Skip to content

Dependency audit: remediate 0 critical / 4 high vulnerabilities #136

@breynol01

Description

@breynol01

Dependency audit run on 2026-03-12 found actionable npm vulnerabilities.

Summary

  • Total vulnerabilities: 4
  • Critical: 0
  • High: 4
  • Moderate: 0
  • Low: 0

Notable vulnerable packages

  • @hono/node-server (high) — @hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware; fix available
  • express-rate-limit (high) — express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network; fix available
  • hono (high) — Hono added timing comparison hardening in basicAuth and bearerAuth; fix available
  • tar (high) — tar has Hardlink Path Traversal via Drive-Relative Linkpath; fix available

Also outdated

  • npm outdated found 9 package(s) behind the latest release

Suggested next steps

  1. Upgrade direct dependencies that pull in the vulnerable packages
  2. Rebuild lockfile and rerun npm audit
  3. Smoke-test build/runtime paths after upgrades, especially where fixes require semver-major jumps

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions