Security

79 open findings · 3 critical need action today.

92score

Security Score

92/100 · up 4 this month

Critical

0

Critical severity findings

High

0

High severity findings

Medium

0

Medium severity findings

Low

0

Low severity findings

Vulnerabilities

8 findings

  • lodashcritical

    CVE-2026-31844 · 4.17.204.17.21

    Bump to 4.17.21 — no breaking API changes across the 14 call sites detected.

  • opensslcritical

    CVE-2026-2908 · 3.0.83.0.13

    Rebuild the payments-api base image; pipeline cache will handle the rest.

  • jsonwebtokencritical

    CVE-2026-11207 · 8.5.19.0.2

    Upgrade and switch to explicit algorithm allow-listing in auth-service.

  • axioshigh

    CVE-2026-45142 · 1.4.01.7.4

    Safe minor upgrade; 2 mocked tests need updated interceptor signatures.

  • postgreshigh

    CVE-2026-1094 · 3.3.43.4.5

    Correlated with the payments-api pool exhaustion seen during INC-2048.

  • vitemedium

    CVE-2026-31125 · 5.1.05.4.6

    Development-only exposure; batch with the next frontend dependency sweep.

  • tarmedium

    CVE-2026-28863 · 6.1.116.2.1

    Included in the next data-pipeline image rebuild.

  • semverlow

    CVE-2026-25883 · 7.5.07.5.2

    No untrusted input reaches this parser. Track only.

lodashcritical

CVE-2026-31844

4.17.204.17.21

Bump to 4.17.21 — no breaking API changes across the 14 call sites detected.

opensslcritical

CVE-2026-2908

3.0.83.0.13

Rebuild the payments-api base image; pipeline cache will handle the rest.

jsonwebtokencritical

CVE-2026-11207

8.5.19.0.2

Upgrade and switch to explicit algorithm allow-listing in auth-service.