Confidential

Example workspaceDependency security report

Software composition assessment

example-monorepo

20 components from cdx-mixed-ecosystems.json, assessed 30 Sept 2026, 21:20 UTC

Prepared forExample workspace
Prepared withsbomtriage, report schema v1
Inventorycdx-mixed-ecosystems.json, CycloneDX JSON 1.5, made by syft 1.4.1
Assessed30 Sept 2026, 21:20 UTC
Vulnerability data as of30 Sept 2026, 21:20 UTC
Referenced022217c15f0c7a65b014e84c3283c09
ClassificationConfidential. Share with the people responsible for this software.
Integrityd1388f1800c8985c73417d82fdd1818f5ba251ab253c41319fb7ff282cb0b37bSHA-256 of this report's JSON export. Anyone holding that file can check it matches with sha256sum.

Executive summary

181 findings. 2 upgrades to make first.

Applying all 19 upgrades clears 180 of them. 1 has no fix yet.

Checked
20 of 20
components, 100% coverage
Known exploited
0
on CISA's KEV list
No fix yet
1
need a mitigation instead
Grade
C 64/100
from published thresholds

One square per finding in this assessment. 3 have a fix and a high chance of being exploited.

  • Fix now 3
  • Fix soon 85
  • Monitor 92
  • No fix 1

Recommended actions

  1. Upgrade django from 3.2.0 to 5.2.17. It clears 37 findings, including 2 in Fix now.
  2. Upgrade nokogiri from 1.11.0 to 1.19.4. It clears 33 findings, including 1 in Fix now.
  3. Schedule the remaining 17 upgrades, which clear 110 more findings (section 2).
  4. Decide how to handle the 1 finding with no fix: mitigate, replace the component, or record a risk acceptance (section 4).

What this assessment covers

Every component declared in the inventory, matched against published advisories and ranked by exploitation evidence: CISA's Known Exploited list and FIRST's EPSS scores.

What it does not

Whether vulnerable code runs in your deployment, components the inventory leaves out, and the rest of your security programme. It is not a certification.

1Scope and approach

An SBOM describes the software at the moment it was generated. This assessment matched every declared component against published advisories and ranked each finding by fixed, published rules. It did not run or inspect the software.

Components declared
20
Components checked
20 (100%, high confidence)
Package identifiers present
20 of 20
Dependency graph
Absent, so direct and transitive dependencies cannot be told apart
VEX statements
None supplied

The inventory collection time was not recorded separately, so the assessment date does not prove the inventory is current.

2Remediation plan

One action per package, ordered by exploitation first and then severity. Each target is the lowest version that clears the most findings, checked against current advisories. It was not tested for compatibility with your application, so verify the deployed result with a fresh scan. Appendix A lists every finding each upgrade clears.

Act now 2

Upgrades that clear a Fix now finding: a fix exists and the vulnerability is known exploited or likely to be.

#PackageUpgradeTierClearsExploit signal
1 django pypi 3.2.0 → 5.2.17 major Fix now 37 EPSS 73.6%
2 nokogiri gem 1.11.0 → 1.19.4 minor Fix now 33 EPSS 51.7%

Next 16

Upgrades whose most urgent finding is Fix soon: a moderate exploitation signal or high severity.

#PackageUpgradeTierClearsExploit signal
3 rack gem 2.2.3 → 2.2.23 patch Fix soon 32 EPSS 35.4%
4 Newtonsoft.Json nuget 12.0.3 → 13.0.1 major Fix soon 1 EPSS 32.9%
5 ejs npm 3.1.6 → 3.1.10 patch Fix soon 2 EPSS 32.8%
6 System.Text.Encodings.Web nuget 4.7.1 → 4.7.2 patch Fix soon 1 EPSS 30.1%
7 lodash npm 4.17.15 → 4.18.0 minor Fix soon 4 EPSS 21.3%
8 requests pypi 2.19.0 → 2.33.0 minor Fix soon 5 EPSS 7.4%
9 pyyaml pypi 5.3.1 → 5.4 minor Fix soon 1 EPSS 6.0%
10 jinja2 pypi 2.11.2 → 3.1.6 major Fix soon 5 EPSS 3.5%
11 urllib3 pypi 1.25.8 → 2.8.0 major Fix soon 11 EPSS 3.3%
12 ws npm 7.4.5 → 7.5.11 minor Fix soon 3 EPSS 2.8%
13 smallvec cargo 1.6.0 → 1.6.1 patch Fix soon 1 EPSS 1.7%
14 golang.org/x/text golang v0.3.7 → v0.39.0 minor Fix soon 2 EPSS 1.5%
15 github.com/gin-gonic/gin golang v1.6.3 → v1.9.1 minor Fix soon 3 EPSS 1.3%
16 @babel/traverse npm 7.20.0 → 7.23.2 minor Fix soon 1 EPSS 0.5%
18 axios npm 0.21.1 → 1.20.0 major Fix soon 24 EPSS 8.5%
19 openssl cargo 0.10.38 → 0.10.80 patch Fix soon 13 EPSS 0.7%

Later 1

Upgrades with no sign of urgency. Worth doing with routine dependency updates.

#PackageUpgradeTierClearsExploit signal
17 time cargo 0.1.44 → 0.2.23 minor Monitor 1 EPSS 1.6%

3Changes and decisions

Baseline assessment. A second saved scan is needed to show what changed.

Recorded decisions

0 upgrades were marked done, and 0 findings were ruled out by the account or by VEX. Marking an upgrade done is a declaration, not verified remediation.

4Findings without a fix

No published version resolves these. Each needs a mitigation, a compensating control, a replacement component, or a recorded risk decision.

PriorityComponent and advisoryFixed inEvidence
No fix available
7.5 high
EPSS 2.2%
github.com/dgrijalva/jwt-go
v3.2.0
CVE-2020-26160
cdx-mixed-ecosystems.json
No published fix identified Authorization bypass in github.com/dgrijalva/jwt-go
CVSS 7.5 (high) via CVSS 3.1; No fixed version is available yet

5Regulatory context: the EU Cyber Resilience Act

Annex I, Part II of Regulation (EU) 2024/2847 asks manufacturers to document the components in their products and handle vulnerabilities without delay. This table maps what this assessment evidences. It is a readiness view, not a conformity assessment, and nothing here makes a product compliant or certified.

What Annex I, Part II asks forStatusWhat this assessment shows
Identify and document the components contained in the productEvidenced20 components documented from CycloneDX JSON.
A software bill of materials in a commonly used, machine-readable formatEvidencedCycloneDX JSON, with 100% of components carrying a package identifier and version.
Identify vulnerabilities in those componentsEvidenced181 findings, 0 of them on CISA's Known Exploited Vulnerabilities list.
A KEV listing is an early signal that Article 14 reporting may apply. Whether a flaw is actively exploited in the product is a separate assessment.
Address and remediate vulnerabilities without delayPartly evidenced19 upgrades recommended, clearing 180 findings.
1 have no available fix and need a mitigation or a documented risk decision.
Secure design, security updates and the rest of Annex INot coveredOutside what a dependency assessment can show.

