226Z | 2026-09-30 | |
| CISA Known Exploited Vulnerabilities | available | 2026-09-30T15:24:34.225Z | 2026.09.29 | |
| FIRST EPSS exploit prediction scores | available | 2026-09-29 | 2026-09-29 | |
| Upgrade target verification | available | 2026-09-30T21:20:11.367Z | — |
Appendix E
Appendix F
For teams that file this report as evidence. Completing this block records who reviewed the findings and accepted the plan.
| Role | Name | Position | Date | Signature |
|---|---|---|---|---|
| Prepared by | ||||
| Reviewed by | ||||
| Approved by |