π [IBM OSPO Security Notification] β IBM/WxPackageCompatibilityAnalyzer
Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.
SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β
they will never trigger warnings or archiving.
π‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β Advanced Security β Dependabot security updates β Enable.
π New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.
Attention: @kalpshekhar-ibm
Dependabot Alerts
| Severity |
CVE/GHSA |
Package |
Affected |
Patched |
Deadline |
Fix PR |
| π high |
CVE-2025-12816 |
node-forge |
< 1.3.2 |
1.3.2 |
2026-10-18 |
β |
| π high |
CVE-2025-66035 |
@angular/common |
< 19.2.16 |
19.2.16 |
2026-10-18 |
β |
| π high |
CVE-2025-66412 |
@angular/compiler |
<= 18.2.14 |
β |
2026-10-18 |
β |
| π high |
CVE-2026-22610 |
@angular/compiler |
<= 18.2.14 |
β |
2026-10-18 |
β |
| π high |
CVE-2026-23745 |
tar |
<= 7.5.2 |
7.5.3 |
2026-10-18 |
β |
| π high |
CVE-2026-23950 |
tar |
<= 7.5.3 |
7.5.4 |
2026-10-18 |
β |
| π high |
CVE-2026-24842 |
tar |
< 7.5.7 |
7.5.7 |
2026-10-18 |
β |
| π high |
CVE-2026-26960 |
tar |
< 7.5.8 |
7.5.8 |
2026-10-18 |
β |
| π high |
CVE-2026-27903 |
minimatch |
>= 5.0.0, < 5.1.8 |
5.1.8 |
2026-10-18 |
β |
| π high |
CVE-2026-27970 |
@angular/core |
<= 18.2.14 |
β |
2026-10-18 |
β |
| π high |
GHSA-5c6j-r48x-rmvq |
serialize-javascript |
<= 7.0.2 |
7.0.3 |
2026-10-18 |
β |
| π high |
CVE-2026-29786 |
tar |
<= 7.5.9 |
7.5.10 |
2026-10-18 |
β |
| π high |
CVE-2026-29063 |
immutable |
>= 4.0.0-rc.1, < 4.3.8 |
4.3.8 |
2026-10-18 |
β |
| π high |
CVE-2026-31802 |
tar |
<= 7.5.10 |
7.5.11 |
2026-10-18 |
β |
| π high |
CVE-2026-33228 |
flatted |
<= 3.4.1 |
3.4.2 |
2026-10-18 |
β |
| π high |
CVE-2026-33894 |
node-forge |
< 1.4.0 |
1.4.0 |
2026-10-18 |
β |
| π high |
CVE-2026-33895 |
node-forge |
< 1.4.0 |
1.4.0 |
2026-10-18 |
β |
| π high |
CVE-2026-33896 |
node-forge |
<= 1.3.3 |
1.4.0 |
2026-10-18 |
β |
| π high |
CVE-2026-4800 |
lodash |
>= 4.0.0, <= 4.17.23 |
4.18.0 |
2026-10-18 |
β |
| π high |
CVE-2026-44728 |
@babel/plugin-transform-modules-systemjs |
>= 7.12.0, <= 7.29.3 |
7.29.4 |
2026-10-18 |
β |
| π high |
CVE-2026-44705 |
tmp |
< 0.2.6 |
0.2.6 |
2026-10-18 |
β |
| π high |
CVE-2026-55388 |
piscina |
<= 4.9.2 |
4.9.3 |
2026-10-18 |
β |
| π high |
CVE-2026-50171 |
@angular/common |
<= 18.2.14 |
β |
2026-10-18 |
β |
| π high |
CVE-2026-54266 |
@angular/common |
<= 19.2.25 |
β |
2026-10-18 |
β |
| π high |
CVE-2026-54267 |
@angular/core |
<= 19.2.25 |
β |
2026-10-18 |
β |
| π high |
CVE-2026-50170 |
@angular/common |
<= 18.2.14 |
β |
2026-10-18 |
β |
| π high |
CVE-2026-59725 |
engine.io |
>= 4.1.0, < 6.6.7 |
6.6.7 |
2026-10-18 |
β |
| π high |
CVE-2026-59869 |
js-yaml |
>= 3.0.0, < 3.15.0 |
3.15.0 |
2026-10-18 |
β |
| π high |
CVE-2026-13149 |
brace-expansion |
< 1.1.16 |
1.1.16 |
2026-10-18 |
β |
| π high |
CVE-2026-45623 |
postcss |
<= 8.5.11 |
8.5.12 |
2026-10-18 |
β |
| π high |
CVE-2026-73646 |
postcss |
<= 8.5.17 |
8.5.18 |
2026-10-18 |
β |
| π high |
CVE-2026-69185 |
socket.io-parser |
>= 4.0.0, < 4.2.7 |
4.2.7 |
2026-10-18 |
β |
| π high |
CVE-2026-68945 |
@angular/common |
<= 19.2.25 |
β |
2026-10-18 |
β |
| π high |
CVE-2026-69151 |
@angular/compiler |
<= 19.2.25 |
β |