Appendix A

Every finding (181)

PriorityComponent and advisoryFixed inEvidence
Fix now
9.8 critical
EPSS 73.6%
django
3.2.0
CVE-2022-34265
cdx-mixed-ecosystems.json
3.2.14 Django `Trunc()` and `Extract()` database functions vulnerable to SQL Injection
EPSS 73.6%: high probability of exploitation in the next 30 days; CVSS 9.8 (critical) via CVSS 3.1; Fixed in 3.2.14
Fix now
7.5 high
EPSS 62.6%
django
3.2.0
CVE-2023-24580
cdx-mixed-ecosystems.json
3.2.18 Resource exhaustion in Django
EPSS 62.6%: high probability of exploitation in the next 30 days; CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.18
Fix now
7.5 high
EPSS 51.7%
nokogiri
1.11.0
CVE-2018-25032
cdx-mixed-ecosystems.json
1.13.4 Nokogiri affected by zlib's Out-of-bounds Write vulnerability
EPSS 51.7%: high probability of exploitation in the next 30 days; CVSS 7.5 (high) via CVSS 3.1; Fixed in 1.13.4
Fix soon
7.5 high
EPSS 49.8%
django
3.2.0
CVE-2023-46695
cdx-mixed-ecosystems.json
3.2.23 Django potential denial of service vulnerability in UsernameField on Windows
EPSS 49.8%: moderate probability of exploitation; CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.23
Fix soon
7.5 high
EPSS 49.5%
django
3.2.0
CVE-2022-23833
cdx-mixed-ecosystems.json
3.2.12 Infinite Loop in Django
EPSS 49.5%: moderate probability of exploitation; CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.12
Fix soon
7.5 high
EPSS 47.4%
django
3.2.0
CVE-2023-23969
cdx-mixed-ecosystems.json
3.2.17 Django contains Uncontrolled Resource Consumption via cached header
EPSS 47.4%: moderate probability of exploitation; CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.17
Fix soon
9.8 critical
EPSS 44.4%
django
3.2.0
CVE-2021-35042
cdx-mixed-ecosystems.json
3.2.5 SQL Injection in Django
EPSS 44.4%: moderate probability of exploitation; CVSS 9.8 (critical) via CVSS 3.1; Fixed in 3.2.5
Fix soon
5.3 medium
EPSS 35.4%
rack
2.2.3
CVE-2024-25126
cdx-mixed-ecosystems.json
2.2.8.1 Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)
EPSS 35.4%: moderate probability of exploitation; Fixed in 2.2.8.1
Fix soon
7.5 high
EPSS 32.9%
Newtonsoft.Json
12.0.3
CVE-2024-21907
cdx-mixed-ecosystems.json
13.0.1 Improper Handling of Exceptional Conditions in Newtonsoft.Json
EPSS 32.9%: moderate probability of exploitation; CVSS 7.5 (high) via CVSS 3.1; Fixed in 13.0.1
Fix soon
9.8 critical
EPSS 32.8%
ejs
3.1.6
CVE-2022-29078
cdx-mixed-ecosystems.json
3.1.7 ejs template injection vulnerability
EPSS 32.8%: moderate probability of exploitation; CVSS 9.8 (critical) via CVSS 3.1; Fixed in 3.1.7
Fix soon
9.8 critical
EPSS 30.1%
System.Text.Encodings.Web
4.7.1
CVE-2021-26701
cdx-mixed-ecosystems.json
4.7.2 .NET Core Remote Code Execution Vulnerability
EPSS 30.1%: moderate probability of exploitation; CVSS 9.8 (critical) via CVSS 3.1; Fixed in 4.7.2
Fix soon
8.8 high
EPSS 21.9%
nokogiri
1.11.0
CVE-2021-3518
cdx-mixed-ecosystems.json
1.11.4 Nokogiri Implements libxml2 version vulnerable to use-after-free
EPSS 21.9%: moderate probability of exploitation; CVSS 8.8 (high) via CVSS 3.1; Fixed in 1.11.4
Fix soon
8.1 high
EPSS 21.3%
lodash
4.17.15
CVE-2021-23337
cdx-mixed-ecosystems.json
4.17.21 Command Injection in lodash
EPSS 21.3%: moderate probability of exploitation; CVSS 8.1 (high) via CVSS 3.1; Fixed in 4.17.21
Fix soon
9.1 critical
EPSS 19.4%
django
3.2.0
CVE-2025-64459
cdx-mixed-ecosystems.json
4.2.26 Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
EPSS 19.4%: moderate probability of exploitation; CVSS 9.1 (critical) via CVSS 3.1; Fixed in 4.2.26
Fix soon
9.8 critical
EPSS 18.7%
django
3.2.0
CVE-2022-28346
cdx-mixed-ecosystems.json
3.2.13 SQL Injection in Django
EPSS 18.7%: moderate probability of exploitation; CVSS 9.8 (critical) via CVSS 3.1; Fixed in 3.2.13
Fix soon
8.8 high
EPSS 17.6%
nokogiri
1.11.0
CVE-2021-30560
cdx-mixed-ecosystems.json
1.13.2 Nokogiri has vulnerable dependencies on libxml2 and libxslt
EPSS 17.6%: moderate probability of exploitation; CVSS 8.8 (high) via CVSS 3.1; Fixed in 1.13.2
Fix soon
8.6 high
EPSS 17.0%
nokogiri
1.11.0
CVE-2021-3517
cdx-mixed-ecosystems.json
1.11.4 Nokogiri contains libxml Out-of-bounds Write vulnerability
EPSS 17.0%: moderate probability of exploitation; CVSS 8.6 (high) via CVSS 3.1; Fixed in 1.11.4
Fix soon
7.1 high
EPSS 16.8%
django
3.2.0
CVE-2025-57833
cdx-mixed-ecosystems.json
4.2.24 Django is subject to SQL injection through its column aliases
EPSS 16.8%: moderate probability of exploitation; CVSS 7.1 (high) via CVSS 3.1; Fixed in 4.2.24
Fix soon
7.5 high
EPSS 8.5%
axios
0.21.1
CVE-2021-3749
cdx-mixed-ecosystems.json
0.21.2 axios Inefficient Regular Expression Complexity vulnerability
CVSS 7.5 (high) via CVSS 3.1; Fixed in 0.21.2
Fix soon
7.5 high
EPSS 7.4%
requests
2.19.0
CVE-2018-18074
cdx-mixed-ecosystems.json
2.20.0 Insufficiently Protected Credentials in Requests
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.20.0
Fix soon
9.8 critical
EPSS 6.0%
pyyaml
5.3.1
CVE-2020-14343
cdx-mixed-ecosystems.json
5.4 Improper Input Validation in PyYAML
CVSS 9.8 (critical) via CVSS 3.1; Fixed in 5.4
Fix soon
7.5 high
EPSS 5.3%
django
3.2.0
CVE-2021-31542
cdx-mixed-ecosystems.json
3.2.1 Path Traversal in Django
CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.1
Fix soon
7.5 high
EPSS 5.3%
django
3.2.0
CVE-2021-33571
cdx-mixed-ecosystems.json
3.2.4 Django Access Control Bypass possibly leading to SSRF, RFI, and LFI attacks
CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.4
Fix soon
7.4 high
EPSS 5.2%
lodash
4.17.15
CVE-2020-8203
cdx-mixed-ecosystems.json
4.17.19 Prototype Pollution in lodash
CVSS 7.4 (high) via CVSS 3.1; Fixed in 4.17.19
