OsVault/npm/request
npm15 critical

request

208 known vulnerabilities · 15 critical · 27 high

CVE-2023-28155MEDIUM

Server-Side Request Forgery in Request

Published Mar 16, 2023
CVE-2017-16026MEDIUM

Remote Memory Exposure in request

Published Nov 9, 2018
CVE-2026-3635

fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections

Published Mar 25, 2026
CVE-2026-5323MEDIUM
Risk: 26.5/100

a11y-mcp: Server-Side Request Forgery (SSRF) vulnerability in A11yServer function

Published Apr 2, 2026
CVE-2023-7078HIGH

Miniflare vulnerable to Server-Side Request Forgery (SSRF)

Published Dec 29, 2023
CVE-2021-31597CRITICAL

Improper Certificate Validation in xmlhttprequest-ssl

Published May 24, 2021
CVE-2023-45884MEDIUM

NASA Open MCT Cross Site Request Forgery (CSRF) vulnerability

Published Nov 9, 2023
CVE-2025-5276

Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function

Published May 29, 2025
CVE-2023-31999HIGH

@fastify/oauth2 vulnerable to Cross Site Request Forgery due to reused Oauth2 state

Published Jul 5, 2023
CVE-2022-23080MEDIUM

Server-Side Request Forgery in Directus

Published Jun 23, 2022
GHSA-6pcv-j4jx-m4vx

Flowise: Unauthenticated Information Disclosure of OAuth Secrets (Cleartext) via GET Request

Published Apr 16, 2026
CVE-2026-34767MEDIUM
Risk: 29.51/100

Electron: HTTP Response Header Injection in custom protocol handlers and webRequest

Published Apr 3, 2026
CVE-2022-37257CRITICAL

steal vulnerable to Prototype Pollution via requestedVersion variable

Published Sep 16, 2022
CVE-2022-31150MEDIUM

undici before v5.8.0 vulnerable to CRLF injection in request headers

Published Jul 21, 2022
CVE-2025-68272

Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding

Published Jan 2, 2026
CVE-2022-2216CRITICAL

Server-Side Request Forgery in parse-url

Published Jun 28, 2022
CVE-2024-53983

Backstage Scaffolder plugin vulnerable to Server-Side Request Forgery

Published Dec 2, 2024
CVE-2026-26319

OpenClaw is Missing Webhook Authentication in Telnyx Provider Allows Unauthenticated Requests

Published Feb 17, 2026
CVE-2024-37890HIGH

ws affected by a DoS when handling a request with many HTTP headers

Published Jun 17, 2024
CVE-2026-25474

OpenClaw has a Telegram webhook request forgery (missing `channels.telegram.webhookSecret`) → auth bypass

Published Feb 17, 2026
CVE-2023-5572CRITICAL

Server-Side Request Forgery (SSRF) in vriteio/vrite

Published Oct 13, 2023
CVE-2024-39338HIGH

Server-Side Request Forgery in axios

Published Aug 12, 2024
CVE-2025-24010

Websites were able to send any requests to the development server and read the response in vite

Published Jan 21, 2025
GHSA-9gvx-vj57-vqqx

Duplicate Advisory: OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authentication

Published Apr 10, 2026
CVE-2026-29772

Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands

Published Mar 24, 2026
CVE-2022-32213MEDIUM

llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding

Published Jul 15, 2022
CVE-2020-8134HIGH

Server-side request forgery in Ghost CMS

Published May 6, 2021
CVE-2023-45857MEDIUM

Axios Cross-Site Request Forgery Vulnerability

Published Nov 8, 2023
CVE-2021-42228HIGH

Cross Site Request Forgery in kindeditor

Published Oct 18, 2021
CVE-2020-28360CRITICAL

Server-Side Request Forgery in private-ip

Published Apr 13, 2021
CVE-2020-28482MEDIUM

Cross-site Request Forgery in fastify-csrf

Published Jan 20, 2021
CVE-2025-68467

Dark Reader gives users the ability to request style sheets from local web servers

Published Mar 4, 2026
CVE-2024-48913

Hono allows bypass of CSRF Middleware by a request without Content-Type header.

