Vulnerabilità · 131 giorni fa

La provenance SLSA valida non garantisce più la sicurezza dei package

I controlli di provenance non chiudono più il divario di fiducia in npm e PyPI. Il worm Mini Shai-Hulud di TeamPCP ha ցույց?

CVE-2026-45321

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 9.6 CRITICAL: on 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. EPSS 1% (63º percentile).

Data di correzione federale CISA 10 giu

Cronologia

Fonti

17 fonti che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-05-18

Editions

Storie correlate