Fix soon
7.5 high
EPSS 3.5%
nokogiri
1.11.0
CVE-2022-24836
cdx-mixed-ecosystems.json
1.13.4 Nokogiri Inefficient Regular Expression Complexity
CVSS 7.5 (high) via CVSS 3.1; Fixed in 1.13.4
Fix soon
7.5 high
EPSS 3.3%
urllib3
1.25.8
CVE-2021-33503
cdx-mixed-ecosystems.json
1.26.5 Catastrophic backtracking in URL authority parser when passed URL containing many @ characters
CVSS 7.5 (high) via CVSS 3.1; Fixed in 1.26.5
Fix soon
8.2 high
EPSS 3.2%
nokogiri
1.11.0
CVE-2022-29181
cdx-mixed-ecosystems.json
1.13.6 Nokogiri Improperly Handles Unexpected Data Type
CVSS 8.2 (high) via CVSS 3.1; Fixed in 1.13.6
Fix soon
7.5 high
EPSS 3.0%
django
3.2.0
CVE-2022-41323
cdx-mixed-ecosystems.json
3.2.16 Django denial-of-service vulnerability in internationalized URLs
CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.16
Fix soon
7.5 high
EPSS 3.0%
django
3.2.0
CVE-2023-36053
cdx-mixed-ecosystems.json
3.2.20 Django has regular expression denial of service vulnerability in EmailValidator/URLValidator
CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.20
Fix soon
7.5 high
EPSS 3.0%
urllib3
1.25.8
CVE-2026-21441
cdx-mixed-ecosystems.json
2.6.3 Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.6.3
Fix soon
9.8 critical
EPSS 2.9%
django
3.2.0
CVE-2022-28347
cdx-mixed-ecosystems.json
3.2.13 SQL Injection in Django
CVSS 9.8 (critical) via CVSS 3.1; Fixed in 3.2.13
Fix soon
7.5 high
EPSS 2.4%
django
3.2.0
CVE-2021-45115
cdx-mixed-ecosystems.json
3.2.11 Denial-of-service in Django
CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.11
Fix soon
7.3 high
EPSS 2.3%
django
3.2.0
CVE-2021-44420
cdx-mixed-ecosystems.json
3.2.10 Potential bypass of an upstream access control based on URL paths in Django
CVSS 7.3 (high) via CVSS 3.1; Fixed in 3.2.10
Fix soon
7.5 high
EPSS 2.1%
rack
2.2.3
CVE-2022-30122
cdx-mixed-ecosystems.json
2.2.3.1 Denial of Service Vulnerability in Rack Multipart Parsing
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.3.1
Fix soon
7.5 high
EPSS 1.9%
django
3.2.0
CVE-2025-64458
cdx-mixed-ecosystems.json
4.2.26 Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVSS 7.5 (high) via CVSS 3.1; Fixed in 4.2.26
Fix soon
10.0 critical
EPSS 1.9%
rack
2.2.3
CVE-2022-30123
cdx-mixed-ecosystems.json
2.2.3.1 Possible shell escape sequence injection vulnerability in Rack
CVSS 10.0 (critical) via CVSS 3.1; Fixed in 2.2.3.1
Fix soon
7.5 high
EPSS 1.9%
django
3.2.0
CVE-2021-45116
cdx-mixed-ecosystems.json
3.2.11 Information disclosure in Django
CVSS 7.5 (high) via CVSS 3.1; Fixed in 3.2.11
Fix soon
7.5 high
EPSS 1.8%
rack
2.2.3
CVE-2023-27530
cdx-mixed-ecosystems.json
2.2.6.3 Rack has possible DoS Vulnerability in Multipart MIME parsing
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.6.3
Fix soon
7.5 high
EPSS 1.8%
axios
0.21.1
CVE-2026-25639
cdx-mixed-ecosystems.json
0.30.3 Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
CVSS 7.5 (high) via CVSS 3.1; Fixed in 0.30.3
Fix soon
9.8 critical
EPSS 1.7%
smallvec
1.6.0
CVE-2021-25900
cdx-mixed-ecosystems.json
1.6.1 Buffer overflow in SmallVec::insert_many
CVSS 9.8 (critical) via CVSS 3.1; Fixed in 1.6.1
Fix soon
7.5 high
EPSS 1.6%
rack
2.2.3
CVE-2022-44570
cdx-mixed-ecosystems.json
2.2.6.2 Denial of service via header parsing in Rack
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.6.2
Fix soon
7.5 high
EPSS 1.5%
golang.org/x/text
v0.3.7
CVE-2022-32149
cdx-mixed-ecosystems.json
0.3.8 golang.org/x/text/language Denial of service via crafted Accept-Language header
CVSS 7.5 (high) via CVSS 3.1; Fixed in 0.3.8
Fix soon
7.5 high
EPSS 1.5%
nokogiri
1.11.0
CVE-2021-41098
cdx-mixed-ecosystems.json
1.12.5 Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby
CVSS 7.5 (high) via CVSS 3.0; Fixed in 1.12.5
Fix soon
9.8 critical
EPSS 1.4%
django
3.2.0
CVE-2023-31047
cdx-mixed-ecosystems.json
3.2.19 Django bypasses validation when using one form field to upload multiple files
CVSS 9.8 (critical) via CVSS 3.1; Fixed in 3.2.19
Fix soon
7.5 high
EPSS 1.3%
ws
7.4.5
CVE-2024-37890
cdx-mixed-ecosystems.json
7.5.10 ws affected by a DoS when handling a request with many HTTP headers
CVSS 7.5 (high) via CVSS 3.1; Fixed in 7.5.10
Fix soon
7.1 high
EPSS 1.3%
github.com/gin-gonic/gin
v1.6.3
CVE-2020-28483
cdx-mixed-ecosystems.json
1.7.7 Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
CVSS 7.1 (high) via CVSS 3.1; Fixed in 1.7.7
Fix soon
8.1 high
EPSS 1.2%
urllib3
1.25.8
CVE-2023-43804
cdx-mixed-ecosystems.json
1.26.17 `Cookie` HTTP header isn't stripped on cross-origin redirects
CVSS 8.1 (high) via CVSS 3.1; Fixed in 1.26.17
Fix soon
7.5 high
EPSS 1.2%
rack
2.2.3
CVE-2025-46727
cdx-mixed-ecosystems.json
2.2.14 Rack has an Unbounded-Parameter DoS in Rack::QueryParser
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.14
Fix soon
7.5 high
EPSS 1.1%
rack
2.2.3
CVE-2025-27610
cdx-mixed-ecosystems.json
2.2.13 Local File Inclusion in Rack::Static
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.13
Fix soon
7.0 high
EPSS 1.0%
axios
0.21.1
CVE-2026-44495
cdx-mixed-ecosystems.json
0.31.1 axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
CVSS 7.0 (high) via CVSS 3.1; Fixed in 0.31.1
Fix soon
7.5 high
EPSS 1.0%
axios
0.21.1
CVE-2026-42039
cdx-mixed-ecosystems.json
0.31.1 Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
CVSS 7.5 (high) via CVSS 3.1; Fixed in 0.31.1
Fix soon
7.5 high
EPSS 1.0%
axios
0.21.1
CVE-2026-44496
cdx-mixed-ecosystems.json
0.32.0 Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
CVSS 7.5 (high) via CVSS 3.1; Fixed in 0.32.0
Fix soon
7.5 high
EPSS 0.9%
ws
7.4.5
CVE-2026-48779
cdx-mixed-ecosystems.json
7.5.11 ws: Memory exhaustion DoS from tiny fragments and data chunks