2026-10-18 |
β |
| π high |
GHSA-5p4m-2wfm-xmqj |
js-yaml |
>= 3.0.0, < 3.15.1 |
3.15.1 |
2026-10-18 |
β |
| π high |
CVE-2026-73088 |
browserslist |
<= 4.28.6 |
4.28.7 |
2026-10-18 |
β |
| π high |
CVE-2026-59880 |
immutable |
>= 4.0.0-beta.1, < 4.3.9 |
4.3.9 |
2026-10-15 |
β |
| π high |
CVE-2026-73086 |
nanoid |
< 3.3.12 |
3.3.12 |
2026-10-15 |
β |
| π high |
CVE-2026-84375 |
js-yaml |
>= 3.0.0, < 3.15.2 |
3.15.2 |
2026-10-12 |
β |
| π high |
CVE-2026-59879 |
immutable |
>= 4.0.0-rc.1, < 4.3.9 |
4.3.9 |
2026-10-18 |
β |
| π‘ medium |
CVE-2025-64718 |
js-yaml |
< 3.14.2 |
3.14.2 |
2026-12-17 |
β |
| π‘ medium |
CVE-2025-66030 |
node-forge |
< 1.3.2 |
1.3.2 |
2026-12-17 |
β |
| π‘ medium |
CVE-2025-15284 |
qs |
< 6.14.1 |
6.14.1 |
2026-12-17 |
β |
| π‘ medium |
CVE-2025-13465 |
lodash |
>= 4.0.0, <= 4.17.22 |
4.17.23 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-33672 |
picomatch |
< 2.3.2 |
2.3.2 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-2950 |
lodash |
<= 4.17.23 |
4.18.0 |
2026-12-17 |
β |
| π‘ medium |
GHSA-r4q5-vmmm-2653 |
follow-redirects |
<= 1.15.11 |
1.16.0 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-6402 |
webpack-dev-server |
<= 5.2.3 |
5.2.4 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-34043 |
serialize-javascript |
>= 5.0.0, < 7.0.5 |
7.0.5 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-41907 |
uuid |
< 11.1.1 |
11.1.1 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-41305 |
postcss |
< 8.5.10 |
8.5.10 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-50557 |
@angular/core |
<= 18.2.14 |
β |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-54265 |
@angular/compiler |
<= 19.2.25 |
β |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-53655 |
tar |
<= 7.5.15 |
7.5.16 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-52725 |
@angular/core |
<= 18.2.14 |
β |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-59871 |
tar |
<= 7.5.17 |
7.5.18 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-14631 |
webpack-dev-server |
<= 5.2.5 |
5.2.6 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-14620 |
webpack-dev-server |
<= 5.2.5 |
5.2.6 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-69153 |
postcss |
<= 8.5.22 |
8.5.23 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-45822 |
decode-uri-component |
<= 0.4.2 |
0.5.0 |
2026-12-17 |
β |
| π‘ medium |
CVE-2026-88059 |
@angular/common |
<= 19.2.25 |
β |
2026-12-11 |
β |
| π‘ medium |
CVE-2026-88057 |
@angular/compiler |
<= 19.2.25 |
β |
2026-12-11 |
β |
| π΅ low |
CVE-2025-7339 |
on-headers |
< 1.1.0 |
1.1.0 |
β |
β |
| π΅ low |
CVE-2025-54798 |
tmp |
<= 0.2.3 |
0.2.4 |
β |
β |
| π΅ low |
CVE-2025-68458 |
webpack |
>= 5.49.0, <= 5.104.0 |
5.104.1 |
β |
β |
| π΅ low |
CVE-2025-68157 |
webpack |
>= 5.49.0, < 5.104.0 |
5.104.0 |
β |
β |
| π΅ low |
CVE-2026-2391 |
qs |
>= 6.7.0, <= 6.14.1 |
6.14.2 |
β |
β |
| π΅ low |
CVE-2026-3449 |
@tootallnate/once |
< 2.0.1 |
2.0.1 |
β |
β |
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.
π [IBM OSPO Security Notification] β IBM/WxPackageCompatibilityAnalyzer
Attention: @kalpshekhar-ibm
Dependabot Alerts
Code Scanning Alerts
No open code scanning alerts.
Secret Scanning Alerts
No open secret scanning alerts.