{
  "schema_version": 1,
  "app_id": "io.thepeoples.Joplin",
  "slug": "joplin",
  "version": "3.6.16",
  "scanned_at": "2026-09-02T01:42:36Z",
  "scanner": {
    "name": "trivy",
    "version": "0.73.0",
    "db_updated_at": "2026-09-01T19:20:44Z"
  },
  "input": {
    "kind": "deb",
    "filename": "Joplin-3.6.16.deb",
    "sha256": "1b7f42d2ee978b1adf5cd95b8880b48769f42e3135076632392192022e300e7d",
    "extracted_without_scripts": true
  },
  "gate": {
    "result": "pass",
    "fail_on": "wrap CRITICAL"
  },
  "counts": {
    "wrap": {
      "critical": 0,
      "high": 0,
      "medium": 0,
      "low": 0,
      "unknown": 0
    },
    "vendor": {
      "critical": 6,
      "high": 54,
      "medium": 16,
      "low": 5,
      "unknown": 0
    }
  },
  "coverage": {
    "packages_seen": 302,
    "wrap": {
      "status": "inventoried",
      "packages_seen": 0,
      "notes": []
    },
    "vendor": {
      "status": "inventoried",
      "packages_seen": 302,
      "notes": [
        "electron asar",
        "read 226 package.json file(s)",
        "trivy sbom on 192 derived PURLs"
      ]
    }
  },
  "findings": [
    {
      "id": "CVE-2017-16137",
      "severity": "LOW",
      "pkg": "debug",
      "installed": "4.1.0",
      "fixed": "2.6.9, 3.1.0, 3.2.7, 4.3.1",
      "class": "vendor",
      "title": "nodejs-debug: Regular expression Denial of Service"
    },
    {
      "id": "CVE-2020-7598",
      "severity": "MEDIUM",
      "pkg": "minimist",
      "installed": "1.2.0",
      "fixed": "0.2.1, 1.2.3",
      "class": "vendor",
      "title": "nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload"
    },
    {
      "id": "CVE-2020-7788",
      "severity": "HIGH",
      "pkg": "ini",
      "installed": "1.3.0",
      "fixed": "1.3.6",
      "class": "vendor",
      "title": "nodejs-ini: Prototype pollution via malicious INI file"
    },
    {
      "id": "CVE-2021-27290",
      "severity": "HIGH",
      "pkg": "ssri",
      "installed": "8.0.0",
      "fixed": "6.0.2, 7.1.1, 8.0.1",
      "class": "vendor",
      "title": "nodejs-ssri: Regular expression DoS (ReDoS) when parsing malicious SRI in strict mode"
    },
    {
      "id": "CVE-2021-32803",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "3.2.3, 4.4.15, 5.0.7, 6.1.2",
      "class": "vendor",
      "title": "nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite"
    },
    {
      "id": "CVE-2021-32804",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "3.2.2, 4.4.14, 5.0.6, 6.1.1",
      "class": "vendor",
      "title": "nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite"
    },
    {
      "id": "CVE-2021-37701",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "4.4.16, 5.0.8, 6.1.7",
      "class": "vendor",
      "title": "nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite"
    },
    {
      "id": "CVE-2021-37701",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "4.4.16, 5.0.8, 6.1.7",
      "class": "vendor",
      "title": "nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite"
    },
    {
      "id": "CVE-2021-37712",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "4.4.18, 5.0.10, 6.1.9",
      "class": "vendor",
      "title": "nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite"
    },
    {
      "id": "CVE-2021-37712",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "4.4.18, 5.0.10, 6.1.9",
      "class": "vendor",
      "title": "nodejs-tar: Insufficient symlink protection due to directory cache poisoning using symbolic links allowing arbitrary file creation and overwrite"
    },
    {
      "id": "CVE-2021-37713",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "4.4.18, 5.0.10, 6.1.9",
      "class": "vendor",
      "title": "nodejs-tar: Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization"
    },
    {
