{
  "stage": "stage2a-vulns",
  "generated_at": "2026-03-28T21:16:52.357Z",
  "scanners": {
    "grype": {
      "findingCount": 0,
      "durationMs": 3053
    },
    "osv_scanner": {
      "findingCount": 0,
      "durationMs": 141
    },
    "npm_audit": {
      "findingCount": 24,
      "durationMs": 1884
    }
  },
  "total_raw_findings": 24,
  "deduplicated_count": 17,
  "findings": [
    {
      "cve_id": null,
      "ghsa_id": "GHSA-wc8c-qw6v-h7f6",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "@hono/node-server",
      "installed_version": "<1.19.10",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware",
      "description": "@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware",
      "url": "https://github.com/advisories/GHSA-wc8c-qw6v-h7f6",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-2g4f-4pwh-qvx6",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 0,
      "epss_score": null,
      "is_kev": false,
      "package_name": "ajv",
      "installed_version": "7.0.0-alpha.0 - 8.17.1",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "ajv has ReDoS when using `$data` option",
      "description": "ajv has ReDoS when using `$data` option",
      "url": "https://github.com/advisories/GHSA-2g4f-4pwh-qvx6",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-f886-m6hf-6m8v",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 6.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "brace-expansion",
      "installed_version": "<1.1.13 || >=2.0.0 <2.0.3",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
      "description": "brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
      "url": "https://github.com/advisories/GHSA-f886-m6hf-6m8v",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-67mh-4wv8-2f99",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 5.3,
      "epss_score": null,
      "is_kev": false,
      "package_name": "esbuild",
      "installed_version": "<=0.24.2",
      "fixed_version": "4.1.2",
      "dependency_scope": "development",
      "title": "esbuild enables any website to send any requests to the development server and read the response",
      "description": "esbuild enables any website to send any requests to the development server and read the response",
      "url": "https://github.com/advisories/GHSA-67mh-4wv8-2f99",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-46wh-pxpv-q5gq",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "express-rate-limit",
      "installed_version": "8.2.0 - 8.2.1",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network",
      "description": "express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network",
      "url": "https://github.com/advisories/GHSA-46wh-pxpv-q5gq",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-gq3j-xvxp-8hrf",
      "osv_id": null,
      "severity": "low",
      "cvss_score": 3.7,
      "epss_score": null,
      "is_kev": false,
      "package_name": "hono",
      "installed_version": "<=4.12.6",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "Hono added timing comparison hardening in basicAuth and bearerAuth",
      "description": "Hono added timing comparison hardening in basicAuth and bearerAuth",
      "url": "https://github.com/advisories/GHSA-gq3j-xvxp-8hrf",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-5pq2-9x2x-5p6w",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 5.4,
      "epss_score": null,
      "is_kev": false,
      "package_name": "hono",
      "installed_version": "<=4.12.6",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()",
      "description": "Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()",
      "url": "https://github.com/advisories/GHSA-5pq2-9x2x-5p6w",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-p6xx-57qc-3wxr",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 6.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "hono",
      "installed_version": "<=4.12.6",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()",
      "description": "Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()",
      "url": "https://github.com/advisories/GHSA-p6xx-57qc-3wxr",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-q5qw-h33p-qvwr",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "hono",
      "installed_version": "<=4.12.6",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "Hono vulnerable to arbitrary file access via serveStatic vulnerability ",
      "description": "Hono vulnerable to arbitrary file access via serveStatic vulnerability ",
      "url": "https://github.com/advisories/GHSA-q5qw-h33p-qvwr",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-v8w9-8mx6-g223",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 4.8,
      "epss_score": null,
      "is_kev": false,
      "package_name": "hono",
      "installed_version": "<=4.12.6",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })",
      "description": "Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })",
      "url": "https://github.com/advisories/GHSA-v8w9-8mx6-g223",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-3ppc-4f35-3m26",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 0,
      "epss_score": null,
      "is_kev": false,
      "package_name": "minimatch",
      "installed_version": "<=3.1.3 || 9.0.0 - 9.0.6 || 10.0.0 - 10.2.2",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
      "description": "minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
      "url": "https://github.com/advisories/GHSA-3ppc-4f35-3m26",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-7r86-cg39-jmmj",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "minimatch",
      "installed_version": "<=3.1.3 || 9.0.0 - 9.0.6 || 10.0.0 - 10.2.2",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments",
      "description": "minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments",
      "url": "https://github.com/advisories/GHSA-7r86-cg39-jmmj",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-23c5-xmqv-rm74",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "minimatch",
      "installed_version": "<=3.1.3 || 9.0.0 - 9.0.6 || 10.0.0 - 10.2.2",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions",
      "description": "minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions",
      "url": "https://github.com/advisories/GHSA-23c5-xmqv-rm74",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-j3q9-mxjg-w52f",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 7.5,
      "epss_score": null,
      "is_kev": false,
      "package_name": "path-to-regexp",
      "installed_version": "8.0.0 - 8.3.0",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "path-to-regexp vulnerable to Denial of Service via sequential optional groups",
      "description": "path-to-regexp vulnerable to Denial of Service via sequential optional groups",
      "url": "https://github.com/advisories/GHSA-j3q9-mxjg-w52f",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-27v5-c462-wpq7",
      "osv_id": null,
      "severity": "moderate",
      "cvss_score": 5.9,
      "epss_score": null,
      "is_kev": false,
      "package_name": "path-to-regexp",
      "installed_version": "8.0.0 - 8.3.0",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards",
      "description": "path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards",
      "url": "https://github.com/advisories/GHSA-27v5-c462-wpq7",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-w7fw-mjwx-w883",
      "osv_id": null,
      "severity": "low",
      "cvss_score": 3.7,
      "epss_score": null,
      "is_kev": false,
      "package_name": "qs",
      "installed_version": "6.7.0 - 6.14.1",
      "fixed_version": "available",
      "dependency_scope": "runtime",
      "title": "qs's arrayLimit bypass in comma parsing allows denial of service",
      "description": "qs's arrayLimit bypass in comma parsing allows denial of service",
      "url": "https://github.com/advisories/GHSA-w7fw-mjwx-w883",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": true
    },
    {
      "cve_id": null,
      "ghsa_id": "GHSA-mw96-cpmx-2vgc",
      "osv_id": null,
      "severity": "high",
      "cvss_score": 0,
      "epss_score": null,
      "is_kev": false,
      "package_name": "rollup",
      "installed_version": "4.0.0 - 4.58.0",
      "fixed_version": "available",
      "dependency_scope": "development",
      "title": "Rollup 4 has Arbitrary File Write via Path Traversal",
      "description": "Rollup 4 has Arbitrary File Write via Path Traversal",
      "url": "https://github.com/advisories/GHSA-mw96-cpmx-2vgc",
      "sources": [
        "npm-audit"
      ],
      "has_fix": true,
      "is_runtime": false
    }
  ],
  "risk_score": {
    "runtimeCount": 14,
    "devCount": 3,
    "weightedScore": 194
  }
}