FLAT-Z38HW (CVE-2026-41650)
XML injection (XXE) In node-webfont
2.5
Low
Ecosystem: Debian
Package: node-webfont
FLAT-7O3CB (CVE-2026-33349)
Lack of data validation In node-webfont
6.3
Medium
Ecosystem: Debian
Package: node-webfont
FLAT-SCSFJ (CVE-2026-33036)
XML injection (XXE) In node-webfont
7.7
High
Ecosystem: Debian
Package: node-webfont
FLAT-S3JQJ (CVE-2026-25896)
Asymmetric denial of service - ReDoS In node-webfont
8.9
High
Ecosystem: Debian
Package: node-webfont
FLAT-MZ9MH (CVE-2026-26278)
XML injection (XXE) In node-webfont
6.3
Medium
Ecosystem: Debian
Package: node-webfont
FLAT-SPG7A (CVE-2023-26920)
Prototype Pollution In node-webfont
4.9
Medium
Ecosystem: Debian
Package: node-webfont