      "id": "CVE-2021-37713",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "4.4.18, 5.0.10, 6.1.9",
      "class": "vendor",
      "title": "nodejs-tar: Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization"
    },
    {
      "id": "CVE-2021-44906",
      "severity": "CRITICAL",
      "pkg": "minimist",
      "installed": "1.2.0",
      "fixed": "1.2.6, 0.2.4",
      "class": "vendor",
      "title": "minimist: prototype pollution"
    },
    {
      "id": "CVE-2021-44906",
      "severity": "CRITICAL",
      "pkg": "minimist",
      "installed": "1.2.3",
      "fixed": "1.2.6, 0.2.4",
      "class": "vendor",
      "title": "minimist: prototype pollution"
    },
    {
      "id": "CVE-2021-44906",
      "severity": "CRITICAL",
      "pkg": "minimist",
      "installed": "1.2.5",
      "fixed": "1.2.6, 0.2.4",
      "class": "vendor",
      "title": "minimist: prototype pollution"
    },
    {
      "id": "CVE-2022-0355",
      "severity": "HIGH",
      "pkg": "simple-get",
      "installed": "4.0.0",
      "fixed": "4.0.1, 3.1.1, 2.8.2",
      "class": "vendor",
      "title": "simple-get: exposure of sensitive information to an unauthorized actor"
    },
    {
      "id": "CVE-2022-24713",
      "severity": "HIGH",
      "pkg": "regex",
      "installed": "1.4.6",
      "fixed": "1.5.5",
      "class": "vendor",
      "title": "Mozilla: Denial of Service via complex regular expressions"
    },
    {
      "id": "CVE-2022-25881",
      "severity": "HIGH",
      "pkg": "http-cache-semantics",
      "installed": "4.1.0",
      "fixed": "4.1.1",
      "class": "vendor",
      "title": "http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability"
    },
    {
      "id": "CVE-2022-25883",
      "severity": "HIGH",
      "pkg": "semver",
      "installed": "6.0.0",
      "fixed": "7.5.2, 6.3.1, 5.7.2",
      "class": "vendor",
      "title": "nodejs-semver: Regular expression denial of service"
    },
    {
      "id": "CVE-2022-25883",
      "severity": "HIGH",
      "pkg": "semver",
      "installed": "7.3.5",
      "fixed": "7.5.2, 6.3.1, 5.7.2",
      "class": "vendor",
      "title": "nodejs-semver: Regular expression denial of service"
    },
    {
      "id": "CVE-2022-3517",
      "severity": "HIGH",
      "pkg": "minimatch",
      "installed": "3.0.4",
      "fixed": "3.0.5",
      "class": "vendor",
      "title": "nodejs-minimatch: ReDoS via the braceExpand function"
    },
    {
      "id": "CVE-2023-42282",
      "severity": "LOW",
      "pkg": "ip",
      "installed": "1.1.5",
      "fixed": "2.0.1, 1.1.9",
      "class": "vendor",
      "title": "nodejs-ip: arbitrary code execution via the isPublic() function"
    },
    {
      "id": "CVE-2024-12905",
      "severity": "HIGH",
      "pkg": "tar-fs",
      "installed": "2.0.0",
      "fixed": "1.16.4, 2.1.2, 3.0.7",
      "class": "vendor",
      "title": "tar-fs: link following and path traversal via maliciously crafted tar file"
    },
    {
      "id": "CVE-2024-28863",
      "severity": "MEDIUM",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "6.2.1",
      "class": "vendor",
      "title": "node-tar: denial of service while parsing a tar file due to lack of folders depth validation"
    },
    {
      "id": "CVE-2024-28863",
      "severity": "MEDIUM",
      "pkg": "tar",
      "installed": "6.1.11",
      "fixed": "6.2.1",
      "class": "vendor",
      "title": "node-tar: denial of service while parsing a tar file due to lack of folders depth validation"
    },
    {
      "id": "CVE-2024-28863",
      "severity": "MEDIUM",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "6.2.1",
      "class": "vendor",
      "title": "node-tar: denial of service while parsing a tar file due to lack of folders depth validation"
    },
    {
      "id": "CVE-2024-29415",
      "severity": "HIGH",
      "pkg": "ip",
      "installed": "1.1.5",
      "fixed": "",
      "class": "vendor",
