Questarr — CVEs fixed per release (v1.2.0 → v1.5.0)
Method: diffedpackage.json/package-lock.json at each tag boundary, then cross-checked every bumped package through OSV.dev’s querybatch endpoint (query old-version vs new-version, take the set difference of returned GHSA IDs) and confirmed exact fixed boundaries via per-GHSA /v1/vulns/{id} lookups. All headline findings below — including axios, node-forge, and socket.io-parser — were verified through the same batch-diff method, not just by trusting commit messages. Only entries with a confirmed OSV fixed event landing inside the bump range are listed as fixes.
Scope note: newly-added dependencies (multer, passport, passport-steam, express-session, rss-parser, js-yaml, node-forge’s initial introduction) were checked for CVEs open at their pinned version only where a later bump partially fixed them (multer). Packages that arrived once and were never re-bumped weren’t separately audited for pre-existing CVEs unless flagged — this report covers fixes, not full current-exposure.
v1.2.0 (from v1.1.0)
- fast-xml-parser 5.3.3 → 5.3.4 — fixes CVE-2026-25128 (GHSA-37qj-frw5-hhjh, HIGH) — RangeError DoS via numeric entities.
v1.2.1 (from v1.2.0)
- fast-xml-parser 5.3.4 → 5.3.5 — fixes CVE-2026-25896 (GHSA-m7jm-9gc2-mpf2, CRITICAL) — entity-encoding bypass via regex injection in DOCTYPE entity names.
v1.2.2 (from v1.2.1)
- fast-xml-parser 5.3.5 → 5.3.7 — fixes CVE-2026-26278 (GHSA-jmr7-xgp7-cmfj, HIGH) — DoS via entity expansion in DOCTYPE (no expansion limit).
v1.3.0 (from v1.2.2) — largest security-relevant release
- fast-xml-parser 5.3.7 → 5.7.1 — fixes 4 CVEs:
- CVE-2026-33036 (GHSA-8gc5-j5rx-235r, HIGH) — numeric entity expansion bypassing all expansion limits (incomplete fix for CVE-2026-26278)
- CVE-2026-27942 (GHSA-fj3w-jwp8-x2g3, LOW) — stack overflow in XMLBuilder with
preserveOrder - CVE-2026-41650 (GHSA-gh4j-gqv2-49f6, MODERATE) — XML Comment/CDATA injection via unescaped delimiters
- CVE-2026-33349 (GHSA-jp2q-39xq-3w4g, MODERATE) — entity expansion limit bypassed when set to
0(JS falsy-evaluation bug)
- node-forge 1.3.3 → 1.4.0 — fixes 4 CVEs:
- CVE-2026-33896 (GHSA-2328-f5f3-gj25, HIGH) —
basicConstraints/RFC 5280 cert-chain validation bypass - CVE-2026-33891 (GHSA-5m6q-g25r-mvwx, HIGH) — DoS via
BigInteger.modInverse(0)infinite loop - CVE-2026-33894 (GHSA-ppp5-5v6c-4jwp, HIGH) — RSA-PKCS1 v1.5 signature forgery (Bleichenbacher-style)
- CVE-2026-33895 (GHSA-q67f-28xg-22rw, HIGH) — Ed25519 signature malleability (missing canonical-scalar check)
- CVE-2026-33896 (GHSA-2328-f5f3-gj25, HIGH) —
- socket.io-parser (npm
overridespin) 4.2.5 → 4.2.6 — fixes CVE-2026-33151 (GHSA-677m-j7p3-52f9, HIGH) — unbounded binary attachments DoS - drizzle-orm 0.45.1 → 0.45.2 — fixes CVE-2026-39356 (GHSA-gpj5-g38j-94v9, HIGH) — SQL injection via improperly escaped SQL identifiers
- express-rate-limit 8.2.1 → 8.3.2 — fixes CVE-2026-30827 (GHSA-46wh-pxpv-q5gq, HIGH) — IPv4-mapped IPv6 addresses bypass per-client rate limiting on dual-stack servers
- multer 2.0.2 → 2.1.1 — fixes 3 of 5 CVEs present since multer’s introduction in v1.2.1:
- CVE-2026-3520 (GHSA-5528-5vmv-3xc2, HIGH) — DoS via uncontrolled recursion
- CVE-2026-2359 (GHSA-v52c-386h-88mc, HIGH) — DoS via resource exhaustion
- CVE-2026-3304 (GHSA-xf7r-hgr6-v32p, HIGH) — DoS via incomplete cleanup
- ⚠️ Still open at 2.1.1 (fix requires multer ≥2.2.0, not yet adopted as of v1.3.1): CVE-2026-5038 (GHSA-3p4h-7m6x-2hcm, MODERATE) and CVE-2026-5079 (GHSA-72gw-mp4g-v24j, HIGH)
v1.3.1 (from v1.3.0)
No dependency bump in this release crosses afixed OSV boundary — purely maintenance/feature updates.
