Questarr β CWEs addressed per release (v1.2.0 β v1.5.0)
Method: same asdocs/CVE_FIXES_BY_RELEASE.md β diffed package-lock.json at each
tag boundary and cross-checked every bumped package through OSV.dev. Each advisory is then mapped to its CWE
IDs sourced from the database_specific.cwe_ids field in the OSV.dev response (e.g. ["CWE-400", "CWE-770"];
older records used database_specific.cwes). The script that automates this
process is scripts/cwe-report.mjs.
This document gives a weakness-category view of what was addressed across releases β useful for tracking
which classes of bugs (injection, DoS, memory safety, SSRF, β¦) were systematically reduced over time. The
companion CVE doc lists the same findings by severity and package. The two documents are complementary;
neither replaces the other.
Scope note: same as the CVE doc β this covers dependency-bump fixes, not a full current-exposure audit.
First-party code weaknesses are tracked separately in docs/SECURITY_ASSESSMENT.md
and docs/THREAT_MODEL.md.
v1.2.0 (from v1.1.0)
CWE-400: Uncontrolled Resource Consumption
- fast-xml-parser 5.3.3 β 5.3.4 β CVE-2026-25128 β numeric entity parsing caused a RangeError DoS; no upper bound on expansion count.
v1.2.1 (from v1.2.0)
CWE-1333: Inefficient Regular Expression Complexity
- fast-xml-parser 5.3.4 β 5.3.5 β CVE-2026-25896 β regex injection in DOCTYPE entity names allowed an attacker to craft a payload triggering catastrophic backtracking; classified as injection-via-regex (ReDoS).
v1.2.2 (from v1.2.1)
CWE-400: Uncontrolled Resource Consumption
- fast-xml-parser 5.3.5 β 5.3.7 β CVE-2026-26278 β entity expansion in DOCTYPE had no recursion depth limit, enabling unbounded memory growth via a small document.
v1.3.0 (from v1.2.2) β largest security-relevant release
CWE-89: Improper Neutralization of Special Elements used in an SQL Command
- drizzle-orm 0.45.1 β 0.45.2 β CVE-2026-39356 β SQL identifiers were not properly escaped, allowing injection via user-controlled column/table names passed to query builders.
CWE-91: XML Injection
- fast-xml-parser 5.3.7 β 5.7.1 β CVE-2026-41650 β XML comment and CDATA delimiters were not escaped in XMLBuilder output, allowing injected markup when user data flowed through the serialiser.
CWE-290: Authentication Bypass by Spoofing
- express-rate-limit 8.2.1 β 8.3.2 β CVE-2026-30827 β IPv4-mapped IPv6 addresses (e.g.
::ffff:1.2.3.4) were not normalised to their IPv4 form, giving dual-stack clients two independent rate-limit buckets and allowing effective bypass of per-client limits.
CWE-295: Improper Certificate Validation
- node-forge 1.3.3 β 1.4.0 β CVE-2026-33896 β
basicConstraintsand RFC 5280 path-length constraints were not validated during certificate-chain building, enabling a crafted intermediate to forge a trusted leaf certificate.
CWE-347: Improper Verification of Cryptographic Signature
- node-forge 1.3.3 β 1.4.0 β CVE-2026-33894 β RSA-PKCS1 v1.5 signature verification was susceptible to a Bleichenbacher-style chosen-ciphertext attack, allowing signature forgery without the private key.
- node-forge 1.3.3 β 1.4.0 β CVE-2026-33895 β Ed25519 signature verification did not check for canonical scalar encoding, allowing signature malleability (different byte sequences passing for the same signature).
CWE-400: Uncontrolled Resource Consumption
- fast-xml-parser 5.3.7 β 5.7.1 β CVE-2026-33036 β incomplete fix for CVE-2026-26278; a numeric entity bypass re-enabled unbounded expansion even when a limit was configured.
- fast-xml-parser 5.3.7 β 5.7.1 β CVE-2026-33349 β entity expansion limit treated as JS falsy when set
to
0, silently disabling all protection. - multer 2.0.2 β 2.1.1 β CVE-2026-2359 β resource exhaustion via concurrent upload requests with pathological field layouts.