CVSS 7.5 (high) via CVSS 3.1; Fixed in 7.5.11
Fix soon
7.5 high
EPSS 0.9%
rack
2.2.3
CVE-2025-61770
cdx-mixed-ecosystems.json
2.2.19 Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.19
Fix soon
7.5 high
EPSS 0.9%
rack
2.2.3
CVE-2025-61772
cdx-mixed-ecosystems.json
2.2.19 Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.19
Fix soon
7.4 high
EPSS 0.9%
axios
0.21.1
CVE-2026-42033
cdx-mixed-ecosystems.json
0.31.1 Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
CVSS 7.4 (high) via CVSS 3.1; Fixed in 0.31.1
Fix soon
8.8 high
EPSS 0.9%
django
3.2.0
CVE-2022-36359
cdx-mixed-ecosystems.json
3.2.15 Django vulnerable to Reflected File Download attack
CVSS 8.8 (high) via CVSS 3.1; Fixed in 3.2.15
Fix soon
8.6 high
EPSS 0.8%
axios
0.21.1
CVE-2026-44492
cdx-mixed-ecosystems.json
0.32.0 axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
CVSS 8.6 (high) via CVSS 3.1; Fixed in 0.32.0
Fix soon
— high
EPSS 0.8%
axios
0.21.1
CVE-2025-27152
cdx-mixed-ecosystems.json
0.30.0 axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
Published severity: high; numeric CVSS score unavailable; Fixed in 0.30.0
Fix soon
7.5 high
EPSS 0.8%
axios
0.21.1
CVE-2026-44486
cdx-mixed-ecosystems.json
0.32.0 Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
CVSS 7.5 (high) via CVSS 3.1; Fixed in 0.32.0
Fix soon
— high
EPSS 0.8%
axios
0.21.1
CVE-2026-44487
cdx-mixed-ecosystems.json
0.32.0 Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
Published severity: high; numeric CVSS score unavailable; Fixed in 0.32.0
Fix soon
— high
EPSS 0.7%
urllib3
1.25.8
CVE-2025-66418
cdx-mixed-ecosystems.json
2.6.0 urllib3 allows an unbounded number of links in the decompression chain
Published severity: high; numeric CVSS score unavailable; Fixed in 2.6.0
Fix soon
— high
EPSS 0.7%
urllib3
1.25.8
CVE-2025-66471
cdx-mixed-ecosystems.json
2.6.0 urllib3 streaming API improperly handles highly compressed data
Published severity: high; numeric CVSS score unavailable; Fixed in 2.6.0
Fix soon
7.5 high
EPSS 0.7%
rack
2.2.3
CVE-2026-22860
cdx-mixed-ecosystems.json
2.2.22 Rack has a Directory Traversal via Rack:Directory
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.22
Fix soon
7.5 high
EPSS 0.7%
rack
2.2.3
CVE-2026-34829
cdx-mixed-ecosystems.json
2.2.23 Rack's multipart parsing without Content-Length header allows unbounded chunked file uploads
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.23
Fix soon
7.5 high
EPSS 0.6%
rack
2.2.3
CVE-2025-61919
cdx-mixed-ecosystems.json
2.2.20 Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.20
Fix soon
7.2 high
EPSS 0.6%
axios
0.21.1
CVE-2026-42043
cdx-mixed-ecosystems.json
0.31.1 Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
CVSS 7.2 (high) via CVSS 3.1; Fixed in 0.31.1
Fix soon
7.5 high
EPSS 0.6%
rack
2.2.3
CVE-2025-59830
cdx-mixed-ecosystems.json
2.2.18 Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.18
Fix soon
7.5 high
EPSS 0.6%
rack
2.2.3
CVE-2025-61771
cdx-mixed-ecosystems.json
2.2.19 Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.19
Fix soon
7.8 high
EPSS 0.5%
jinja2
2.11.2
CVE-2024-56326
cdx-mixed-ecosystems.json
3.1.5 Jinja has a sandbox breakout through indirect reference to format method
CVSS 7.8 (high) via CVSS 3.1; Fixed in 3.1.5
Fix soon
9.3 critical
EPSS 0.5%
traverse
7.20.0
CVE-2023-45133
cdx-mixed-ecosystems.json
7.23.2 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
CVSS 9.3 (critical) via CVSS 3.1; Fixed in 7.23.2
Fix soon
7.5 high
EPSS 0.5%
rack
2.2.3
CVE-2026-34785
cdx-mixed-ecosystems.json
2.2.23 Rack::Static prefix matching can expose unintended files under the static root
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.23
Fix soon
7.5 high
EPSS 0.5%
nokogiri
1.11.0
CVE-2026-79770
cdx-mixed-ecosystems.json
1.19.3 Nokogiri CSS selector tokenizer has regular expression backtracking
CVSS 7.5 (high) via CVSS 3.1; Fixed in 1.19.3
Fix soon
7.5 high
EPSS 0.5%
rack
2.2.3
CVE-2026-34230
cdx-mixed-ecosystems.json
2.2.23 Rack has quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
CVSS 7.5 (high) via CVSS 3.1; Fixed in 2.2.23
Fix soon
7.4 high
EPSS 0.4%
axios
0.21.1
CVE-2026-42035
cdx-mixed-ecosystems.json
0.31.1 Axios: Header Injection via Prototype Pollution
CVSS 7.4 (high) via CVSS 3.1; Fixed in 0.31.1
Fix soon
— high
EPSS 0.3%
openssl
0.10.38
CVE-2026-41676
cdx-mixed-ecosystems.json
0.10.78 rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
Published severity: high; numeric CVSS score unavailable; Fixed in 0.10.78
Fix soon
— high
EPSS 0.3%
openssl
0.10.38
CVE-2026-41898
cdx-mixed-ecosystems.json
0.10.78 rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
Published severity: high; numeric CVSS score unavailable; Fixed in 0.10.78
Fix soon
— high
EPSS 0.3%
openssl
0.10.38
CVE-2026-41678
cdx-mixed-ecosystems.json
0.10.78 rust-openssl has incorrect bounds assertion in aes key wrap
Published severity: high; numeric CVSS score unavailable; Fixed in 0.10.78
Fix soon
— high
EPSS 0.2%
openssl
0.10.38
CVE-2026-42327
cdx-mixed-ecosystems.json
0.10.79 rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
Published severity: high; numeric CVSS score unavailable; Fixed in 0.10.79
Fix soon
8.6 high
EPSS —
nokogiri
1.11.0
CVE-2022-50999
cdx-mixed-ecosystems.json
1.13.5 Integer Overflow or Wraparound in libxml2 affects Nokogiri
CVSS 8.6 (high) via CVSS 3.1; Fixed in 1.13.5
Fix soon
7.8 high
EPSS —
nokogiri
1.11.0
CVE-2025-71406
cdx-mixed-ecosystems.json
1.18.4 Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
CVSS 7.8 (high) via CVSS 3.1; Fixed in 1.18.4
Fix soon
7.5 high
EPSS —
nokogiri
1.11.0
GHSA-gx8x-g87m-h5q6