Published Oct 15, 2024
CVE-2026-30820

Flowise has Authorization Bypass via Spoofed x-request-from Header

Published Mar 6, 2026
CVE-2025-59155

HackMD MCP Server has Server-Side Request Forgery (SSRF) vulnerability

Published Sep 15, 2025
CVE-2020-11021MEDIUM

Http request which redirect to another hostname do not strip authorization header in @actions/http-client

Published Apr 29, 2020
CVE-2023-2307MEDIUM

@builder.io/qwik-city Cross-Site Request Forgery vulnerability

Published Apr 26, 2023
CVE-2020-8128CRITICAL

Server-Side Request Forgery and Inclusion of Functionality from Untrusted Control Sphere in jsreport

Published Apr 13, 2021
CVE-2025-15104

Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability

Published Jan 16, 2026
CVE-2025-7338

Multer vulnerable to Denial of Service via unhandled exception from malformed request

Published Jul 17, 2025
GHSA-569q-mpph-wgww

Better Auth affected by external request basePath modification DoS

Published Dec 1, 2025
GHSA-pqhr-mp3f-hrpp

Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parameters

Published Mar 31, 2026
GHSA-pg8g-f2hf-x82m

Duplicate Advisory: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects

Published Apr 9, 2026
CVE-2023-26492MEDIUM

Directus vulnerable to Server-Side Request Forgery On File Import

Published Mar 3, 2023
CVE-2022-2900CRITICAL

Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url

Published Sep 15, 2022
MAL-2025-2703

Malicious code in requestz-promises (npm)

Published Mar 25, 2025
CVE-2020-36851

cors-anywhere vulnerable to server-side request forgery

Published Sep 25, 2025
CVE-2024-31207MEDIUM

Vite's `server.fs.deny` did not deny requests for patterns with directories.

Published Apr 3, 2024
CVE-2020-11610HIGH

xdlocalstorage does not verify request origin

Published May 24, 2022
CVE-2026-25957

Cube Core is vulnerable to Denial of Service (DoS) via crafted request

Published Feb 10, 2026
CVE-2026-25528

LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

Published Feb 9, 2026
CVE-2025-27097

Cache variables with the operations when transforms exist on the root level even if variables change in the further requests with the same operation

Published Oct 10, 2023
GHSA-6rmx-gvvg-vh6j

OpenClaw's hooks count non-POST requests toward auth lockout

Published Mar 9, 2026
MAL-2022-4382

Malicious code in loglongakamairequest (npm)

Published Jun 20, 2022
GHSA-x8rx-789c-2pxq

RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests

Published Apr 8, 2026
CVE-2026-33624

Parse Server: MFA recovery code single-use bypass via concurrent requests

Published Mar 24, 2026
CVE-2025-25289

@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Feb 14, 2025
MAL-2022-2091

Malicious code in com.unity.modules.unitywebrequesttexture (npm)

Published Jun 20, 2022
GHSA-353c-v8x9-v7c3

MCP-Framework: Unbounded memory allocation in readRequestBody allows denial of service via HTTP transport

Published Apr 16, 2026
CVE-2025-32395

Vite has an `server.fs.deny` bypass with an invalid `request-target`

Published Apr 11, 2025
GHSA-8f9r-gr6r-x63q

Duplicate Advisory: OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation

Published Apr 10, 2026
CVE-2025-68150

Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter

Published Dec 16, 2025
MAL-2022-2088

Malicious code in com.unity.modules.unitywebrequest (npm)

Published Jun 20, 2022
MAL-2022-2089

Malicious code in com.unity.modules.unitywebrequestassetbundle (npm)

Published Jun 20, 2022
MAL-2024-10401

Malicious code in puppeteerrequestinterceptor (npm)

