Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Mosskappa

#23581of 56,330
10.2Total CVSS
Vulnerabilities · 2
Low
1
Medium
1
PT-2026-52516
6.9
2026-06-25
Pnpm · Pnpm · CVE-2026-50017
**Name of the Vulnerable Software and Affected Versions** pnpm versions prior to 10.34.0 pnpm versions prior to 11.4.0 **Description** pnpm may send user-level unscoped npm authentication credentials to a registry specified in a repository-local `.npmrc` file. This occurs when a user's global configuration contains a default registry and an unscoped ` authToken`, but the repository's `.npmrc` file only defines a different registry URL without providing its own authentication. During metadata or installation workflows, pnpm incorrectly binds the user's global unscoped credential to the repository-selected registry and transmits it within the Authorization header. **Recommendations** Update pnpm to version 10.34.0 or later. Update pnpm to version 11.4.0 or later.
PT-2026-49168
3.3
2026-06-13
Runc · Runc · CVE-2026-41579
**Name of the Vulnerable Software and Affected Versions** runc versions prior to 1.3.6 runc versions prior to 1.4.3 runc versions prior to 1.5.0-rc.3 **Description** A flaw involving a `/dev` symlink allows a malicious container image to obtain limited write access to the host filesystem. This issue occurs during the rootfs setup process. **Recommendations** Update to version 1.3.6. Update to version 1.4.3. Update to version 1.5.0-rc.3.