cdx-mixed-ecosystems.json
1.13.4 Denial of Service (DoS) in Nokogiri on JRuby
CVSS 7.5 (high) via CVSS 3.1; Fixed in 1.13.4
Fix soon
7.5 high
EPSS —
nokogiri
1.11.0
GHSA-v6gp-9mmm-c6p5
cdx-mixed-ecosystems.json
1.13.4 Out-of-bounds Write in zlib affects Nokogiri
CVSS 7.5 (high) via CVSS 3.1; Fixed in 1.13.4
Fix soon
— high
EPSS —
nokogiri
1.11.0
CVE-2022-51000
cdx-mixed-ecosystems.json
1.13.2 Vulnerable dependencies in Nokogiri
Published severity: high; numeric CVSS score unavailable; Fixed in 1.13.2
Fix soon
— high
EPSS —
urllib3
1.25.8
CVE-2026-97689
cdx-mixed-ecosystems.json
2.8.0 urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
Published severity: high; numeric CVSS score unavailable; Fixed in 2.8.0
Fix soon
— critical
EPSS —
nokogiri
1.11.0
GHSA-353f-x4gh-cqq8
cdx-mixed-ecosystems.json
1.18.9 Nokogiri patches vendored libxml2 to resolve multiple CVEs
Published severity: critical; numeric CVSS score unavailable; Fixed in 1.18.9
Fix soon
— high
EPSS —
openssl
0.10.38
GHSA-6hcf-g6gr-hhcr
cdx-mixed-ecosystems.json
0.10.48 `openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference
Published severity: high; numeric CVSS score unavailable; Fixed in 0.10.48
Fix soon
— high
EPSS —
openssl
0.10.38
GHSA-9qwg-crg9-m2vc
cdx-mixed-ecosystems.json
0.10.48 `openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read
Published severity: high; numeric CVSS score unavailable; Fixed in 0.10.48
Monitor
5.3 medium
EPSS 7.3%
lodash
4.17.15
CVE-2020-28500
cdx-mixed-ecosystems.json
4.17.21 Regular Expression Denial of Service (ReDoS) in lodash
Fixed in 4.17.21
Monitor
5.3 medium
EPSS 3.5%
jinja2
2.11.2
CVE-2020-28493
cdx-mixed-ecosystems.json
2.11.3 Regular Expression Denial of Service (ReDoS) in Jinja2
Fixed in 2.11.3
Monitor
5.9 medium
EPSS 3.5%
nokogiri
1.11.0
CVE-2021-3537
cdx-mixed-ecosystems.json
1.11.4 Nokogiri Implements libxml2 version vulnerable to null pointer dereferencing
Fixed in 1.11.4
Monitor
6.1 medium
EPSS 3.4%
django
3.2.0
CVE-2022-22818
cdx-mixed-ecosystems.json
3.2.12 Cross-site Scripting in Django
Fixed in 3.2.12
Monitor
6.1 medium
EPSS 3.2%
django
3.2.0
CVE-2021-32052
cdx-mixed-ecosystems.json
3.2.2 Header injection possible in Django
Fixed in 3.2.2
Monitor
6.1 medium
EPSS 3.0%
requests
2.19.0
CVE-2023-32681
cdx-mixed-ecosystems.json
2.31.0 Unintended leak of Proxy-Authorization header in requests
Fixed in 2.31.0
Monitor
5.3 medium
EPSS 2.8%
ws
7.4.5
CVE-2021-32640
cdx-mixed-ecosystems.json
7.4.6 ReDoS in Sec-Websocket-Protocol header
Fixed in 7.4.6
Monitor
4.9 medium
EPSS 2.7%
django
3.2.0
CVE-2021-33203
cdx-mixed-ecosystems.json
3.2.4 Path Traversal in Django
Fixed in 3.2.4
Monitor
5.3 medium
EPSS 2.4%
django
3.2.0
CVE-2021-45452
cdx-mixed-ecosystems.json
3.2.11 Directory-traversal in Django
Fixed in 3.2.11
Monitor
6.5 medium
EPSS 2.3%
urllib3
1.25.8
CVE-2020-26137
cdx-mixed-ecosystems.json
1.25.9 CRLF injection in urllib3
Fixed in 1.25.9
Monitor
— low
EPSS 2.0%
rack
2.2.3
CVE-2024-26146
cdx-mixed-ecosystems.json
2.2.8.1 Rack Header Parsing leads to Possible Denial of Service Vulnerability
Fixed in 2.2.8.1
Monitor
5.3 medium
EPSS 1.9%
django
3.2.0
CVE-2024-27351
cdx-mixed-ecosystems.json
3.2.25 Regular expression denial-of-service in Django
Fixed in 3.2.25
Monitor
6.5 medium
EPSS 1.8%
lodash
4.17.15
CVE-2025-13465
cdx-mixed-ecosystems.json
4.17.23 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
Fixed in 4.17.23
Monitor
6.2 medium
EPSS 1.6%
time
0.1.44
CVE-2020-26235
cdx-mixed-ecosystems.json
0.2.0 Segmentation fault in time
Fixed in 0.2.0
Monitor
— low
EPSS 1.6%
rack
2.2.3
CVE-2022-44572
cdx-mixed-ecosystems.json
2.2.6.1 Denial of service via multipart parsing in Rack
Fixed in 2.2.6.1
Monitor
— low
EPSS 1.6%
rack
2.2.3
CVE-2024-26141
cdx-mixed-ecosystems.json
2.2.8.1 Rack has possible DoS Vulnerability with Range Header
Fixed in 2.2.8.1
Monitor
5.9 medium
EPSS 1.6%
django
3.2.0
CVE-2024-24680
cdx-mixed-ecosystems.json
3.2.24 Django denial-of-service attack in the intcomma template filter
Fixed in 3.2.24
Monitor
5.3 medium
EPSS 1.5%
django
3.2.0
CVE-2023-41164
cdx-mixed-ecosystems.json
3.2.21 Django Denial of service vulnerability in django.utils.encoding.uri_to_iri
Fixed in 3.2.21
Monitor
— low
EPSS 1.5%
rack
2.2.3
CVE-2022-44571
cdx-mixed-ecosystems.json
2.2.6.1 Denial of Service Vulnerability in Rack Content-Disposition parsing
Fixed in 2.2.6.1
Monitor
4.8 medium
EPSS 1.3%
axios
0.21.1
CVE-2026-40175
cdx-mixed-ecosystems.json
0.31.0 Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
Fixed in 0.31.0
Monitor
5.9 medium
EPSS 1.2%
django
3.2.0
CVE-2023-43665
cdx-mixed-ecosystems.json
3.2.22 Django Denial-of-service in django.utils.text.Truncator
Fixed in 3.2.22
Monitor
4.8 medium
EPSS 1.2%
axios
0.21.1
CVE-2025-62718
cdx-mixed-ecosystems.json
0.31.0 Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
Fixed in 0.31.0
Monitor
6.5 medium
EPSS 1.2%
rack
2.2.3
CVE-2025-25184
cdx-mixed-ecosystems.json
2.2.11 Possible Log Injection in Rack::CommonLogger
Fixed in 2.2.11
Monitor
4.4 medium
EPSS 1.1%
urllib3
1.25.8
CVE-2024-37891
cdx-mixed-ecosystems.json
1.26.19 urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
Fixed in 1.26.19
Monitor
— low
EPSS 1.1%
rack
2.2.3
CVE-2023-27539
cdx-mixed-ecosystems.json
2.2.6.4 Possible Denial of Service Vulnerability in Rack's header parsing
Fixed in 2.2.6.4
Monitor
5.3 medium
EPSS 1.0%
requests
2.19.0
CVE-2024-47081
cdx-mixed-ecosystems.json
2.32.4 Requests vulnerable to .netrc credentials leak via malicious URLs
Fixed in 2.32.4
Monitor
5.4 medium
EPSS 1.0%
jinja2
2.11.2
CVE-2024-34064
cdx-mixed-ecosystems.json
3.1.4 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Fixed in 3.1.4