Published Nov 5, 2024
CVE-2026-26317

OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints

Published Feb 18, 2026
CVE-2021-41167HIGH

modern-async's `forEachSeries` and `forEachLimit` functions do not limit the number of requests

Published Oct 21, 2021
MAL-2023-549

Malicious code in karma-jasmine-i-request (npm)

Published Jan 30, 2023
CVE-2026-33226

Budibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview

Published Mar 18, 2026
CVE-2020-28168MEDIUM

Axios vulnerable to Server-Side Request Forgery

Published Jan 4, 2021
CVE-2020-8205HIGH

Server-Side Request Forgery in @uppy/companion

Published Aug 13, 2020
CVE-2023-29008HIGH

SvelteKit framework has Insufficient CSRF protection for CORS requests

Published Apr 7, 2023
GHSA-4f8g-77mw-3rxc

OpenClaw: Gateway plugin HTTP `auth: gateway` widens identity-bearing `operator.read` requests into runtime `operator.write`

Published Apr 9, 2026
GHSA-9q82-xgwf-vj6h

Apollo Server: Browser bug allows for bypass of XS-Search (read-only Cross-Site Request Forgery) prevention

Published Mar 26, 2026
CVE-2025-27152

axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL

Published Mar 7, 2025
CVE-2021-45851HIGH

Server-Side Request Forgery in FUXA

Published Mar 17, 2022
CVE-2021-23431MEDIUM

Cross-site Request Forgery (CSRF) in joplin

Published Sep 2, 2021
CVE-2026-22030

React Router has CSRF issue in Action/Server Action Request Processing

Published Jan 8, 2026
CVE-2020-22403HIGH

Cross-Site Request Forgery in express-cart

Published Aug 30, 2021
CVE-2023-32688MEDIUM

Invalid push request payload crashes Parse Server

Published May 22, 2023
GHSA-c447-w54g-f55j

Duplicate Advisory: OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustion

Published Mar 29, 2026
CVE-2025-66405

Portkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom Host

Published Dec 2, 2025
MAL-2024-9250

Malicious code in request-ip-validator (npm)

Published Oct 11, 2024
CVE-2025-64430

Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format

Published Nov 5, 2025
CVE-2023-30589HIGH

llhttp vulnerable to HTTP request smuggling

Published Jul 1, 2023
CVE-2024-55500

Avenwu Whistle Cross-Site Request Forgery (CSRF)

Published Dec 10, 2024
CVE-2026-29057

Next.js: HTTP request smuggling in rewrites

Published Mar 17, 2026
CVE-2022-0508MEDIUM

Server-Side Request Forgery in @peertube/embed-api

Published Feb 9, 2022
MAL-2024-8951

Malicious code in express-request-ip (npm)

Published Sep 23, 2024
CVE-2026-21858

n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling

Published Jan 7, 2026
MAL-2024-11136

Malicious code in discord-json-requests (npm)

Published Nov 29, 2024
CVE-2025-67427

evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API

Published Jan 5, 2026
CVE-2025-69206

hemmelig allows SSRF Filter bypass via Secret Request functionality

Published Dec 29, 2025
CVE-2024-34351HIGH

Next.js Server-Side Request Forgery in Server Actions

Published May 9, 2024
CVE-2022-32214MEDIUM

llhttp allows HTTP Request Smuggling via Improper Delimiting of Header Fields

Published Jul 15, 2022
CVE-2022-0654HIGH

Cookie exposure in requestretry

Published Feb 24, 2022
MAL-2025-191201

Malicious code in @clausehq/flows-step-httprequest (npm)

Published Nov 25, 2025
CVE-2020-7740HIGH

Server-Side Request Forgery in node-pdf-generator

Published May 10, 2021
CVE-2025-32997

http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failed

Published Apr 15, 2025
CVE-2026-27646

OpenClaw: Sandboxed /acp spawn requests could initialize host ACP sessions

Published Mar 9, 2026
CVE-2026-33732

srvx is vulnerable to middleware bypass via absolute URI in request line

Published Mar 26, 2026
CVE-2020-28502HIGH

xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code Injection

Published May 4, 2021
CVE-2025-9862

Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark

Published Sep 15, 2025
CVE-2022-25876MEDIUM

Server-Side Request Forgery in link-preview-js

Published Jul 2, 2022
CVE-2020-15152CRITICAL

Server-Side Request Forgery in ftp-srv

Published Aug 17, 2020
CVE-2026-27567

Payload: Server-Side Request Forgery (SSRF) in External File URL Uploads

Published Feb 24, 2026
CVE-2022-39313HIGH

parse-server crashes when receiving file download request with invalid byte range

Published Oct 18, 2022
CVE-2020-7739HIGH

Server-Side Request Forgery in phantomjs-seo

Published May 10, 2021
CVE-2026-30938

Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement

Published Mar 10, 2026
MAL-2025-618

Malicious code in requests-async (npm)

Published Jan 29, 2025
GHSA-mvvv-v22x-xqwp

NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins

Published Apr 15, 2026
CVE-2022-31830CRITICAL

Server-Side Request Forgery in kityminder

Published Jun 10, 2022
GHSA-pfm2-2mhg-8wpx

n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests

Published Apr 23, 2026
GHSA-qrmm-w75w-3wpx

Server side request forgery in SwaggerUI

Published Dec 9, 2021
CVE-2021-23664HIGH

Server side request forgery in @isomorphic-git/cors-proxy

Published Jan 26, 2022
CVE-2025-67718

Formio improperly authorized permission elevation through specially crafted request path

Published Dec 10, 2025
GHSA-qx8j-g322-qj6m

OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects

Published Apr 9, 2026
CVE-2026-32943

Parse Server has a password reset token single-use bypass via concurrent requests

Published Mar 17, 2026
CVE-2026-34777MEDIUM
Risk: 27/100

Electron: Incorrect origin passed to permission request handler for iframe requests

Published Apr 3, 2026
CVE-2021-23718MEDIUM

Server-Side Request Forgery in ssrf-agent

Published Dec 2, 2021
CVE-2020-7646CRITICAL

curlrequest allows execution of arbitrary commands

Published May 13, 2020
CVE-2026-24052

Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains

Published Feb 3, 2026
CVE-2023-40178MEDIUM

@node-saml/node-saml's validatePostRequestAsync does not include checkTimestampsValidityError

Published Aug 21, 2023
CVE-2026-23527

h3 v1 has Request Smuggling (TE.TE) issue

Published Jan 15, 2026
CVE-2026-33011

Nest Fastify HEAD Request Middleware Bypass

Published Mar 17, 2026
CVE-2025-67490

Improper Request Caching Lookup in the Auth0 Next.js SDK

Published Dec 10, 2025
CVE-2026-26801

pdfmake is vulnerable to server-side request forgery (SSRF)

Published Mar 10, 2026
CVE-2017-16073HIGH

noderequest is malware

Published Sep 17, 2018
CVE-2026-27739

Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline

Published Feb 25, 2026
GHSA-3h52-cx59-c456

OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation

Published Mar 29, 2026
GHSA-cmfr-9m2r-xwhq

OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard

Published Apr 9, 2026
CVE-2022-0086CRITICAL

uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF)

Published Jan 6, 2022
MAL-2025-48241

Malicious code in bird-clean-sky-request (npm)

Published Oct 9, 2025
CVE-2025-25290

@octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking

Published Feb 14, 2025
MAL-2022-3098

Malicious code in font-request (npm)

Published Jun 20, 2022
CVE-2026-24767

NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality

Published Jan 28, 2026
CVE-2025-63700

Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage

Published Nov 20, 2025
CVE-2023-29003HIGH

SvelteKit vulnerable to Cross-Site Request Forgery

Published Apr 4, 2023
MAL-2022-2503

Malicious code in discord.js-request (npm)

Published Jul 18, 2022
MAL-2022-640

Malicious code in @thrift-api/request (npm)

