piscina
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting piscinapage 1 of 1
- CVE-2026-102992CRITICALCVSS 9.2EG 9.2fixed in 5.3.2, 4.9.4 or 6.0.0-rc.5, by version range2026-09-30
piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-polluti…
- CVE-2026-55388HIGHCVSS 8.1EG 8.1fixed in 5.2.0, 4.9.3 or 6.0.0-rc.2, by version range2026-06-18
piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() paths read the filename option via plain member access. Both reads fall through the prototype chain when the caller's o…
Check whether piscina is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for piscina CVEs against the assets you own.
Book a Demo →