Monitor
5.6 medium
EPSS 0.9%
github.com/gin-gonic/gin
v1.6.3
CVE-2023-26125
cdx-mixed-ecosystems.json
1.9.0 Improper input validation in github.com/gin-gonic/gin
Fixed in 1.9.0
Monitor
5.4 medium
EPSS 0.9%
jinja2
2.11.2
CVE-2024-22195
cdx-mixed-ecosystems.json
3.1.3 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Fixed in 3.1.3
Monitor
4.8 medium
EPSS 0.8%
axios
0.21.1
CVE-2026-42041
cdx-mixed-ecosystems.json
0.31.1 Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Fixed in 0.31.1
Monitor
3.7 low
EPSS 0.8%
django
3.2.0
CVE-2024-45231
cdx-mixed-ecosystems.json
4.2.16 Django allows enumeration of user e-mail addresses
Fixed in 4.2.16
Monitor
5.3 medium
EPSS 0.8%
django
3.2.0
CVE-2026-15830
cdx-mixed-ecosystems.json
5.2.17 Django GeoDjango vulnerable to denial of service through deeply nested geometry collections
Fixed in 5.2.17
Monitor
— medium
EPSS 0.8%
rack
2.2.3
CVE-2025-27111
cdx-mixed-ecosystems.json
2.2.12 Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
Fixed in 2.2.12
Monitor
4.0 medium
EPSS 0.8%
django
3.2.0
CVE-2025-48432
cdx-mixed-ecosystems.json
4.2.22 Django Improper Output Neutralization for Logs vulnerability
Fixed in 4.2.22
Monitor
— medium
EPSS 0.7%
openssl
0.10.38
CVE-2025-24898
cdx-mixed-ecosystems.json
0.10.70 rust-openssl ssl::select_next_proto use after free
Fixed in 0.10.70
Monitor
4.0 medium
EPSS 0.6%
ejs
3.1.6
CVE-2024-33883
cdx-mixed-ecosystems.json
3.1.10 ejs lacks certain pollution protection
Fixed in 3.1.10
Monitor
6.5 medium
EPSS 0.6%
axios
0.21.1
CVE-2023-45857
cdx-mixed-ecosystems.json
0.28.0 Axios Cross-Site Request Forgery Vulnerability
Fixed in 0.28.0
Monitor
5.8 medium
EPSS 0.6%
rack
2.2.3
CVE-2025-61780
cdx-mixed-ecosystems.json
2.2.20 Rack has a Possible Information Disclosure Vulnerability
Fixed in 2.2.20
Monitor
4.2 medium
EPSS 0.5%
urllib3
1.25.8
CVE-2023-45803
cdx-mixed-ecosystems.json
1.26.18 urllib3's request body not stripped after redirect from 303 status changes request method to GET
Fixed in 1.26.18
Monitor
— medium
EPSS 0.5%
jinja2
2.11.2
CVE-2025-27516
cdx-mixed-ecosystems.json
3.1.6 Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Fixed in 3.1.6
Monitor
4.3 medium
EPSS 0.5%
github.com/gin-gonic/gin
v1.6.3
CVE-2023-29401
cdx-mixed-ecosystems.json
1.9.1 Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function
Fixed in 1.9.1
Monitor
5.3 medium
EPSS 0.5%
axios
0.21.1
CVE-2026-42034
cdx-mixed-ecosystems.json
0.31.1 Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
Fixed in 0.31.1
Monitor
5.3 medium
EPSS 0.5%
axios
0.21.1
CVE-2026-42036
cdx-mixed-ecosystems.json
0.31.1 Axios: HTTP adapter streamed responses bypass maxContentLength
Fixed in 0.31.1
Monitor
— unknown
EPSS 0.5%
golang.org/x/text
v0.3.7
CVE-2026-56852
cdx-mixed-ecosystems.json
0.39.0 Infinite loop on invalid input in golang.org/x/text
No severity score published for this advisory; Fixed in 0.39.0
Monitor
5.3 medium
EPSS 0.5%
urllib3
1.25.8
CVE-2025-50181
cdx-mixed-ecosystems.json
2.5.0 urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
Fixed in 2.5.0
Monitor
5.3 medium
EPSS 0.5%
rack
2.2.3
CVE-2026-34826
cdx-mixed-ecosystems.json
2.2.23 Rack's multipart byte range processing allows denial of service via excessive overlapping ranges
Fixed in 2.2.23
Monitor
— low
EPSS 0.5%
nokogiri
1.11.0
CVE-2026-57434
cdx-mixed-ecosystems.json
1.19.4 Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
Fixed in 1.19.4
Monitor
— low
EPSS 0.5%
nokogiri
1.11.0
CVE-2026-57435
cdx-mixed-ecosystems.json
1.19.4 Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
Fixed in 1.19.4
Monitor
4.8 medium
EPSS 0.4%
django
3.2.0
CVE-2026-53877
cdx-mixed-ecosystems.json
5.2.16 Django: GDALRaster may over-read heap memory when constructed from bytes
Fixed in 5.2.16
Monitor
3.1 low
EPSS 0.4%
django
3.2.0
CVE-2026-48587
cdx-mixed-ecosystems.json
5.2.15 Django: has_vary_header may expose cached responses when Vary values contain whitespace
Fixed in 5.2.15
Monitor
3.1 low
EPSS 0.4%
django
3.2.0
CVE-2026-48588
cdx-mixed-ecosystems.json
5.2.16 Django: cache middleware may expose private responses when unrelated request cookies are present
Fixed in 5.2.16
Monitor
3.1 low
EPSS 0.4%
django
3.2.0
CVE-2026-8404
cdx-mixed-ecosystems.json
5.2.15 Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
Fixed in 5.2.15
Monitor
— medium
EPSS 0.4%
nokogiri
1.11.0
CVE-2026-57235
cdx-mixed-ecosystems.json
1.19.4 Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
Fixed in 1.19.4
Monitor
— low
EPSS 0.4%
nokogiri
1.11.0
CVE-2026-57236
cdx-mixed-ecosystems.json
1.19.4 Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception
Fixed in 1.19.4
Monitor
— medium
EPSS 0.4%
axios
0.21.1
CVE-2026-67316
cdx-mixed-ecosystems.json
0.33.0 Axios: Prototype pollution gadgets can alter axios request construction
Fixed in 0.33.0
Monitor
5.3 medium
EPSS 0.4%
nokogiri
1.11.0
CVE-2026-79771
cdx-mixed-ecosystems.json
1.19.3 Nokogiri XSLT transform has a memory leak
Fixed in 1.19.3
Monitor
4.8 medium
EPSS 0.4%
axios
0.21.1
CVE-2026-44490
cdx-mixed-ecosystems.json
0.32.0 axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
Fixed in 0.32.0
Monitor
— low
EPSS 0.4%
nokogiri
1.11.0
CVE-2026-57436
cdx-mixed-ecosystems.json
1.19.4 Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
Fixed in 1.19.4
Monitor
— low
EPSS 0.4%
nokogiri
1.11.0
CVE-2026-57437
cdx-mixed-ecosystems.json
1.19.4 Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
Fixed in 1.19.4
Monitor
5.9 medium
EPSS 0.4%
rack
2.2.3
CVE-2026-34830
cdx-mixed-ecosystems.json
2.2.23 Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect
Fixed in 2.2.23
Monitor
6.8 medium
