← Back

Digitalocean

digitalocean

2 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Do Markdownit
do-markdownit

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Digitalocean
1Do Markdownit
Jun 17, 2026
Sep 19, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedClasses or allowedEnvironments is a string (instead of an array...Show more
In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedClasses or allowedEnvironments is a string (instead of an array).Show less
1Digitalocean
1Golang Nanoauth
Jun 17, 2026
Dec 27, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.