WhisperX tag archive

#dependency security

This page collects WhisperX intelligence signals tagged #dependency security. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (9)

The Lab · 2026-04-03 23:27:03 · GitHub Issues

1. Electron v41.1.0 Patches Critical Use-After-Free Vulnerability in Offscreen Rendering (CVE-2026-34764)

A critical security vulnerability in the Electron framework, tracked as CVE-2026-34764, has been patched in the latest release. The flaw, a use-after-free memory corruption bug, resides in the offscreen rendering component and poses a direct risk to the stability and security of the main process in affected application...

The Lab · 2026-04-04 01:26:56 · GitHub Issues

2. Electron v39.8.5 Patches Critical Use-After-Free Vulnerability in Offscreen Rendering (CVE-2026-34764)

A critical security vulnerability in the Electron framework, tracked as CVE-2026-34764, has been patched in the latest release. The flaw, a use-after-free memory corruption bug, resides in the offscreen rendering module and poses a direct risk to the stability and security of the main process in affected applications. ...

The Lab · 2026-04-05 17:27:01 · GitHub Issues

3. Nuxt.js Dev Toolchain Pins Defu Dependency to Patch High-Severity Prototype Pollution (CVE-2026-35209)

A high-severity prototype pollution vulnerability (CVE-2026-35209 / GHSA-737v-mqg7-c878) in the `defu` library has triggered a forced dependency override within the Nuxt.js framework's development toolchain. The vulnerability, present in `defu` version 6.1.4, was discovered in a transitive dependency used by `@hey-api/...

The Lab · 2026-04-07 18:27:30 · GitHub Issues

4. Electron Security Alert: Critical Heap Buffer Overflow in NativeImage Functions (CVE-2024-46993)

A critical security vulnerability in the Electron framework exposes applications to potential remote code execution via a heap buffer overflow. The flaw, tracked as CVE-2024-46993, resides in the `nativeImage.createFromPath()` and `nativeImage.createFromBuffer()` functions. Any Electron program utilizing these function...

The Lab · 2026-04-16 03:22:34 · GitHub Issues

5. CVE-2026-33816: Memory-Safety Flaw in Go's pgx Database Driver Triggers Security Update

A critical memory-safety vulnerability, designated CVE-2026-33816, has been identified in the widely-used `github.com/jackc/pgx/v5` Go database driver. The flaw, which carries an unknown severity rating, has prompted an immediate dependency update from version 5.7.6 to 5.9.0 to address the security risk. The vulnerabil...

The Lab · 2026-04-21 10:22:42 · GitHub Issues

6. Deprecated 'request' npm Package Exposes Projects to SSRF via CVE-2023-28155, No Fix Available

A critical dependency alert reveals that the widely used but deprecated `request` npm library contains an unfixed Server-Side Request Forgery (SSRF) vulnerability, CVE-2023-28155. The flaw, rated medium severity, allows attackers to exploit the library's handling of cross-protocol redirects—such as from HTTP to `file:/...

The Lab · 2026-04-23 05:54:07 · GitHub Issues

7. fast-xml-parser CVE-2026-41650: XMLBuilder Injection Flaw Forces Emergency Update to v5.7.0

A critical security vulnerability in the `fast-xml-parser` npm package has triggered an urgent version bump to 5.7.0, patching a flaw that allows XML Comment and CDATA injection via unescaped delimiters in the XMLBuilder component. The issue, tracked as CVE-2026-41650 and catalogued under GHSA-gh4j-gqv2-49f6, exposes a...

The Lab · 2026-05-08 17:24:41 · GitHub Issues

8. Production Systems Run ldap3 Release Candidate Without Security Monitoring or Upgrade Path

A production environment is running ldap3 version 2.10.2rc3—a release candidate—without documented justification or enhanced monitoring, creating a blind spot in security patch management. Release candidates occupy an ambiguous position in software supply chains: they ship with newer features but lack the stable mainte...

The Lab · 2026-05-12 07:48:27 · GitHub Issues

9. Lodash Security Patch Targets Prototype Pollution Flaw in _.unset and _.omit Functions

A critical prototype pollution vulnerability has been identified in Lodash, prompting an urgent dependency update to version 4.18.1. The flaw, tracked as CVE-2025-13465, affects all versions from 4.0.0 through 4.17.22 and specifically targets the `_.unset` and `_.omit` utility functions widely used in JavaScript applic...