npm package report

Is devcert safe?

2 known vulnerabilities, worst severity HIGH.

cvss
5.9

how bad it is if exploited, out of 10

epss
0.60%

chance of exploitation in the next 30 days

xyz score
4.0

CyberXYZ composite, out of 10

fig. 01 — GHSA-fp36-299x-pwmw, the advisory selected below

// advisories

GHSA-fp36-299x-pwmw

HIGHCVE-2022-1929

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method

Affected
< 1.2.1
Fixed in
1.2.1
Weakness
CWE-1333
Published
2022-06-03
Source
github

GHSANVDMITREreferencereference


// dependencies

29 direct, 5 carrying known advisories, worst CRITICAL

Sign in for dependency paths and remediation

// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 01:32 UTC. The most recent advisory here was published 2022-06-03. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is devcert safe? npm package security report | CyberXYZ