cve
Safeguard articles tagged "cve" — guides, analysis, and best practices for software supply chain and application security.
184 articles
Axios npm Vulnerabilities: The Full CVE History and Patch Guide
Every notable axios npm vulnerability, from the 2019 DoS to the 2025 SSRF, with the fixed versions and a patch path that also catches the transitive ones.
http-proxy-middleware on npm: Security Review and Safe Usage
http-proxy-middleware is a widely used npm proxy library that has shipped two notable CVEs. Here is what to pin, what to patch, and how to use it safely.
spring-webmvc Security: Known CVEs and How to Stay Patched
A security guide to the spring-webmvc Maven dependency: recent path traversal CVEs, affected version ranges, and how to keep this core Spring artifact patched.
CVE-2022-42004: The jackson-databind DoS Explained
CVE-2022-42004 is a denial-of-service flaw in jackson-databind where deeply nested arrays exhaust resources during deserialization. Here is who is affected and how to fix it.
CVE vs CVSS vs EPSS vs SSVC scoring compared
CVE tells you a flaw exists, CVSS rates severity, EPSS predicts exploitation, and SSVC drives decisions. Here's how Safeguard and Socket.dev use each differently.
EchoLeak (CVE-2025-32711): The First Zero-Click Production LLM Exfiltration
A single crafted email could exfiltrate data from Microsoft 365 Copilot without a user click. We walk the attack chain, the patch, and the lessons for agent operators.
The ROI of CVE Prioritization with Reachability in 2026
Concrete numbers on what reachability-based CVE prioritization saves: engineering hours, mean time to remediate, and the ROI math that survives finance review.
CVE-2025-23121 in Veeam Backup & Replication: Patch Posture & SBOM Response
Veeam B&R authenticated RCE on the backup server scored CVSS 9.9. Backup infrastructure cannot be a soft underbelly. Here is the defender playbook.
MySQL Vulnerabilities: Common Risks and How to Patch Them
MySQL vulnerabilities range from privilege-escalation flaws in the server to injection and misconfiguration in the apps that use it. Here is what to watch and how to close the gaps.
How to Secure webpack-dev-server Against Source Code Theft
webpack-dev-server is a local development server, not a production one, and two 2025 CVEs showed exactly why that distinction matters. Here is how it leaks and how to lock it down.
netty-codec-http2 in Maven: Vulnerabilities and Fixes
The netty-codec-http2 Maven artifact powers HTTP/2 in gRPC, Spring, and countless services. Here are the CVEs that matter, the safe versions, and how to find it in your tree.
Lodash 4.17.21 Vulnerabilities: What the 'Safe' Version Still Misses
Lodash 4.17.21 was the release that fixed the famous prototype pollution and command injection bugs. Here is what it patched and why it is no longer the final word.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.