Known vulnerabilities in npm

Vendor: OpenAnolis
Software: npm
Software CPE: cpe:2.3:o:openanolis:npm:*:*:*:*:*:anolis_os:*:*
Total vulnerabilities: 96
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting npm npm is affected by 96 known vulnerabilities: 7 high, 72 medium, 17 low Critical High Medium Low

Vulnerabilities (96)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU127046 - Improper input validation
CVE-2026-27135
CWE-20 Medium
No
No
10.8.2-1.20.20.2.1 23.04.2026 SB2026042395
SB20260423101
SB20260423102
and 37 more
#VU126873 - Inefficient Regular Expression Complexity
CVE-2026-27904
CWE-1333 Low
No
No
10.8.2-1.20.20.2.1 22.04.2026 SB20260422244
SB20260423104
SB20260423105
and 16 more
#VU126386 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-55131
CWE-362 Low
No
No
10.8.2-1.20.20.0.1 17.04.2026 SB2026041708
SB2026041712
SB2026041714
and 20 more
#VU126387 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-55130
CWE-59 Low
No
No
10.8.2-1.20.20.0.1 17.04.2026 SB2026041708
SB2026041712
SB2026041714
and 17 more
#VU126388 - Uncaught Exception
CVE-2025-59465
CWE-248 Medium
No
No
10.8.2-1.20.20.0.1 17.04.2026 SB2026041708
SB2026041712
SB2026041714
and 23 more
#VU126389 - Uncaught Exception
CVE-2025-59466
CWE-248 Medium
No
No
10.8.2-1.20.20.0.1 17.04.2026 SB2026041708
SB2026041712
SB2026041714
and 17 more
#VU126392 - Improper Access Control
CVE-2025-55132
CWE-284 Low
No
No
10.8.2-1.20.20.0.1 17.04.2026 SB2026041708
SB2026041712
SB2026041714
and 13 more
#VU124541 - DEPRECATED: Often Misused: Path Manipulation
CVE-2026-21637
CWE-249 High
No
No
10.8.2-1.20.20.0.1 25.03.2026 SB2026032902
SB20260415182
SB20260415187
and 29 more
#VU124542 - Error Handling
CVE-2026-21710
CWE-388 Medium
No
No
10.8.2-1.20.20.2.1 25.03.2026 SB20260325154
SB2026032902
SB2026041056
and 33 more
#VU123140 - Inefficient Regular Expression Complexity
CVE-2026-26996
CWE-1333 Medium
No
No
10.8.2-1.20.20.2.1 23.02.2026 SB2026022345
SB2026030633
SB2026032328
and 35 more
#VU109243 - Missing release of memory after effective lifetime
CVE-2025-23165
CWE-401 Low
No
No
10.8.2-1.20.19.2.1 16.05.2025 SB2025051605
SB2025051901
SB2025051902
and 17 more
#VU109242 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-23167
CWE-444 Medium
Available
No
10.8.2-1.20.19.2.1 16.05.2025 SB2025051605
SB2025051901
SB2025051958
and 12 more
#VU109241 - Error Handling
CVE-2025-23166
CWE-388 Medium
No
No
10.8.2-1.20.19.2.1 16.05.2025 SB2025051605
SB2025051901
SB2025051902
and 31 more
#VU107155 - Use After Free
CVE-2025-31498
CWE-416 High
No
No
10.8.2-1.20.19.1.1 08.04.2025 SB2025040846
SB2025040925
SB2025040926
and 18 more
#VU93882 - Permissions, Privileges, and Access Controls
CVE-2024-22018
CWE-264 Low
No
No
10.8.1-1.20.16.0.1 09.07.2024 SB2024070937
SB20240717120
SB2024072232
and 15 more
#VU93881 - Permissions, Privileges, and Access Controls
CVE-2024-36137
CWE-264 Low
No
No
10.8.1-1.20.16.0.1 09.07.2024 SB2024070937
SB20240717120
SB2024072232
and 23 more
#VU93880 - Server-Side Request Forgery (SSRF)
CVE-2024-22020
CWE-918 Medium
No
No
10.7.0-1.18.20.4.1, 10.8.1-1.20.16.0.1 09.07.2024 SB2024070937
SB2024071636
SB20240717119
and 30 more
#VU87734 - Resource exhaustion
CVE-2024-28863
CWE-400 Medium
No
No
10.7.0-1.18.20.4.1, 10.8.1-1.20.16.0.1 22.03.2024 SB2024032234
SB2024052306
SB2024061114
and 30 more
#VU86728 - Inconsistency Between Implementation and Documented Design
CVE-2024-21890
CWE-1068 Low
No
No
10.8.1-1.20.16.0.1 22.02.2024 SB2024022225
SB2024022226
SB2024022833
and 16 more
#VU82068 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-39332
CWE-22 Medium
No
No
10.8.1-1.20.16.0.1 17.10.2023 SB2023101703
SB2023101804
SB2023101805
and 13 more


Showing elements 1 - 20 out of 96