- multer 2.0.2 β 2.1.1 β CVE-2026-3304 β incomplete cleanup of aborted uploads consumed disk space until the process ran out of writable storage.
- socket.io-parser 4.2.5 β 4.2.6 β CVE-2026-33151 β unbounded binary attachments in Socket.IO messages were buffered in memory without any size limit, enabling memory exhaustion DoS.
CWE-459: Incomplete Cleanup
- multer 2.0.2 β 2.1.1 β CVE-2026-3304 β see CWE-400 entry above; incomplete cleanup of aborted uploads is classified under both resource consumption and incomplete cleanup.
CWE-674: Uncontrolled Recursion
- fast-xml-parser 5.3.7 β 5.7.1 β CVE-2026-27942 β
XMLBuilderwithpreserveOrder: truerecursed into nested structures without a depth guard, causing a stack overflow on deeply nested input. - multer 2.0.2 β 2.1.1 β CVE-2026-3520 β uncontrolled recursion when parsing multipart payloads with deeply nested boundary markers; exploitable with a crafted ~4 KB request body.
CWE-835: Loop with Unreachable Exit Condition (Infinite Loop)
- node-forge 1.3.3 β 1.4.0 β CVE-2026-33891 β
BigInteger.modInverse(0)entered an infinite loop with no exit path; reachable via crafted RSA public keys or DH parameters.
v1.3.1 (from v1.3.0)
No dependency bump in this release crosses afixed OSV boundary β no CWE fixes to attribute.
v1.4.0 (from v1.3.1)
CWE-20: Improper Input Validation
- qs 6.14.2 β 6.15.2 β CVE-2026-8723 β
qs.stringifythrew an uncaughtTypeErrorwhen it encounterednull/undefinedarray entries withencodeValuesOnlyset; missing input guard turned invalid data into a remotely-triggerable DoS.
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) (devDep)
- vite 8.0.12 β 8.1.4 β CVE-2026-53571 β
server.fs.denyallow-list bypass; crafted paths using URL encoding evaded the restriction and allowed arbitrary file reads from the dev serverβs host filesystem.
CWE-93: Improper Neutralization of CRLF Sequences
- form-data 4.0.5 β 4.0.6 β CVE-2026-12143 β multipart field names and filenames were passed through to
MIME headers without stripping
\r\nsequences, allowing header injection in any HTTP client that consumed the generated body (e.g. proxied upload forwarding).
CWE-200: Exposure of Sensitive Information to an Unauthorised Actor (devDep)
- vite 8.0.12 β 8.1.4 β CVE-2026-53632 β the
launch-editorintegration passed user-supplied paths through to an OS shell command on Windows; a UNC path could be crafted to trigger an outbound SMB connection and capture an NTLMv2 authentication hash from the developerβs machine.
CWE-400: Uncontrolled Resource Consumption
- multer 2.1.1 β 2.2.0 β CVE-2026-5079 β deeply nested field name arrays (e.g.
a[b][c][β¦]repeated thousands of times) caused O(nΒ²) processing and memory growth, eventually OOM-killing the process. - ws 8.18.3 β 8.21.0 β CVE-2026-48779 β the receiver reassembled fragmented frames and tiny data chunks without a per-message size cap, allowing memory exhaustion from a stream of small messages.
CWE-457: Use of Uninitialized Variable
- ws 8.18.3 β 8.21.0 β CVE-2026-45736 β a buffer slice was returned to callers before being zeroed, leaking up to 124 bytes of adjacent heap content from a prior message in the same allocation region.
CWE-459: Incomplete Cleanup
- multer 2.1.1 β 2.2.0 β CVE-2026-5038 β aborted uploads left temporary files on disk; the cleanup path
was skipped when the request was destroyed before the
finishevent fired.
CWE-770: Allocation of Resources Without Limits or Throttling
- brace-expansion 5.0.6 β 5.0.7 β CVE-2026-45149 β a crafted large numeric range (e.g.
{1..999999999}) bypassed the documented DoS protection; the guard checked only the final count, not intermediate string lengths, so the per-item buffer could exhaust memory before the limit was tested.