Published Jun 20, 2022
GHSA-67mh-4wv8-2f99

esbuild enables any website to send any requests to the development server and read the response

Published Feb 10, 2025
CVE-2022-3978MEDIUM

NodeBB vulnerable to Cross-Site Request Forgery

Published Nov 13, 2022
MAL-2025-2038

Malicious code in dependabot-pull-request-action (npm)

Published Mar 3, 2025
CVE-2025-65513

Fetch MCP Server has a Server-Side Request Forgery (SSRF) vulnerability

Published Dec 10, 2025
MAL-2024-10752

Malicious code in magic-umi-request (npm)

Published Nov 14, 2024
CVE-2026-26118

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

Published Mar 10, 2026
GHSA-hqf9-8xv5-x8xw

ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not revert and result in loss of funds.

Published Jan 5, 2026
CVE-2024-37818HIGH

Strapi Server-Side Request Forgery (SSRF)

Published Jun 20, 2024
CVE-2020-8135CRITICAL

Server-Side Request Forgery in @uppy/companion

Published Sep 3, 2020
MAL-2026-71

Malicious code in redis-request-parser (npm)

Published Jan 6, 2026
CVE-2026-27729

Astro has memory exhaustion DoS due to missing request body size limit in Server Actions

Published Feb 25, 2026
CVE-2026-32980

OpenClaw Telegram webhook request bodies were read before secret validation, enabling unauthenticated resource exhaustion

Published Mar 16, 2026
MAL-2022-6393

Malicious code in synfc-wrequest (npm)

Published Aug 19, 2022
MAL-2025-4884

Malicious code in smart-request-buffers (npm)

Published Jun 10, 2025
CVE-2024-32964CRITICAL

lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability

Published May 10, 2024
MAL-2022-2092

Malicious code in com.unity.modules.unitywebrequestwww (npm)

Published Jun 20, 2022
CVE-2025-47944

Multer vulnerable to Denial of Service from maliciously crafted requests

Published May 19, 2025
CVE-2025-36852

@nx/azure-cache Vulnerable to Build Cache Poisoning via Untrusted Pull Requests

Published Jun 10, 2025
CVE-2024-31206HIGH

dectalk-tts Uses Unencrypted HTTP Request

Published Apr 4, 2024
CVE-2026-31818CRITICAL
Risk: 48/100

Budibase: Server-Side Request Forgery via REST Connector with Empty Default Blacklist

Published Apr 3, 2026
CVE-2025-60542

TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update

Published Oct 29, 2025
CVE-2017-16570HIGH

Cross-Site Request Forgery (CSRF) in keystone

Published Nov 30, 2017
CVE-2022-35949MEDIUM

`undici.request` vulnerable to SSRF using absolute URL on `pathname`

Published Aug 18, 2022
CVE-2018-6874HIGH

Cross-Site Request Forgery (CSRF) in Auth0

Published Nov 6, 2018
CVE-2026-31829

Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access

Published Mar 11, 2026
MAL-2023-8646

Malicious code in requestlyx (npm)

Published Nov 30, 2023
GHSA-h25m-26qc-wcjf

Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components

Published Jan 28, 2026
MAL-2024-7924

Malicious code in affirm-requests (npm)

Published Aug 7, 2024
MAL-2026-2798

Malicious code in request-easy-validator (npm)

Published Apr 16, 2026
CVE-2022-35924CRITICAL

NextAuth.js before 4.10.3 and 3.29.10 sending verification requests (magic link) to unwanted emails

Published Aug 2, 2022
CVE-2026-32011

OpenClaw has pre-auth webhook body parsing that can enable unauthenticated slow-request DoS

Published Mar 3, 2026
GHSA-xp9r-prpg-373r

OpenClaw: `browser.request` still allows `POST /reset-profile` through the `operator.write` surface

Published Mar 30, 2026
GHSA-vmhq-cqm9-6p7q

OpenClaw: `browser.request` let `operator.write` persist admin-only browser profile changes