v1.4.0 (From v1.3.1)
- js-yaml 4.1.1 → 5.2.1 — fixes CVE-2026-53550 (GHSA-h67p-54hq-rp68, MODERATE) — quadratic-complexity DoS in merge-key handling via repeated aliases. (Three separate devDep-tooling nested copies — under
eslint’s@eslint/eslintrc,textlint’slinter-formatter, andrc-config-loader— resolve independently to4.3.0; that’s past the4.2.0fix boundary for this CVE, so they were never vulnerable and aren’t a fix to attribute.) - multer 2.1.1 → 2.2.0 — fixes the 2 CVEs left open in the v1.3.0 report:
- CVE-2026-5038 (GHSA-3p4h-7m6x-2hcm, MODERATE) — DoS via incomplete cleanup of aborted uploads
- CVE-2026-5079 (GHSA-72gw-mp4g-v24j, HIGH) — DoS via deeply nested field names
- form-data (transitive, resolved 4.0.5 → 4.0.6) — fixes CVE-2026-12143 (GHSA-hmw2-7cc7-3qxx, HIGH) — CRLF injection via unescaped multipart field names/filenames.
- ws (transitive, resolved 8.18.3 → 8.21.0) — fixes 2 CVEs:
- CVE-2026-45736 (GHSA-58qx-3vcg-4xpx, MODERATE) — uninitialized memory disclosure
- CVE-2026-48779 (GHSA-96hv-2xvq-fx4p, HIGH) — memory exhaustion DoS from tiny fragments/data chunks
- qs (transitive, resolved 6.14.2 → 6.15.2; pulled in by
body-parser/express, and separately byopenid/steam-web/superagent) — fixes CVE-2026-8723 (GHSA-q8mj-m7cp-5q26, MODERATE) —qs.stringifythrows an uncaughtTypeError(remotely-triggerable DoS) onnull/undefinedarray entries whenencodeValuesOnlyis set. Confirmed fix boundary via OSV: vulnerable range isintroduced: 6.11.1,fixed: 6.15.2— the resolved-at-v1.3.1 version 6.14.2 falls inside it. - brace-expansion (transitive, dedup’d across multiple resolutions) — fixes CVE-2026-45149 (GHSA-jxxr-4gwj-5jf2, MODERATE) — a crafted large numeric range (e.g.
{1..999999999999}) defeats the library’s documented DoS protection. At v1.3.1 the lockfile carried four parallel resolutions from different dependency chains:1.1.13,2.0.3, and two under theminimatchfamily,5.0.5and5.0.6. Verified each individually against OSV — only5.0.5fell inside the vulnerable range (fixed at5.0.6); the other three were already safe. By HEAD, dependency resolution consolidates everything onto the already-patched5.0.7/1.1.14, so there’s no longer a vulnerable resolution anywhere in the tree. (The1.1.13→1.1.14hop on the legacyminimatch@3.xchain carries no CVE fix of its own — it’s incidental to this consolidation.) - esbuild (devDep) 0.28.0 → 0.28.1 — fixes GHSA-g7r4-m6w7-qqqr (no CVE assigned) — the Windows dev-server arbitrary-file-read issue flagged as still-open in the v1.2.1/v1.3.0 entries is now fixed.