      "title": "node-ip: Incomplete fix for CVE-2023-42282"
    },
    {
      "id": "CVE-2025-48387",
      "severity": "HIGH",
      "pkg": "tar-fs",
      "installed": "2.0.0",
      "fixed": "1.16.5, 2.1.3, 3.0.9",
      "class": "vendor",
      "title": "tar-fs: tar-fs has issue where extract can write outside the specified dir with a specific tarball"
    },
    {
      "id": "CVE-2025-58160",
      "severity": "LOW",
      "pkg": "tracing-subscriber",
      "installed": "0.2.25",
      "fixed": "0.3.20",
      "class": "vendor",
      "title": "tracing-subscriber: Tracing log pollution"
    },
    {
      "id": "CVE-2025-5889",
      "severity": "LOW",
      "pkg": "brace-expansion",
      "installed": "1.1.7",
      "fixed": "2.0.2, 1.1.12, 3.0.1, 4.0.1",
      "class": "vendor",
      "title": "brace-expansion: juliangruber brace-expansion index.js expand redos"
    },
    {
      "id": "CVE-2025-59343",
      "severity": "HIGH",
      "pkg": "tar-fs",
      "installed": "2.0.0",
      "fixed": "3.1.1, 2.1.4, 1.16.6",
      "class": "vendor",
      "title": "tar-fs: tar-fs symlink validation bypass"
    },
    {
      "id": "CVE-2026-13149",
      "severity": "HIGH",
      "pkg": "brace-expansion",
      "installed": "1.1.7",
      "fixed": "5.0.7, 1.1.16, 2.1.2",
      "class": "vendor",
      "title": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity"
    },
    {
      "id": "CVE-2026-14257",
      "severity": "HIGH",
      "pkg": "brace-expansion",
      "installed": "1.1.7",
      "fixed": "5.0.8, 3.0.3, 2.1.3, 1.1.17",
      "class": "vendor",
      "title": "brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function"
    },
    {
      "id": "CVE-2026-23745",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "7.5.3",
      "class": "vendor",
      "title": "node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives"
    },
    {
      "id": "CVE-2026-23745",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.11",
      "fixed": "7.5.3",
      "class": "vendor",
      "title": "node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives"
    },
    {
      "id": "CVE-2026-23745",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "7.5.3",
      "class": "vendor",
      "title": "node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives"
    },
    {
      "id": "CVE-2026-23950",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "7.5.4",
      "class": "vendor",
      "title": "node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition"
    },
    {
      "id": "CVE-2026-23950",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.11",
      "fixed": "7.5.4",
      "class": "vendor",
      "title": "node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition"
    },
    {
      "id": "CVE-2026-23950",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "7.5.4",
      "class": "vendor",
      "title": "node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition"
    },
    {
      "id": "CVE-2026-24842",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "7.5.7",
      "class": "vendor",
      "title": "node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check"
    },
    {
      "id": "CVE-2026-24842",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.11",
      "fixed": "7.5.7",
      "class": "vendor",
      "title": "node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check"
    },
    {
      "id": "CVE-2026-24842",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "7.5.7",
      "class": "vendor",
      "title": "node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check"
    },
    {
      "id": "CVE-2026-25541",
      "severity": "MEDIUM",
      "pkg": "bytes",
      "installed": "1.10.1",
      "fixed": "1.11.1",
      "class": "vendor",
      "title": "Bytes is a utility library for working with bytes. From version 1.2.1  ..."