CWE-1333: Inefficient Regular Expression Complexity
- js-yaml 4.1.1 β 5.2.1 β CVE-2026-53550 β YAML merge keys (
<<) with repeated alias references caused O(nΒ²) work during parsing; a payload under 10 KB could delay processing by several seconds.
v1.4.1 (from v1.4.0) β hotfix
CWE-400: Uncontrolled Resource Consumption
- brace-expansion 5.0.7 β 5.0.9 β CVE-2026-14257 (GHSA-mh99-v99m-4gvg) β brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash
- brace-expansion 5.0.7 β 5.0.9 β CVE-2026-13149 (GHSA-3jxr-9vmj-r5cp) β
- brace-expansion 5.0.7 β 5.0.9 β CVE-2026-69152 (GHSA-rgw5-rvv9-x895) β brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
CWE-407: Inefficient Algorithmic Complexity
- brace-expansion 5.0.7 β 5.0.9 β CVE-2026-13149 (GHSA-3jxr-9vmj-r5cp) β
- js-yaml 5.2.1 β 5.2.2 β CVE-2026-73643 (GHSA-pm4m-ph32-ghv5) β js-yaml: Exponential parsing time in the flow collections leads to denial of service
CWE-436: Interpretation Conflict
- fast-uri 3.1.3 β 3.1.4 β CVE-2026-16221 (GHSA-v2hh-gcrm-f6hx) β fast-uri vulnerable to host confusion via literal backslash authority delimiter (devDep)
CWE-770: Allocation of Resources Without Limits or Throttling
- brace-expansion 5.0.7 β 5.0.9 β CVE-2026-14257 (GHSA-mh99-v99m-4gvg) β brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash
- brace-expansion 5.0.7 β 5.0.9 β CVE-2026-69152 (GHSA-rgw5-rvv9-x895) β brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
- body-parser 1.20.5 β 1.20.6 β CVE-2026-12590 (GHSA-v422-hmwv-36x6) β body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
CWE-776: Improper Restriction of Recursive Entity References in DTDs (βXML Entity Expansionβ)
- fast-xml-parser 5.10.0 β 5.10.1 β CVE-2026-73569 (GHSA-8r6m-32jq-jx6q) β fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
v1.4.2 (from v1.4.1) β hotfix tag off v1.4.1
CWE-20: Improper Input Validation
- ip-address 10.2.0 β 10.5.0 β CVE-2026-69192 (GHSA-mwp4-54f8-5fhr) β ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
- ip-address 10.2.0 β 10.5.0 β CVE-2026-54272 (GHSA-22jq-vg5j-6vgg) β ip-address: Misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
- ip-address 10.2.0 β 10.5.0 β CVE-2026-69198 (GHSA-4xrf-jv44-h6hh) β ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
- socket.io-parser 4.2.6 β 4.2.7 β CVE-2026-69185 (GHSA-2m8v-j782-fhvr) β Socket.IO: Zero-attachment Memory Exhaustion
CWE-754: Improper Check for Unusual or Exceptional Conditions
- socket.io-parser 4.2.6 β 4.2.7 β CVE-2026-69185 (GHSA-2m8v-j782-fhvr) β Socket.IO: Zero-attachment Memory Exhaustion
CWE-918: Server-Side Request Forgery (SSRF)
- ip-address 10.2.0 β 10.5.0 β CVE-2026-69192 (GHSA-mwp4-54f8-5fhr) β ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
- ip-address 10.2.0 β 10.5.0 β CVE-2026-54272 (GHSA-22jq-vg5j-6vgg) β ip-address: Misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
- ip-address 10.2.0 β 10.5.0 β CVE-2026-69198 (GHSA-4xrf-jv44-h6hh) β ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
v1.5.0 (from v1.4.2)
proxy-addr 2.0.7 β 2.0.8 (CVE-2026-90711, CRITICAL) is not yet indexed by OSV.dev, so it carries no CWE here; the Docker base-image fixes (#1113) are OS packages, outside this npm report.
