Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 50 additions & 2 deletions docs/multiple-tests/pattern-vulnerability-high/results.xml
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,12 @@
message="Insecure dependency golang/stdlib@v1.22.0 (CVE-2026-33814: net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame) (update to 1.25.10)"
severity="high"
/>
<error
source="vulnerability_high"
line="3"
message="Insecure dependency golang/stdlib@v1.22.0 (CVE-2026-33818: encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal) (update to 1.25.13)"
severity="high"
/>
<error
source="vulnerability_high"
line="3"
Expand All @@ -84,13 +90,19 @@
<error
source="vulnerability_high"
line="3"
message="Insecure dependency golang/stdlib@v1.22.0 (CVE-2026-39822: os: golang: Go os.Root: Symlink following vulnerability allows directory traversal) (update to 1.25.12)"
message="Insecure dependency golang/stdlib@v1.22.0 (CVE-2026-39821: golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing) (update to 1.25.13)"
severity="high"
/>
<error
source="vulnerability_high"
line="3"
message="Insecure dependency golang/stdlib@v1.22.0 (CVE-2026-39822: golang: Go os.Root: Symlink following vulnerability allows directory traversal) (update to 1.25.12)"
severity="high"
/>
<error
source="vulnerability_high"
line="3"
message="Insecure dependency golang/stdlib@v1.22.0 (CVE-2026-39836: ELSA-2026-22121: golang security update (IMPORTANT)) (update to 1.25.10)"
message="Insecure dependency golang/stdlib@v1.22.0 (CVE-2026-39836: net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows) (update to 1.25.10)"
severity="high"
/>
<error
Expand All @@ -105,6 +117,36 @@
message="Insecure dependency golang/stdlib@v1.22.0 (CVE-2026-42504: mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header) (update to 1.25.11)"
severity="high"
/>
<error
source="vulnerability_high"
line="3"
message="Insecure dependency golang/stdlib@v1.22.0 (CVE-2026-56853: net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service) (update to 1.25.13)"
severity="high"
/>
<error
source="vulnerability_high"
line="3"
message="Insecure dependency golang/stdlib@v1.22.0 (CVE-2026-56858: html/template: golang: Go html/template: Cross-Site Scripting via pathological input) (update to 1.25.13)"
severity="high"
/>
<error
source="vulnerability_high"
line="3"
message="Insecure dependency golang/stdlib@v1.22.0 (CVE-2026-56859: encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue) (update to 1.25.13)"
severity="high"
/>
<error
source="vulnerability_high"
line="3"
message="Insecure dependency golang/stdlib@v1.22.0 (CVE-2026-56860: net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution) (update to 1.25.13)"
severity="high"
/>
<error
source="vulnerability_high"
line="3"
message="Insecure dependency golang/stdlib@v1.22.0 (CVE-2026-56862: crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages) (update to 1.25.13)"
severity="high"
/>
<error
source="vulnerability_high"
line="5"
Expand Down Expand Up @@ -135,6 +177,12 @@
message="Insecure dependency golang/golang.org/x/net@v0.25.0 (CVE-2026-39821: golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing) (update to 0.55.0)"
severity="high"
/>
<error
source="vulnerability_high"
line="5"
message="Insecure dependency golang/golang.org/x/net@v0.25.0 (CVE-2026-46600: golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing) (update to 0.56.0)"
severity="high"
/>
<error
source="vulnerability_high"
line="7"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -406,13 +406,13 @@
<error
source="vulnerability_medium"
line="14"
message="Insecure dependency npm/axios@0.21.0 (GHSA-7q8q-rj6j-mhjq: Axios: Nested axios option objects can consume polluted prototype values) (update to 0.33.0)"
message="Insecure dependency npm/axios@0.21.0 (CVE-2026-67316: axios: axios: Prototype Pollution allows unauthorized data transmission and network redirection) (update to 0.33.0)"
severity="warning"
/>
<error
source="vulnerability_medium"
line="14"
message="Insecure dependency npm/axios@0.21.0 (GHSA-mmx7-hfxf-jppx: Axios: Prototype pollution gadgets can alter axios request construction) (update to 0.33.0)"
message="Insecure dependency npm/axios@0.21.0 (CVE-2026-67319: axios: axios: Information disclosure and data manipulation via prototype pollution) (update to 0.33.0)"
severity="warning"
/>
<error
Expand Down Expand Up @@ -492,13 +492,13 @@
<error
source="vulnerability_medium"
line="5"
message="Insecure dependency npm/axios@0.21.0 (GHSA-7q8q-rj6j-mhjq: Axios: Nested axios option objects can consume polluted prototype values) (update to 0.33.0)"
message="Insecure dependency npm/axios@0.21.0 (CVE-2026-67316: axios: axios: Prototype Pollution allows unauthorized data transmission and network redirection) (update to 0.33.0)"
severity="warning"
/>
<error
source="vulnerability_medium"
line="5"
message="Insecure dependency npm/axios@0.21.0 (GHSA-mmx7-hfxf-jppx: Axios: Prototype pollution gadgets can alter axios request construction) (update to 0.33.0)"
message="Insecure dependency npm/axios@0.21.0 (CVE-2026-67319: axios: axios: Information disclosure and data manipulation via prototype pollution) (update to 0.33.0)"
severity="warning"
/>
<error
Expand Down