- esbuild, nested copy — the new npm
overridesentry (@esbuild-kit/core-utils→esbuild ^0.25.0) bumps that dependency’s bundled esbuild from 0.18.20 to 0.25.12, fixing GHSA-67mh-4wv8-2f99 (no CVE, MODERATE — dev server accepts arbitrary cross-origin requests). Separately,tsx’s own duplicate nested esbuild copy (0.27.7, carrying the same GHSA-g7r4-m6w7-qqqr as above) was deduped away entirely by this bump round rather than upgraded. - vite (devDep) 8.0.12 → 8.1.4 — fixes both issues left open in the v1.3.0 report:
- CVE-2026-53571 (GHSA-fx2h-pf6j-xcff, HIGH) —
server.fs.denybypass - CVE-2026-53632 (GHSA-v6wh-96g9-6wx3, MODERATE) — launch-editor NTLMv2 hash disclosure via UNC path on Windows
- CVE-2026-53571 (GHSA-fx2h-pf6j-xcff, HIGH) —
v1.4.1 (from v1.4.0) — hotfix
- brace-expansion (npm
overridespin^5.0.8, resolved 5.0.9) 5.0.7 → 5.0.9 — fixes 3 HIGH CVEs:- CVE-2026-14257 (GHSA-mh99-v99m-4gvg) — DoS via unbounded expansion length causing an out-of-memory process crash
- CVE-2026-13149 (GHSA-3jxr-9vmj-r5cp) — DoS via exponential-time expansion of consecutive non-expanding
{}groups - CVE-2026-69152 (GHSA-rgw5-rvv9-x895) — DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
- fast-xml-parser 5.10.0 → 5.10.1 — fixes CVE-2026-73569 (GHSA-8r6m-32jq-jx6q, HIGH) — repeated DOCTYPE declarations reset entity expansion limits.
- js-yaml 5.2.1 → 5.2.2 — fixes CVE-2026-73643 (GHSA-pm4m-ph32-ghv5, HIGH) — exponential parsing time in flow collections leading to denial of service.
- body-parser 1.20.5 → 1.20.6 — fixes CVE-2026-12590 (GHSA-v422-hmwv-36x6, LOW) — an invalid
limitvalue silently disabled size enforcement, allowing arbitrarily large request payloads. - fast-uri (npm
overridespin, dev-only at the time) 3.1.3 → 3.1.4 — fixes CVE-2026-16221 (GHSA-v2hh-gcrm-f6hx, HIGH) — host confusion via a literal backslash authority delimiter. - minimatch override pinned to
^10.2.5— closes a second resolution path for thebrace-expansionadvisories:eslint-plugin-react’s bundledminimatch@3.1.5still pulled the vulnerablebrace-expansion@1.1.x. devDependency-only (not shipped in the production image), but flagged bynpm auditwithout--omit=dev, so pinned for a fully clean audit.
v1.4.2 (from v1.4.1) — hotfix
Tagged directly offv1.4.1, not from main; main picked up the same fixes independently.
- ip-address (transitive, via
express-rate-limit) 10.2.0 → 10.5.0 — fixes 3 CVEs; nooverridespin needed,express-rate-limit’s^8.5.2range already permitted 10.5.0:- CVE-2026-69192 (GHSA-mwp4-54f8-5fhr, HIGH) —
Address4decoded leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass - CVE-2026-54272 (GHSA-22jq-vg5j-6vgg, MODERATE) — misclassification of IPv4-mapped/NAT64 IPv6 addresses
- CVE-2026-69198 (GHSA-4xrf-jv44-h6hh, MODERATE) — a CIDR suffix on the parsed address suppressed special-use classification
- CVE-2026-69192 (GHSA-mwp4-54f8-5fhr, HIGH) —
- socket.io-parser (npm
overridespin) 4.2.6 → 4.2.7 — fixes CVE-2026-69185 (GHSA-2m8v-j782-fhvr, HIGH, CVSS 7.5) — zero-attachment memory exhaustion, vulnerable range4.0.0 - <4.2.7. Reaches production viasocket.io/socket.io-client(real-time download-progress and notification updates).
v1.5.0 (from v1.4.2)
Regenerated on 2026-09-29 withnode scripts/cve-report.mjs v1.4.2 HEAD (plus v1.4.0 v1.4.1 and v1.4.1 v1.4.2 for the hotfixes above). Fixes that already shipped in v1.4.1/v1.4.2 are not repeated here, even where main re-applied them.
