Known Vulnerabilities for Lexical by Facebook
Listed below are 1 of the newest known vulnerabilities associated with "Lexical" by "Facebook".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-101894 json | The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API r... | Not Provided | 2026-09-28 | 2026-09-28 |
| CVE-2026-100690 json | Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js per... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-90930 json | File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying ... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-88879 json | Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, heade... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-85731 json | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with i... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-78381 json | RansomLook contains a path traversal vulnerability in the handling of the screen field associated with group posts. The Group... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-71493 json | Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathEx... | Not Provided | 2026-08-21 | 2026-08-26 |
| CVE-2026-70626 json | NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read ... | Not Provided | 2026-08-22 | 2026-08-24 |
| CVE-2026-68497 json | jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by pas... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-66907 json | Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.... | Not Provided | 2026-08-24 | 2026-08-25 |