    },
    {
      "id": "CVE-2026-25547",
      "severity": "HIGH",
      "pkg": "@isaacs/brace-expansion",
      "installed": "5.0.0",
      "fixed": "5.0.1",
      "class": "vendor",
      "title": "brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion"
    },
    {
      "id": "CVE-2026-25727",
      "severity": "MEDIUM",
      "pkg": "time",
      "installed": "0.3.44",
      "fixed": "0.3.47",
      "class": "vendor",
      "title": "time: time affected by a stack exhaustion denial of service attack"
    },
    {
      "id": "CVE-2026-26960",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "7.5.8",
      "class": "vendor",
      "title": "node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation"
    },
    {
      "id": "CVE-2026-26960",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.11",
      "fixed": "7.5.8",
      "class": "vendor",
      "title": "node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation"
    },
    {
      "id": "CVE-2026-26960",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "7.5.8",
      "class": "vendor",
      "title": "node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation"
    },
    {
      "id": "CVE-2026-26996",
      "severity": "HIGH",
      "pkg": "minimatch",
      "installed": "10.1.1",
      "fixed": "10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3",
      "class": "vendor",
      "title": "minimatch: minimatch: Denial of Service via specially crafted glob patterns"
    },
    {
      "id": "CVE-2026-26996",
      "severity": "HIGH",
      "pkg": "minimatch",
      "installed": "3.0.4",
      "fixed": "10.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3",
      "class": "vendor",
      "title": "minimatch: minimatch: Denial of Service via specially crafted glob patterns"
    },
    {
      "id": "CVE-2026-27903",
      "severity": "HIGH",
      "pkg": "minimatch",
      "installed": "10.1.1",
      "fixed": "10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3",
      "class": "vendor",
      "title": "minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns"
    },
    {
      "id": "CVE-2026-27903",
      "severity": "HIGH",
      "pkg": "minimatch",
      "installed": "3.0.4",
      "fixed": "10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3",
      "class": "vendor",
      "title": "minimatch: minimatch: Denial of Service due to unbounded recursive backtracking via crafted glob patterns"
    },
    {
      "id": "CVE-2026-27904",
      "severity": "HIGH",
      "pkg": "minimatch",
      "installed": "10.1.1",
      "fixed": "10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4",
      "class": "vendor",
      "title": "minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions"
    },
    {
      "id": "CVE-2026-27904",
      "severity": "HIGH",
      "pkg": "minimatch",
      "installed": "3.0.4",
      "fixed": "10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4",
      "class": "vendor",
      "title": "minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions"
    },
    {
      "id": "CVE-2026-29786",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "7.5.10",
      "class": "vendor",
      "title": "node-tar: hardlink path traversal via drive-relative linkpath"
    },
    {
      "id": "CVE-2026-29786",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.11",
      "fixed": "7.5.10",
      "class": "vendor",
      "title": "node-tar: hardlink path traversal via drive-relative linkpath"
    },
    {
      "id": "CVE-2026-29786",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "7.5.10",
      "class": "vendor",
      "title": "node-tar: hardlink path traversal via drive-relative linkpath"
    },
    {
      "id": "CVE-2026-31802",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "7.5.11",
      "class": "vendor",
      "title": "tar: tar: File overwrite via drive-relative symlink traversal"
    },
    {
      "id": "CVE-2026-31802",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.11",
      "fixed": "7.5.11",
      "class": "vendor",
      "title": "tar: tar: File overwrite via drive-relative symlink traversal"
    },
    {
      "id": "CVE-2026-31802",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "7.5.11",
      "class": "vendor",
      "title": "tar: tar: File overwrite via drive-relative symlink traversal"
    },
    {
      "id": "CVE-2026-33750",
      "severity": "MEDIUM",
      "pkg": "brace-expansion",
      "installed": "1.1.7",
      "fixed": "5.0.5, 3.0.2, 2.0.3, 1.1.13",
      "class": "vendor",
      "title": "brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern"
    },
    {
      "id": "CVE-2026-53655",
      "severity": "MEDIUM",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "7.5.16",
      "class": "vendor",