EPSS 0.4%
axios
0.21.1
CVE-2026-42038
cdx-mixed-ecosystems.json
0.31.1 Axios: no_proxy bypass via IP alias allows SSRF
Fixed in 0.31.1
Monitor
5.3 medium
EPSS 0.3%
nokogiri
1.11.0
CVE-2026-79772
cdx-mixed-ecosystems.json
1.19.1 Nokogiri does not check the return value from xmlC14NExecute
Fixed in 1.19.1
Monitor
5.6 medium
EPSS 0.3%
requests
2.19.0
CVE-2024-35195
cdx-mixed-ecosystems.json
2.32.0 Requests `Session` object does not verify requests after making first request with verify=False
Fixed in 2.32.0
Monitor
5.3 medium
EPSS 0.3%
urllib3
1.25.8
CVE-2026-44431
cdx-mixed-ecosystems.json
2.7.0 urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
Fixed in 2.7.0
Monitor
5.3 medium
EPSS 0.3%
rack
2.2.3
CVE-2026-34763
cdx-mixed-ecosystems.json
2.2.23 Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory
Fixed in 2.2.23
Monitor
6.1 medium
EPSS 0.3%
django
3.2.0
CVE-2026-53878
cdx-mixed-ecosystems.json
5.2.16 Django: DomainNameValidator permits newline characters that may enable HTTP header injection
Fixed in 5.2.16
Monitor
5.3 medium
EPSS 0.3%
rack
2.2.3
CVE-2026-34786
cdx-mixed-ecosystems.json
2.2.23 Rack:: Static header_rules bypass via URL-encoded paths
Fixed in 2.2.23
Monitor
5.4 medium
EPSS 0.3%
axios
0.21.1
CVE-2026-42042
cdx-mixed-ecosystems.json
0.31.1 Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
Fixed in 0.31.1
Monitor
— medium
EPSS 0.3%
axios
0.21.1
CVE-2026-67319
cdx-mixed-ecosystems.json
0.33.0 Axios: Nested axios option objects can consume polluted prototype values
Fixed in 0.33.0
Monitor
— low
EPSS 0.3%
openssl
0.10.38
CVE-2026-41677
cdx-mixed-ecosystems.json
0.10.78 rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
Fixed in 0.10.78
Monitor
3.1 low
EPSS 0.3%
django
3.2.0
CVE-2026-6873
cdx-mixed-ecosystems.json
5.2.15 Django: signed cookies are vulnerable to salt namespace collisions
Fixed in 5.2.15
Monitor
5.4 medium
EPSS 0.3%
rack
2.2.3
CVE-2026-25500
cdx-mixed-ecosystems.json
2.2.22 Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href
Fixed in 2.2.22
Monitor
5.3 medium
EPSS 0.3%
rack
2.2.3
CVE-2026-26961
cdx-mixed-ecosystems.json
2.2.23 Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass.
Fixed in 2.2.23
Monitor
3.7 low
EPSS 0.3%
axios
0.21.1
CVE-2026-42040
cdx-mixed-ecosystems.json
0.31.1 Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
Fixed in 0.31.1
Monitor
4.8 medium
EPSS 0.2%
rack
2.2.3
CVE-2026-34831
cdx-mixed-ecosystems.json
2.2.23 Rack has Content-Length mismatch in Rack::Files error responses
Fixed in 2.2.23
Monitor
4.2 medium
EPSS 0.2%
rack
2.2.3
CVE-2025-32441
cdx-mixed-ecosystems.json
2.2.14 Rack session gets restored after deletion
Fixed in 2.2.14
Monitor
4.5 medium
EPSS 0.2%
openssl
0.10.38
CVE-2023-53159
cdx-mixed-ecosystems.json
0.10.55 `openssl` `X509VerifyParamRef::set_host` buffer over-read
Fixed in 0.10.55
Monitor
2.6 low
EPSS 0.2%
nokogiri
1.11.0
CVE-2026-57234
cdx-mixed-ecosystems.json
1.19.4 Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
Fixed in 1.19.4
Monitor
5.5 medium
EPSS 0.2%
requests
2.19.0
CVE-2026-25645
cdx-mixed-ecosystems.json
2.33.0 Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
Fixed in 2.33.0
Monitor
— medium
EPSS 0.2%
openssl
0.10.38
CVE-2026-44662
cdx-mixed-ecosystems.json
0.10.79 rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
Fixed in 0.10.79
Monitor
— low
EPSS 0.1%
nokogiri
1.11.0
CVE-2026-57438
cdx-mixed-ecosystems.json
1.19.4 Nokogiri: Possible Use-After-Free in XInclude Processing
Fixed in 1.19.4
Monitor
6.5 medium
EPSS —
openssl
0.10.38
GHSA-q445-7m23-qrmw
cdx-mixed-ecosystems.json
0.10.66 openssl's `MemBio::get_buf` has undefined behavior with empty buffers
Fixed in 0.10.66
Monitor
6.5 medium
EPSS —
nokogiri
1.11.0
GHSA-xxx9-3xcr-gjj3
cdx-mixed-ecosystems.json
1.13.4 XML Injection in Xerces Java affects Nokogiri
Fixed in 1.13.4
Monitor
— medium
EPSS —
nokogiri
1.11.0
CVE-2021-47996
cdx-mixed-ecosystems.json
1.11.4 Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
Fixed in 1.11.4
Monitor
— medium
EPSS —
nokogiri
1.11.0
CVE-2022-50998
cdx-mixed-ecosystems.json
1.13.9 Update bundled libxml2 to v2.10.3 to resolve multiple CVEs
Fixed in 1.13.9
Monitor
— medium
EPSS —
nokogiri
1.11.0
CVE-2023-54354
cdx-mixed-ecosystems.json
1.14.3 Nokogiri updates packaged libxml2 to v2.10.4 to resolve multiple CVEs
Fixed in 1.14.3
Monitor
— low
EPSS —
nokogiri
1.11.0
CVE-2024-58377
cdx-mixed-ecosystems.json
1.16.5 Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459
Fixed in 1.16.5
Monitor
— medium
EPSS —
nokogiri
1.11.0
CVE-2024-58378
cdx-mixed-ecosystems.json
1.15.6 Nokogiri update packaged libxml2 to v2.12.5 to resolve CVE-2024-25062
Fixed in 1.15.6
Monitor
— low
EPSS —
nokogiri
1.11.0
CVE-2025-71346
cdx-mixed-ecosystems.json
1.18.8 Nokogiri updates packaged libxml2 to v2.13.8 to resolve CVE-2025-32414 and CVE-2025-32415
Fixed in 1.18.8
Monitor
— low
EPSS —
nokogiri
1.11.0
CVE-2025-71407
cdx-mixed-ecosystems.json
1.18.3 Nokogiri updates packaged libxml2 to 2.13.6 to resolve CVE-2025-24928 and CVE-2024-56171
Fixed in 1.18.3
Monitor
— medium
EPSS —
openssl
0.10.38
GHSA-3gxf-9r58-2ghg
cdx-mixed-ecosystems.json
0.10.48 `openssl` `X509NameBuilder::build` returned object is not thread safe
Fixed in 0.10.48
Monitor
— medium
EPSS —
openssl
0.10.38
GHSA-xphf-cx8h-7q9g
cdx-mixed-ecosystems.json
0.10.60 `openssl` `X509StoreRef::objects` is unsound
Fixed in 0.10.60
No fix available
7.5 high
EPSS 2.2%
github.com/dgrijalva/jwt-go
v3.2.0
CVE-2020-26160
cdx-mixed-ecosystems.json
No published fix identified Authorization bypass in github.com/dgrijalva/jwt-go
CVSS 7.5 (high) via CVSS 3.1; No fixed version is available yet

