CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
More on CrowdSec
Other advisories
- CVE-2026-44982highgo github.com/crowdsecurity/crowdsec: Protection Mechanism Failure
- CVE-2026-44981highgo github.com/crowdsecurity/crowdsec: Improper Handling of Highly Compressed Data (Data Amplification)
- CVE-2026-44982highgo github.com/crowdsecurity/crowdsec: Protection Mechanism Failure
- osv:CVE-2026-44982noneCrowdSec AppSec silently drops request body for chunked / HTTP-2 requests
- osv:CVE-2026-44981noneCrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression
- CVE-2026-44981highgo github.com/crowdsecurity/crowdsec: Improper Handling of Highly Compressed Data (Data Amplification)
- CVE-2026-44982noneCrowdSec AppSec silently drops request body for chunked / HTTP-2 requests in github.com/crowdsecurity/crowdsec
- CVE-2026-44981noneCrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression in github.com/crowdsecurity/crowdsec
Source: https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html
ID