Conversation
Spectra Assure Community Scan: ❌ FAILScanned:
|
Spectra Assure Community Scan: ❌ FAILScanned: ❌ Rejected packages📦
|
| CVE/GHSA | CVSS | Summary | Signals |
|---|---|---|---|
| CVE-2026-42043 | 🔴 10.00 | Axios is vulnerable to a NO_PROXY protection bypass via RFC 1122 loopback subnet (127.0.0.0/8) due to an incomplete fix for CVE-2025-62718. | ⚡ exploit |
| CVE-2026-44492 | 🟠 8.60 | Axios does not properly normalize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass. | ⚡ exploit |
| CVE-2026-44487 | 🟠 8.20 | Axios's Node.js HTTP adapter may leak Proxy-Authorization credentials to the origin server during specific proxy-to-direct redirect flows. | ⚡ exploit |
| CVE-2026-42038 | 🟠 7.50 | Axios is vulnerable to a no_proxy bypass, allowing SSRF attacks due to incomplete hostname normalization. | ⚡ exploit |
| CVE-2026-44486 | 🟠 7.50 | Axios leaks proxy credentials to a redirect target when using an authenticated proxy configuration with automatic redirects enabled. | ⚡ exploit |
and 13 more vulnerabilities — see full report →
📦 pkg:npm/plain-crypto-js@4.2.1 — REJECT (2 of 3) [REMOVED] [QUARANTINED]
🔗 axios@0.30.4 → plain-crypto-js@4.2.1
📅 Released 4 months ago
⚖️ Permissive (MIT)
Caution
Malware
🛑 Threat detected: Archive-GZIP.Downloader.SupplyChain
🛑 Threat detected: Text.PUA.SupplyChain
🛑 Threat detected: Text.Downloader.SupplyChain
🛑 Threat detected: Script-JS.Downloader.SupplyChain
🛑 Threat detected: Archive-TAR.Downloader.SupplyChain
Caution
SAFE Assessment
❌ Tampering: 1 quarantined components found
❌ Malware: 4 supply chain attack artifacts
📦 pkg:npm/qs@6.15.3 — REJECT (3 of 3)
🔗 express@5.2.1 → qs@6.15.3 (2 paths)
📅 Released 1 month ago
⚖️ Permissive (BSD-3-Clause)
Caution
Policy violations
❌ TH17127 — Detected presence of files containing URLs that link to raw files on GitHub.
No description provided.