csv-parse
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting csv-parsepage 1 of 1
- CVE-2019-17592HIGHCVSS 7.5EG 7.5✓ Fixed in 4.4.62019-10-14
The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regular expression that processes large crafted input very slowly. This is triggered when usin…
- CVE-2026-85063MEDIUMCVSS 6.9EG 6.9✓ Fixed in 7.0.22026-09-03
node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2, csv-parse with the columns and group_columns_by_name options enabled treats a duplicate __proto__ header as an existing propert…
Check whether csv-parse is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for csv-parse CVEs against the assets you own.
Start Free Scan →