CWE-20: Improper Input Validation
- fast-uri 3.1.4 β 3.1.7 β CVE-2026-75975 (GHSA-f65p-4m7j-42xc) β fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (βPath Traversalβ)
- postcss 8.5.18 β 8.5.28 β CVE-2026-69153 (GHSA-fxqj-rqcc-2cmp) β PostCSS: incomplete fix of CVE-2026-45623 β attacker-controlled sourceMappingURL reads arbitrary .map files when
fromis unset (devDep) - vitest / @vitest/mocker 4.1.10 β 5.0.1 β CVE-2026-84373 (GHSA-82fw-gwwq-j7x9) β Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock (devDep)
CWE-116: Improper Encoding or Escaping of Output
- fast-uri 3.1.4 β 3.1.7 β CVE-2026-84292 (GHSA-qw65-cvwx-89v3) β fast-uri vulnerable to authority injection via an unvalidated port in serialize
CWE-174: Double Decoding of the Same Data
- fast-uri 3.1.4 β 3.1.7 β CVE-2026-75899 (GHSA-fph4-wmhf-6fwf) β fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
CWE-177: Improper Handling of URL Encoding (Hex Encoding)
- fast-uri 3.1.4 β 3.1.7 β CVE-2026-76172 (GHSA-jqff-g426-hqxp) β fast-uri vulnerable to host confusion via percent-encoded scheme normalization
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- postcss 8.5.18 β 8.5.28 β CVE-2026-69153 (GHSA-fxqj-rqcc-2cmp) β PostCSS: incomplete fix of CVE-2026-45623 β attacker-controlled sourceMappingURL reads arbitrary .map files when
fromis unset (devDep)
CWE-248: Uncaught Exception
- multer 2.2.0 β 2.4.0 β CVE-2026-77078 (GHSA-wc9g-mqfw-jrwm) β multer vulnerable to Denial of Service via crafted multipart field names
- qs 6.15.2 β 6.16.0 β CVE-2026-82417 (GHSA-4mjr-xmp4-gh2g) β qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property
- undici 8.10.0 β 8.10.2 β CVE-2026-85024 (GHSA-3wwx-pv8p-q78v) β undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
- browserslist 4.28.4 β 4.28.9 β CVE-2026-73088 (GHSA-73wf-gq98-2v4g) β Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) (devDep)
- undici (node-gyp) 6.28.0 β 6.29.0 β CVE-2026-85024 (GHSA-3wwx-pv8p-q78v) β undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression (devDep)
CWE-362: Race Condition
- multer 2.2.0 β 2.4.0 β CVE-2026-77063 (GHSA-qvfw-j98x-7q72) β multer vulnerable to file size limit bypass via async fileFilter race condition
CWE-400: Uncontrolled Resource Consumption
- multer 2.2.0 β 2.4.0 β CVE-2026-82333 (GHSA-535w-7cp7-47q4) β multer vulnerable to Denial of Service via oversized array index in field names
- multer 2.2.0 β 2.4.0 β CVE-2026-77037 (GHSA-qfvm-cv95-jqjf) β multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
- multer 2.2.0 β 2.4.0 β CVE-2026-88932 (GHSA-3pph-fpjx-jg34) β multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
- js-yaml 4.3.0 β 4.3.2 β CVE-2026-84375 (GHSA-2883-xcg3-v3hh) β js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources (devDep)
CWE-407: Inefficient Algorithmic Complexity
- js-yaml 4.3.0 β 4.3.2 β GHSA-5p4m-2wfm-xmqj β JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) β CVE-2026-59870 fix not backported (devDep)
- js-yaml 4.3.0 β 4.3.2 β CVE-2026-84375 (GHSA-2883-xcg3-v3hh) β js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources (devDep)
CWE-436: Interpretation Conflict
- fast-uri 3.1.4 β 3.1.7 β CVE-2026-18446 (GHSA-7p8r-x3mc-p8w7) β fast-uri vulnerable to host confusion via backslash authority introducer
- fast-uri 3.1.4 β 3.1.7 β CVE-2026-75931 (GHSA-5jgf-p345-68v8) β fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
CWE-459: Incomplete Cleanup
