Skip to content

v3.1.26 — 5 new rules + dep audit fix

Choose a tag to compare

@goklab goklab released this 06 Jun 09:12
  • VG1071-1073: axios proxy-auth redirect leak (CVE-2026-44486/87), hono setCookie attribute injection (CVE-2026-47675), drizzle sql.raw/sql.identifier interpolation
  • VG1074-1075: Miasma @redhat-cloud-services namespace IOC (RHSB-2026-006), Session messenger filev2.getsession.org exfil endpoint
  • npm audit fix: hono / brace-expansion / qs patched; hono override floor bumped to ^4.12.21; self-audit PASS A 100