Appendix B

Component inventory (20)

The full inventory, including components that could not be analysed. A component with no usable package URL is a blind spot, not a clean result.

ComponentVersionEcosystemDepthAnalysedFindings
lodash4.17.15 npmunknown yes4
axios0.21.1 npmunknown yes24
ejs3.1.6 npmunknown yes2
ws7.4.5 npmunknown yes3
traverse7.20.0 npmunknown yes1
django3.2.0 pypiunknown yes37
pyyaml5.3.1 pypiunknown yes1
requests2.19.0 pypiunknown yes5
urllib31.25.8 pypiunknown yes11
jinja22.11.2 pypiunknown yes5
github.com/gin-gonic/ginv1.6.3 golangunknown yes3
golang.org/x/textv0.3.7 golangunknown yes2
github.com/dgrijalva/jwt-gov3.2.0 golangunknown yes1
openssl0.10.38 cargounknown yes13
time0.1.44 cargounknown yes1
smallvec1.6.0 cargounknown yes1
Newtonsoft.Json12.0.3 nugetunknown yes1
System.Text.Encodings.Web4.7.1 nugetunknown yes1
rack2.2.3 gemunknown yes32
nokogiri1.11.0 gemunknown yes33

Appendix C

Declared licenses

Declarations supplied by the inventory, not independently verified license conclusions. No license policy was applied to this review. Missing declarations and compound expressions need review, and no legal compliance is implied.

ComponentDeclared licenseReview status
lodashMITDeclared
axiosMITDeclared
ejsApache-2.0Declared
wsMITDeclared
traverseMITDeclared
djangoBSD-3-ClauseDeclared
pyyamlMITDeclared
requestsApache-2.0Declared
urllib3MITDeclared
jinja2BSD-3-ClauseDeclared
github.com/gin-gonic/ginMITDeclared
golang.org/x/textBSD-3-ClauseDeclared
github.com/dgrijalva/jwt-goMITDeclared
opensslApache-2.0Declared
timeMITDeclared
smallvecMITDeclared
Newtonsoft.JsonMITDeclared
System.Text.Encodings.WebMITDeclared
rackMITDeclared
nokogiriMITDeclared

Appendix D

Method and data sources

Tiers
  • Fix now: a fix exists AND (the vulnerability is in CISA KEV OR EPSS >= 0.50)
  • Fix soon: a fix exists AND (EPSS >= 0.10 OR CVSS >= 7.0 OR published severity is high/critical)
  • Monitor: a fix exists but no exploitation signal and no high severity
  • No fix available: reported separately so it cannot dilute the action list; flagged urgent when in CISA KEV
Order of upgrades
  1. Highest tier contained in the action
  2. Number of KEV-listed vulnerabilities resolved
  3. Highest EPSS score resolved
  4. Number of vulnerabilities resolved
  5. Smaller upgrade distance (patch before minor before major)
  6. Direct dependencies before transitive ones
Recommended version
The recommended version is the lowest version at or above the highest version present that resolves the most known vulnerabilities for that package, not the latest release. This keeps upgrades applicable.
Grade
  • Start at 100.
  • Subtract 25 for any vulnerability in CISA KEV that has a fix, and 15 for any in KEV without one.
  • Subtract 8 per fix-now action, up to 40.
  • Subtract 3 per fix-soon action, up to 20.
  • A finding published with no severity score counts as high: an upgrade that clears one, otherwise rated monitor, is counted as fix soon.
  • Subtract 50 if the SBOM declares no components at all, because nothing can be concluded from it.
  • Subtract up to 20 in proportion to how much of the SBOM could not be matched.
  • The grade is flagged as possibly optimistic, with no score change, if any vulnerability data source failed during the scan.
  • A: 90+, B: 75+, C: 60+, D: 40+, F: below 40.

For this assessment: Fix-now actions (-16), Fix-soon actions (-20), No published severity.

Data sources

SourceStatusData dateVersionNote
OSV.dev vulnerability databaseavailable 2026-09-30T21:20:10.226Z2026-09-30
CISA Known Exploited Vulnerabilitiesavailable 2026-09-30T15:24:34.225Z2026.09.29
FIRST EPSS exploit prediction scoresavailable 2026-09-292026-09-29
Upgrade target verificationavailable 2026-09-30T21:20:11.367Z—

Appendix E

Glossary

SBOM
Software bill of materials: the list of components, and their versions, inside a piece of software.
Package URL (purl)
A standard identifier for a package, such as pkg:npm/lodash@4.17.21. Without one a component cannot be matched reliably.
Finding
One published advisory affecting one component. The same CVE in two components is two findings.
CVE
Common Vulnerabilities and Exposures: the public identifier for a known vulnerability.
CVSS
Common Vulnerability Scoring System: a 0 to 10 rating of how severe a vulnerability is, not how likely it is to be used.
EPSS
FIRST's Exploit Prediction Scoring System: the estimated probability that a vulnerability is exploited in the next 30 days.
CISA KEV
The US Cybersecurity and Infrastructure Security Agency's catalogue of vulnerabilities known to be exploited.
VEX
Vulnerability Exploitability eXchange: a supplier statement that a vulnerability does or does not affect a product, and why.
Fix now
A fix exists, and the vulnerability is known exploited or likely to be (EPSS 50% or more).
Fix soon
A fix exists, and there is a moderate exploitation signal or high severity.
Monitor
A fix exists, and nothing points to urgency.
No fix
No published version resolves it. It needs a mitigation or a risk decision.

Appendix F

Limitations

Review and approval

For teams that file this report as evidence. Completing this block records who reviewed the findings and accepted the plan.

RoleNamePositionDateSignature
Prepared by
Reviewed by
Approved by