- multer 2.2.0 β 2.4.0 β CVE-2026-77037 (GHSA-qfvm-cv95-jqjf) β multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
- multer 2.2.0 β 2.4.0 β CVE-2026-88932 (GHSA-3pph-fpjx-jg34) β multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
CWE-697: Incorrect Comparison
- ip-address 10.5.0 β 10.7.2 β CVE-2026-101913 (GHSA-rpw4-54j3-4h4q) β ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
CWE-703: Improper Check or Handling of Exceptional Conditions
- qs 6.15.2 β 6.16.0 β CVE-2026-82417 (GHSA-4mjr-xmp4-gh2g) β qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property
CWE-705: Incorrect Control Flow Scoping
- baseline-browser-mapping 2.10.40 β 2.11.21 β CVE-2026-45819 (GHSA-w5vr-8v7q-w6rv) β (devDep)
CWE-755: Improper Handling of Exceptional Conditions
- baseline-browser-mapping 2.10.40 β 2.11.21 β CVE-2026-45819 (GHSA-w5vr-8v7q-w6rv) β (devDep)
CWE-770: Allocation of Resources Without Limits or Throttling
- qs 6.15.2 β 6.16.0 β CVE-2026-82562 (GHSA-x5fp-wj9c-mxmx) β qs.parse does not enforce arrayLimit on comma groups under bracket-push keys when throwOnLimitExceeded is set (incomplete fix for CVE-2026-2391)
- browserslist 4.28.4 β 4.28.9 β CVE-2026-73089 (GHSA-c83g-rgw3-j3cx) β Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM (devDep)
CWE-835: Loop with Unreachable Exit Condition (βInfinite Loopβ)
- nanoid 3.3.12 β 3.3.18 β CVE-2026-67214 (GHSA-28wg-ghj8-5hjv) β nanoid Infinite Loop via Negative Size in non-secure module (devDep)
- nanoid 3.3.12 β 3.3.18 β CVE-2026-67213 (GHSA-2v37-7h3g-55p8) β nanoid before 5.1.6 Infinite Loop via Zero Size in customAlphabet and customRandom (devDep)
CWE-918: Server-Side Request Forgery (SSRF)
- fast-uri 3.1.4 β 3.1.7 β CVE-2026-75975 (GHSA-f65p-4m7j-42xc) β fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
- fast-uri 3.1.4 β 3.1.7 β CVE-2026-75899 (GHSA-fph4-wmhf-6fwf) β fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
- ip-address 10.5.0 β 10.7.2 β CVE-2026-101913 (GHSA-rpw4-54j3-4h4q) β ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
- ip-address 10.5.0 β 10.7.2 β CVE-2026-101910 (GHSA-2vr4-cq9g-pvrc) β ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (βPrototype Pollutionβ)
- browserslist 4.28.4 β 4.28.9 β CVE-2026-73088 (GHSA-73wf-gq98-2v4g) β Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) (devDep)
Footnote: devDependencies (build-time only, not shipped to production)
The CWE entries marked (devDep) above apply only to tooling that runs at build time (Vite, esbuild, secretlint). They donβt affect the deployed server. Included for completeness sonpm audit is fully clean.
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (devDep)
- esbuild 0.27.2 β 0.27.3 (v1.2.1) β GHSA-g7r4-m6w7-qqqr β the esbuild dev server served arbitrary files
outside the configured root on Windows when path traversal sequences were used in asset requests. Fixed
properly in 0.28.1 (v1.4.0). A separate advisory (GHSA-67mh-4wv8-2f99) in the
@esbuild-kit/core-utilsnested copy covered permissive cross-origin request handling (related CWE-942). - vite 5.4.21 β 8.0.9 (v1.3.0) β CVE-2026-39365 β path traversal in optimised-deps
.maphandling (build-time only).
To regenerate this report, run
node scripts/cwe-report.mjs after fetching all v* tags (git fetch --tags).
To save a specific range: node scripts/cwe-report.mjs v1.3.0 v1.4.0. OSV.dev is queried live; network access
is required.