Skip to content

CVE monitor: high/critical finding 2026-08-04 #145

Description

@github-actions

Nightly CVE monitor — high/critical finding

Run: https://github.com/zeroauth-dev/ZeroAuth/actions/runs/30871775537
Workflow: CVE Monitor
Commit: e307919

Closes audit-findings.md C-14 instrumentation; see
docs/plan/bfsi-v1/04-commits.md commit C-032 for context.

Scanner output

cve-monitor: scanning /home/runner/work/ZeroAuth/ZeroAuth (dry-run=0)
cve-monitor: running npm audit --json in /home/runner/work/ZeroAuth/ZeroAuth
./scripts/cve-monitor.sh: line 84: echo: write error: Broken pipe
npm audit summary: {"info":0,"low":20,"moderate":13,"high":28,"critical":0,"total":61}
npm audit: 28 high/critical advisories found
  - @nomicfoundation/hardhat-chai-matchers (high): see npm audit
  - @nomicfoundation/hardhat-ethers (high): see npm audit
  - @nomicfoundation/hardhat-network-helpers (high): see npm audit
  - @nomicfoundation/hardhat-toolbox (high): see npm audit
  - @nomicfoundation/hardhat-verify (high): see npm audit
  - @typechain/hardhat (high): see npm audit
  - adm-zip (high): adm-zip: Crafted ZIP file triggers 4GB memory allocation
  - axios (high): Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
  - bfj (high): see npm audit
  - brace-expansion (high): brace-expansion: Zero-step sequence causes process hang and memory exhaustion
  - fast-uri (high): fast-uri vulnerable to path traversal via percent-encoded dot segments
  - form-data (high): form-data: CRLF injection in form-data via unescaped multipart field names and filenames
  - hardhat (high): see npm audit
  - hardhat-gas-reporter (high): see npm audit
  - immutable (high): Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
  - ip-address (high): ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
  - js-yaml (high): JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
  - jsonpath (high): see npm audit
  - lodash (high): lodash vulnerable to Code Injection via `_.template` imports key names
  - nodemailer (high): Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
  - path-to-regexp (high): path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters
  - picomatch (high): Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
  - serialize-javascript (high): Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()
  - solidity-coverage (high): see npm audit
  - tmp (high): tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
  - underscore (high): Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
  - undici (high): Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
  - ws (high): ws: Uninitialized memory disclosure
cve-monitor: osv-scanner not installed on this runner; skipping
::warning::osv-scanner not found — npm audit only. See C-032 setup notes.
cve-monitor: at least one HIGH or CRITICAL CVE found — failing

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions