# Named CVE watchlist (2025–2026)

Companion of `security-baseline` (OWASP 2025-A03). **Not** injected via Claude
`skills:` and **not** inlined in agents. Read this file only when a trigger
below matches the lockfile / manifest.

Do **not** invent CVE ids. Refresh this table on the next SVS release.
`npm audit` / `composer audit` / `pip-audit` stay mandatory — this list
covers waves those tools lag or miss (no CVE on the leaf package).

## When to Read

Any of these in `package-lock.json` / `pnpm-lock.yaml` / `yarn.lock` /
`composer.lock` / `package.json` / `composer.json`:

`react` · `react-dom` · `react-server-dom-*` · `next` · `axios` ·
`react-router` · `@remix-run/react` · `laravel/passport` ·
`symfony/html-sanitizer` · `symfony/http-client` · `@tanstack/`

Also Read on worm indicators you did not write: `preinstall` → `setup.mjs`,
`Math_Symbol.js`, unexpected hooks in `.claude/settings.json` or
`.vscode/tasks.json`.

## Table

| CVE | Sev | When it hits | Floor (fixed) |
|---|---|---|---|
| CVE-2025-55182 | CRIT | React RSC / Next App Router — `react-server-dom-*` 19.0.0, 19.1.0, 19.1.1, 19.2.0 (React2Shell Flight RCE). `CVE-2025-66478` is a **rejected duplicate** — cite 55182. First patches (19.0.1 / 19.1.2 / 19.2.1) are **not** the combined floor. | Prefer `react` / `react-dom` / `react-server-dom-*` **19.3.x**. Line floors after follow-ons: **19.0.5 / 19.1.6 / 19.2.5**. `next` ≥ latest patched on your line (see 55183/55184 rows) |
| CVE-2025-55183 | MED | RSC Server Function source / secret-in-source leak on Flight endpoints | Same combined floor as 55182 follow-ons (`react-server-dom-*` 19.0.5 / 19.1.6 / 19.2.5 / 19.3) |
| CVE-2025-55184 | HIGH | RSC Flight DoS (hang / CPU). Incomplete first fix → also **CVE-2025-67779**, **CVE-2026-23864** | `react-server-dom-*` **19.0.5 / 19.1.6 / 19.2.5** or **19.3.x** |
| CVE-2026-44579 | HIGH | `next` 15.x < 15.5.16 or 16.x < 16.2.5 **and** Cache Components / PPR (server-action body deadlock) | 15.5.16 or 16.2.5 |
| CVE-2026-44580 | HIGH | `next` beforeInteractive script XSS when script content is untrusted | 15.5.16 or 16.2.5 |
| CVE-2026-21884 | HIGH | `react-router` 7.0–7.11 Framework Mode `<ScrollRestoration>` SSR XSS (`getKey` / `storageKey`) | `react-router` **7.12.0+**; `@remix-run/react` **2.17.3+** |
| CVE-2026-33245 | HIGH | `react-router` 7.7.0–7.13.1 unstable RSC redirect XSS | `react-router` **7.13.2+** |
| CVE-2025-27152 | HIGH | `axios` absolute URL overrides `baseURL` — SSRF / header leak | `axios` **1.8.2** / **0.30.0** (still bump — later CVEs) |
| CVE-2025-58754 | HIGH | `axios` Node `data:` URI unbounded memory | `axios` **1.12.0** / **0.30.2** |
| CVE-2026-42042 | MED | `axios` `withXSRFToken` truthy (non-boolean) skips same-origin check — XSRF cookie leaked cross-origin | First fix **1.15.1** / **0.31.1**; pin **≥ 1.20.0** |
| CVE-2025-62718 | MED | `axios` `NO_PROXY` bypass / SSRF (1.15.0 incomplete — later loopback / `0.0.0.0` follow-ons) | Pin **≥ 1.20.0** (Node adapter) |
| CVE-2026-40175 | MED | `axios` cloud-metadata exfil / proxy path | Pin **≥ 1.20.0** (Node adapter) |
| CVE-2026-45321 | CRIT | Mini Shai-Hulud worm (npm + PyPI). Lockfile/`preinstall` → `setup.mjs`; unexpected `.claude/settings.json` / `.vscode/tasks.json` hooks; `@tanstack/*` versions from the May-2026 window. Contain host **before** revoke (watchdog) — `secrets-management` rotation playbook. | Pin clean versions; `npm i --ignore-scripts`; rotate from a **clean** machine |
| CVE-2026-39976 | HIGH | `laravel/passport` ≥ 13.0.0 < 13.7.1 — `client_credentials` token can resolve as a user | 13.7.1 |
| CVE-2026-45753 | HIGH | `symfony/html-sanitizer` < 6.4.40 / < 7.4.12 / < 8.0.12 — `javascript:` survives on action/formaction/poster/cite | 6.4.40 / 7.4.12 / 8.0.12 |
| CVE-2026-48736 | HIGH | `symfony/http-client` / `IpUtils` — IPv6 6to4/NAT64/Teredo bypass of private-IP SSRF block | 5.4.53 / 6.4.41 / 7.4.13 / 8.0.13 |

Worm / malware waves often have **no CVE on the leaf package** (GHSA malware /
OSV `MAL-*`). Still VETO on the indicators above.

## Cite

`CVE-YYYY-#####` + package + installed version + one-line floor.
Any **hit** = VETO (same as audit HIGH+).