Production dependencies
- proxy-addr (npm
overridespin) 2.0.7 → 2.0.8 — fixes CVE-2026-90711 (AIKIDO-2026-101201, CRITICAL) — an undersized IPv4-mapped IPv6 trust-subnet prefix (e.g.::ffff:10.0.0.0/8instead of::ffff:10.0.0.0/104) was accepted without error but trusted every IPv4 address on the internet, letting unauthenticated clients spoofX-Forwarded-Forand bypass IP-based access controls, rate limiting, and audit logging, vulnerable range>=1.1.0 <=2.0.7. Reaches production viaexpress, which pinsproxy-addr: ~2.0.7(a range that otherwise excludes the fix). Not yet indexed by OSV.dev, so absent from the script output. - fast-uri (npm
overridespin) 3.1.4 → 3.1.7 — fixes 6 HIGH advisories (#879, #981). Reaches production throughajv, an optional peer of@hookform/resolvers(and dev-only throughsecretlint):- CVE-2026-18446 (GHSA-7p8r-x3mc-p8w7) — host confusion via backslash authority introducer (fixed in 3.1.5)
- CVE-2026-75931 (GHSA-5jgf-p345-68v8) — host confusion via skipped IDN canonicalization on scheme-relative references
- CVE-2026-76172 (GHSA-jqff-g426-hqxp) — host confusion via percent-encoded scheme normalization
- CVE-2026-75975 (GHSA-f65p-4m7j-42xc) — SSRF via malformed IPv6 normalization
- CVE-2026-75899 (GHSA-fph4-wmhf-6fwf) — SSRF via repeated hostname percent-decoding
- CVE-2026-84292 (GHSA-qw65-cvwx-89v3) — authority injection via an unvalidated port in
serialize
- multer 2.2.0 → 2.4.0 — fixes 5 CVEs (#1000, #1066):
- CVE-2026-82333 (GHSA-535w-7cp7-47q4, HIGH) — DoS via oversized array index in field names
- CVE-2026-77037 (GHSA-qfvm-cv95-jqjf, HIGH) — DoS via file descriptor leak on aborted uploads
- CVE-2026-77078 (GHSA-wc9g-mqfw-jrwm, HIGH) — DoS via crafted multipart field names
- CVE-2026-88932 (GHSA-3pph-fpjx-jg34, MODERATE) — DoS via orphaned disk writes on aborted uploads (fixed in 2.4.0)
- CVE-2026-77063 (GHSA-qvfw-j98x-7q72, LOW) — file size limit bypass via async
fileFilterrace condition
- ip-address (npm
overridespin, transitive viaexpress-rate-limitandsocks) 10.5.0 → 10.7.2 — fixes CVE-2026-101913 (GHSA-rpw4-54j3-4h4q, MODERATE) —Address6.isLinkLocal()recognizedfe80::/64rather thanfe80::/10— and CVE-2026-101910 (GHSA-2vr4-cq9g-pvrc, MODERATE) — the NAT64 local-use range64:ff9b:1::/48was not classified; both allowed SSRF and trust-boundary bypass (#1118). - qs (npm
overridespin) 6.15.2 → 6.16.0 — fixes CVE-2026-82417 (GHSA-4mjr-xmp4-gh2g, MODERATE) — DoS via attacker-controlledisBuffer, vulnerable range>=2.2.5 <6.16.0— and CVE-2026-82562 (GHSA-x5fp-wj9c-mxmx, MODERATE) — array-limit bypass via bracket-key comma parsing, vulnerable range>=6.14.2 <=6.15.3. Reaches production viaexpress/body-parser, both of which pinqs: ~6.15.1(a range that otherwise excludes the fix); the same override also closes the gap inopenid,steam-web, andsuperagent(#997). - undici (direct dependency) 8.10.0 → 8.10.2 — fixes CVE-2026-85024 (GHSA-3wwx-pv8p-q78v, MODERATE) — DoS via an unhandled error in WebSocket permessage-deflate decompression (#1028). The earlier 7.29.0 → 8.9.0 major bump crossed no fix boundary (see Changed). Before it became a direct dependency,
undiciwas only a dev-only transitive ofjsdom, whose 7.28.0 → 7.29.0 refresh fixed CVE-2026-13697, CVE-2026-16728, CVE-2026-14643, CVE-2026-15157 and CVE-2026-16729 in test tooling.