Published Mar 13, 2026
CVE-2015-9236MEDIUM

Incorrect handling of CORS preflight request headers in hapi

Published Jun 7, 2018
GHSA-wwfp-w96m-c6x8

OpenClaw: Pairing pending-request caps were enforced per channel instead of per account

Published Apr 7, 2026
CVE-2022-31089HIGH

Invalid file request can crash server

Published Jun 20, 2022
MAL-2022-5377

Malicious code in plywood-clickhouse-requester (npm)

Published Jun 20, 2022
MAL-2025-3045

Malicious code in @hongfangze/http-request (npm)

Published Apr 2, 2025
MAL-2025-2410

Malicious code in request-draft-ui (npm)

Published Mar 14, 2025
GHSA-6mqc-jqh6-x8fc

OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authentication

Published Mar 26, 2026
MAL-2023-8242

Malicious code in @ltd2research/tldrequest (npm)

Published Sep 26, 2023
CVE-2026-34224MEDIUM
Risk: 22.01/100

Parse Server has an MFA single-use token bypass via concurrent authData login requests

Published Mar 29, 2026
MAL-2022-2090

Malicious code in com.unity.modules.unitywebrequestaudio (npm)

Published Jun 20, 2022
MAL-2022-5452

Malicious code in prerequests-xcode (npm)

Published Jun 20, 2022
MAL-2022-5503

Malicious code in ps-request-ws (npm)

Published Jun 20, 2022
MAL-2024-10852

Malicious code in electron-request (npm)

Published Nov 20, 2024
MAL-2022-5755

Malicious code in request-progres (npm)

Published Jun 20, 2022
MAL-2022-5997

Malicious code in segmentrequestmanager (npm)

Published Jun 20, 2022
MAL-2022-603

Malicious code in @specials/request-tinkoff (npm)

Published Jun 20, 2022
CVE-2026-1525

Undici has an HTTP Request/Response Smuggling issue

Published Mar 13, 2026
MAL-2025-1491

Malicious code in norequest-akash (npm)

Published Feb 19, 2025
MAL-2025-302

Malicious code in request-external-access (npm)

Published Jan 21, 2025
GHSA-3xv9-89fm-7h4r

OpenClaw: diffs viewer misclassifies proxied remote requests as loopback when `allowRemoteViewer` is disabled

Published Apr 3, 2026
MAL-2025-2702

Malicious code in requests-promises (npm)

Published Mar 25, 2025
MAL-2022-63

Malicious code in @aia-digital/request-module (npm)

Published Jun 20, 2022
CVE-2026-30972

Parse Server has a rate limit bypass via batch request endpoint

Published Mar 11, 2026
CVE-2023-35167MEDIUM

When setting EntityOptions.apiPrefilter to a function, the filter is not applied to API requests for a resource by Id

Published Jun 20, 2023
MAL-2023-7969

Malicious code in mmolecule-httprequester (npm)

Published Aug 31, 2023
GHSA-4p4f-fc8q-84m3

OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatch

Published Apr 7, 2026
CVE-2025-59052

Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data Leakage

Published Sep 10, 2025
CVE-2026-25958

Cube Core is vulnerable to privilege escalation via a specially crafted request

Published Feb 10, 2026
CVE-2025-69203

Signal K Server Vulnerable to Access Request Spoofing

Published Jan 2, 2026
MAL-2026-1646

Malicious code in abstract-http-request (npm)

Published Mar 18, 2026
MAL-2026-1444

Malicious code in graphql-request-dom (npm)

Published Mar 16, 2026
MAL-2026-2526

Malicious code in request-js-validator (npm)

Published Apr 6, 2026
MAL-2025-4001

Malicious code in ing-feat-payment-request (npm)

Published May 19, 2025
MAL-2025-47967

Malicious code in simplerequestnode (npm)

Published Oct 7, 2025
MAL-2025-47669

Malicious code in express-xmlrequest (npm)

Published Sep 26, 2025
Check your entire dependency tree at onceRun dependency scan →