Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-23644

esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925-c62ab83c589e, the software has a path traversal vulnerability due to an incomplete fix. `path.Clean` normalizes a path but does not prevent absolute paths in a malicious tar file. Commit https://github.com/esm-dev/esm.sh/commit/9d77b88c320733ff6689d938d85d246a3af9af16, corresponding to pseudoversion 0.0.0-20260116051925-c62ab83c589e, fixes this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.1%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-23644
  • Esm » Esm.sh » Version: 100
    cpe:2.3:a:esm:esm.sh:100
  • Esm » Esm.sh » Version: 101
    cpe:2.3:a:esm:esm.sh:101
  • Esm » Esm.sh » Version: 102
    cpe:2.3:a:esm:esm.sh:102
  • Esm » Esm.sh » Version: 103
    cpe:2.3:a:esm:esm.sh:103
  • Esm » Esm.sh » Version: 104
    cpe:2.3:a:esm:esm.sh:104
  • Esm » Esm.sh » Version: 105
    cpe:2.3:a:esm:esm.sh:105
  • Esm » Esm.sh » Version: 106
    cpe:2.3:a:esm:esm.sh:106
  • Esm » Esm.sh » Version: 107
    cpe:2.3:a:esm:esm.sh:107
  • Esm » Esm.sh » Version: 108
    cpe:2.3:a:esm:esm.sh:108
  • Esm » Esm.sh » Version: 109
    cpe:2.3:a:esm:esm.sh:109
  • Esm » Esm.sh » Version: 110
    cpe:2.3:a:esm:esm.sh:110
  • Esm » Esm.sh » Version: 111
    cpe:2.3:a:esm:esm.sh:111
  • Esm » Esm.sh » Version: 112
    cpe:2.3:a:esm:esm.sh:112
  • Esm » Esm.sh » Version: 113
    cpe:2.3:a:esm:esm.sh:113
  • Esm » Esm.sh » Version: 114
    cpe:2.3:a:esm:esm.sh:114
  • Esm » Esm.sh » Version: 115
    cpe:2.3:a:esm:esm.sh:115
  • Esm » Esm.sh » Version: 116
    cpe:2.3:a:esm:esm.sh:116
  • Esm » Esm.sh » Version: 117
    cpe:2.3:a:esm:esm.sh:117
  • Esm » Esm.sh » Version: 118
    cpe:2.3:a:esm:esm.sh:118
  • Esm » Esm.sh » Version: 119
    cpe:2.3:a:esm:esm.sh:119
  • Esm » Esm.sh » Version: 120
    cpe:2.3:a:esm:esm.sh:120
  • Esm » Esm.sh » Version: 121
    cpe:2.3:a:esm:esm.sh:121
  • Esm » Esm.sh » Version: 122
    cpe:2.3:a:esm:esm.sh:122
  • Esm » Esm.sh » Version: 123
    cpe:2.3:a:esm:esm.sh:123
  • Esm » Esm.sh » Version: 124
    cpe:2.3:a:esm:esm.sh:124
  • Esm » Esm.sh » Version: 125
    cpe:2.3:a:esm:esm.sh:125
  • Esm » Esm.sh » Version: 126
    cpe:2.3:a:esm:esm.sh:126
  • Esm » Esm.sh » Version: 127
    cpe:2.3:a:esm:esm.sh:127
  • Esm » Esm.sh » Version: 128
    cpe:2.3:a:esm:esm.sh:128
  • Esm » Esm.sh » Version: 129
    cpe:2.3:a:esm:esm.sh:129
  • Esm » Esm.sh » Version: 130
    cpe:2.3:a:esm:esm.sh:130
  • Esm » Esm.sh » Version: 131
    cpe:2.3:a:esm:esm.sh:131
  • Esm » Esm.sh » Version: 132
    cpe:2.3:a:esm:esm.sh:132
  • Esm » Esm.sh » Version: 133
    cpe:2.3:a:esm:esm.sh:133
  • Esm » Esm.sh » Version: 134
    cpe:2.3:a:esm:esm.sh:134
  • Esm » Esm.sh » Version: 135
    cpe:2.3:a:esm:esm.sh:135
  • Esm » Esm.sh » Version: 135_1
    cpe:2.3:a:esm:esm.sh:135_1
  • Esm » Esm.sh » Version: 135_2
    cpe:2.3:a:esm:esm.sh:135_2
  • Esm » Esm.sh » Version: 135_3
    cpe:2.3:a:esm:esm.sh:135_3
  • Esm » Esm.sh » Version: 135_4
    cpe:2.3:a:esm:esm.sh:135_4
  • Esm » Esm.sh » Version: 135_5