      "title": "node-tar: node-tar: File smuggling due to inconsistent tar archive parsing"
    },
    {
      "id": "CVE-2026-53655",
      "severity": "MEDIUM",
      "pkg": "tar",
      "installed": "6.1.11",
      "fixed": "7.5.16",
      "class": "vendor",
      "title": "node-tar: node-tar: File smuggling due to inconsistent tar archive parsing"
    },
    {
      "id": "CVE-2026-53655",
      "severity": "MEDIUM",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "7.5.16",
      "class": "vendor",
      "title": "node-tar: node-tar: File smuggling due to inconsistent tar archive parsing"
    },
    {
      "id": "CVE-2026-59871",
      "severity": "MEDIUM",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "7.5.18",
      "class": "vendor",
      "title": "node-tar: node-tar: Denial of Service due to incorrect PAX path handling"
    },
    {
      "id": "CVE-2026-59871",
      "severity": "MEDIUM",
      "pkg": "tar",
      "installed": "6.1.11",
      "fixed": "7.5.18",
      "class": "vendor",
      "title": "node-tar: node-tar: Denial of Service due to incorrect PAX path handling"
    },
    {
      "id": "CVE-2026-59871",
      "severity": "MEDIUM",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "7.5.18",
      "class": "vendor",
      "title": "node-tar: node-tar: Denial of Service due to incorrect PAX path handling"
    },
    {
      "id": "CVE-2026-59873",
      "severity": "CRITICAL",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "7.5.19",
      "class": "vendor",
      "title": "tar: node-tar: Denial of Service via crafted gzip bomb"
    },
    {
      "id": "CVE-2026-59873",
      "severity": "CRITICAL",
      "pkg": "tar",
      "installed": "6.1.11",
      "fixed": "7.5.19",
      "class": "vendor",
      "title": "tar: node-tar: Denial of Service via crafted gzip bomb"
    },
    {
      "id": "CVE-2026-59873",
      "severity": "CRITICAL",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "7.5.19",
      "class": "vendor",
      "title": "tar: node-tar: Denial of Service via crafted gzip bomb"
    },
    {
      "id": "CVE-2026-59874",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "7.5.18",
      "class": "vendor",
      "title": "tar: Node-tar: Denial of Service via malformed tar archive header"
    },
    {
      "id": "CVE-2026-59874",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.11",
      "fixed": "7.5.18",
      "class": "vendor",
      "title": "tar: Node-tar: Denial of Service via malformed tar archive header"
    },
    {
      "id": "CVE-2026-59874",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "7.5.18",
      "class": "vendor",
      "title": "tar: Node-tar: Denial of Service via malformed tar archive header"
    },
    {
      "id": "CVE-2026-59875",
      "severity": "MEDIUM",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "7.5.17",
      "class": "vendor",
      "title": "node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata"
    },
    {
      "id": "CVE-2026-59875",
      "severity": "MEDIUM",
      "pkg": "tar",
      "installed": "6.1.11",
      "fixed": "7.5.17",
      "class": "vendor",
      "title": "node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata"
    },
    {
      "id": "CVE-2026-59875",
      "severity": "MEDIUM",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "7.5.17",
      "class": "vendor",
      "title": "node-tar: node-tar: Denial of Service via crafted archive with NUL bytes in metadata"
    },
    {
      "id": "CVE-2026-69152",
      "severity": "HIGH",
      "pkg": "brace-expansion",
      "installed": "1.1.7",
      "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
      "class": "vendor",
      "title": "brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation"
    },
    {
      "id": "CVE-2026-73566",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.0.2",
      "fixed": "7.5.21",
      "class": "vendor",
      "title": "tar: node-tar: Denial of Service via crafted long-path tar archive"
    },
    {
      "id": "CVE-2026-73566",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.11",
      "fixed": "7.5.21",
      "class": "vendor",
      "title": "tar: node-tar: Denial of Service via crafted long-path tar archive"
    },
    {
      "id": "CVE-2026-73566",
      "severity": "HIGH",
      "pkg": "tar",
      "installed": "6.1.2",
      "fixed": "7.5.21",
      "class": "vendor",
      "title": "tar: node-tar: Denial of Service via crafted long-path tar archive"
    },
    {
      "id": "GHSA-cq8v-f236-94qc",
      "severity": "LOW",
      "pkg": "rand",
      "installed": "0.7.3",
      "fixed": "0.9.3, 0.10.1, 0.8.6",
      "class": "vendor",
      "title": "Rand is unsound with a custom logger using rand::rng()"
    }
  ]
}