Development dependencies (not shipped in the production image)
- js-yaml (npm
overridespin, scoped to@eslint/eslintrc, and the other nested 4.x copies) 4.3.0 → 4.3.2 — fixes GHSA-5p4m-2wfm-xmqj (no CVE assigned, HIGH) — quadratic CPU consumption in!!omapresolution — and CVE-2026-84375 (GHSA-2883-xcg3-v3hh, HIGH) —maxTotalMergeKeysdid not limit CPU use for empty merge sources (#894, #997, #998). The top-leveljs-yaml5.x used in production was already unaffected. - nanoid (nested under
postcss) 3.3.12 → 3.3.18 — fixes CVE-2026-67214 (GHSA-28wg-ghj8-5hjv, HIGH) and CVE-2026-67213 (GHSA-2v37-7h3g-55p8, HIGH) — generators could loop indefinitely with a negative or zero size (#917). The productionnanoid6.x was never affected. - browserslist 4.28.4 → 4.28.9 — fixes CVE-2026-73088 (GHSA-73wf-gq98-2v4g, HIGH) — crash / prototype write via untrusted custom stats — and CVE-2026-73089 (GHSA-c83g-rgw3-j3cx, HIGH) — unbounded memory growth via distinct query results.
- baseline-browser-mapping 2.10.40 → 2.11.21 — fixes CVE-2026-45819 (GHSA-w5vr-8v7q-w6rv, MODERATE) — process termination on invalid input.
- postcss 8.5.18 → 8.5.28 — fixes CVE-2026-69153 (GHSA-fxqj-rqcc-2cmp, MODERATE) — attacker-controlled
sourceMappingURLcould read arbitrary.mapfiles whenfromis unset (#882). - vitest / @vitest/mocker 4.1.10 → 5.0.1 — fixes CVE-2026-84373 (GHSA-82fw-gwwq-j7x9, MODERATE) — path traversal / arbitrary file read via the redirect mock (#971).
- undici (scoped
overridespin undernode-gyp, via@lizenz/checker) 6.28.0 → 6.29.0 — fixes CVE-2026-85024 (GHSA-3wwx-pv8p-q78v), the same advisory as the production entry above (#1118).
Container image
- Docker base image:
apk upgradefor Alpine’s patchedopenssl/expat(Trivy #417, #361, #351, #364, #363); removed the base image’s bundled npm CLI afternpm prune, dropping its vendoredtar/ip-address/brace-expansioncopies (Trivy #350, #287, #286, #272) (#1113).
Footnote: devDependencies (build-time only, not shipped to production)
Checked per the “each bumped package” instruction, but these tools run only at build time (Vite/esbuild/PostCSS output is bundled; the tools themselves aren’t part of the running server) so their CVEs don’t apply to the deployed app:- vite 5.4.21 → 8.0.9 (v1.3.0) fixed CVE-2026-39365 (path traversal in optimized-deps
.maphandling). Two Windows-dev-server-only issues remain open through 8.0.12: CVE-2026-53571 (server.fs.denybypass) and CVE-2026-53632 (launch-editor NTLMv2 hash disclosure via UNC path). - esbuild 0.27.2 → 0.27.3 (v1.2.1) actually introduced a still-open, no-CVE-assigned advisory (GHSA-g7r4-m6w7-qqqr, dev-server arbitrary file read on Windows) — never fixed by the later 0.28.0 bump.
- postcss 8.4.47 → 8.5.10 (v1.3.0) fixed CVE-2026-41305 (XSS via unescaped
</style>in stringify output) — relevant only if user-controlled CSS is ever processed at build time, which it isn’t here.