openjsf
14 known vulnerabilities affecting openjsf products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-25244 | High | 2.8% | 9.8 | WebdriverIO is a test automation framework for unit, e2e and component testing u… | |
| CVE-2026-6321 | Medium | 0.6% | 7.5 | fast-uri decoded percent-encoded path separators and dot segments before applyin… | |
| CVE-2026-6322 | Medium | 0.5% | 7.5 | fast-uri normalize() decoded percent-encoded authority delimiters inside the hos… | |
| CVE-2026-13676 | Medium | 0.5% | 7.5 | fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (ID… | |
| CVE-2026-10796 | Medium | 0.5% | 7.5 | nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from versi… | |
| CVE-2026-16221 | Medium | 0.3% | 7.5 | Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to… | |
| CVE-2026-75931 | Medium | 0.2% | 7.5 | fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form … | |
| CVE-2026-76172 | Medium | 0.2% | 7.5 | fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding p… | |
| CVE-2026-84292 | Medium | 0.2% | 7.5 | fast-uri serializes the port component of a URI without validating it. When reco… | |
| CVE-2026-84394 | Medium | 0.2% | 7.5 | fast-uri accepts a host that contains an unbalanced or misplaced authority brack… | |
| CVE-2026-18446 | Medium | 0.2% | 7.5 | fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash … | |
| CVE-2026-75975 | Medium | 0.2% | 7.5 | fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 liter… | |
| CVE-2026-75899 | Medium | 0.2% | 7.5 | fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname d… | |
| CVE-2026-41591 | Low | 0.2% | 6.4 | Marko is a declarative, HTML-based language for building web apps. Prior to mark… |