    cpe:2.3:a:esm:esm.sh:135_5
  • Esm » Esm.sh » Version: 135_6
    cpe:2.3:a:esm:esm.sh:135_6
  • Esm » Esm.sh » Version: 135_7
    cpe:2.3:a:esm:esm.sh:135_7
  • Esm » Esm.sh » Version: 34
    cpe:2.3:a:esm:esm.sh:34
  • Esm » Esm.sh » Version: 35
    cpe:2.3:a:esm:esm.sh:35
  • Esm » Esm.sh » Version: 37
    cpe:2.3:a:esm:esm.sh:37
  • Esm » Esm.sh » Version: 38
    cpe:2.3:a:esm:esm.sh:38
  • Esm » Esm.sh » Version: 39
    cpe:2.3:a:esm:esm.sh:39
  • Esm » Esm.sh » Version: 40
    cpe:2.3:a:esm:esm.sh:40
  • Esm » Esm.sh » Version: 41
    cpe:2.3:a:esm:esm.sh:41
  • Esm » Esm.sh » Version: 43
    cpe:2.3:a:esm:esm.sh:43
  • Esm » Esm.sh » Version: 44
    cpe:2.3:a:esm:esm.sh:44
  • Esm » Esm.sh » Version: 45
    cpe:2.3:a:esm:esm.sh:45
  • Esm » Esm.sh » Version: 46
    cpe:2.3:a:esm:esm.sh:46
  • Esm » Esm.sh » Version: 47
    cpe:2.3:a:esm:esm.sh:47
  • Esm » Esm.sh » Version: 48
    cpe:2.3:a:esm:esm.sh:48
  • Esm » Esm.sh » Version: 49
    cpe:2.3:a:esm:esm.sh:49
  • Esm » Esm.sh » Version: 50
    cpe:2.3:a:esm:esm.sh:50
  • Esm » Esm.sh » Version: 51
    cpe:2.3:a:esm:esm.sh:51
  • Esm » Esm.sh » Version: 52
    cpe:2.3:a:esm:esm.sh:52
  • Esm » Esm.sh » Version: 53
    cpe:2.3:a:esm:esm.sh:53
  • Esm » Esm.sh » Version: 55
    cpe:2.3:a:esm:esm.sh:55
  • Esm » Esm.sh » Version: 56
    cpe:2.3:a:esm:esm.sh:56
  • Esm » Esm.sh » Version: 57
    cpe:2.3:a:esm:esm.sh:57
  • Esm » Esm.sh » Version: 59
    cpe:2.3:a:esm:esm.sh:59
  • Esm » Esm.sh » Version: 60
    cpe:2.3:a:esm:esm.sh:60
  • Esm » Esm.sh » Version: 61
    cpe:2.3:a:esm:esm.sh:61
  • Esm » Esm.sh » Version: 62
    cpe:2.3:a:esm:esm.sh:62
  • Esm » Esm.sh » Version: 63
    cpe:2.3:a:esm:esm.sh:63
  • Esm » Esm.sh » Version: 64
    cpe:2.3:a:esm:esm.sh:64
  • Esm » Esm.sh » Version: 65
    cpe:2.3:a:esm:esm.sh:65
  • Esm » Esm.sh » Version: 66
    cpe:2.3:a:esm:esm.sh:66
  • Esm » Esm.sh » Version: 67
    cpe:2.3:a:esm:esm.sh:67
  • Esm » Esm.sh » Version: 68
    cpe:2.3:a:esm:esm.sh:68
  • Esm » Esm.sh » Version: 69
    cpe:2.3:a:esm:esm.sh:69
  • Esm » Esm.sh » Version: 70
    cpe:2.3:a:esm:esm.sh:70
  • Esm » Esm.sh » Version: 71
    cpe:2.3:a:esm:esm.sh:71
  • Esm » Esm.sh » Version: 72
    cpe:2.3:a:esm:esm.sh:72
  • Esm » Esm.sh » Version: 73
    cpe:2.3:a:esm:esm.sh:73
  • Esm » Esm.sh » Version: 74
    cpe:2.3:a:esm:esm.sh:74
  • Esm » Esm.sh » Version: 75
    cpe:2.3:a:esm:esm.sh:75
  • Esm » Esm.sh » Version: 76
    cpe:2.3:a:esm:esm.sh:76
  • Esm » Esm.sh » Version: 77
    cpe:2.3:a:esm:esm.sh:77
  • Esm » Esm.sh » Version: 78
    cpe:2.3:a:esm:esm.sh:78
  • Esm » Esm.sh » Version: 79
    cpe:2.3:a:esm:esm.sh:79
  • Esm » Esm.sh » Version: 80
    cpe:2.3:a:esm:esm.sh:80
  • Esm » Esm.sh » Version: 81
    cpe:2.3:a:esm:esm.sh:81
  • Esm » Esm.sh » Version: 82
    cpe:2.3:a:esm:esm.sh:82
  • Esm » Esm.sh » Version: 83
    cpe:2.3:a:esm:esm.sh:83
  • Esm » Esm.sh » Version: 84
    cpe:2.3:a:esm:esm.sh:84
  • Esm » Esm.sh » Version: 85
    cpe:2.3:a:esm:esm.sh:85
  • Esm » Esm.sh » Version: 86
    cpe:2.3:a:esm:esm.sh:86
  • Esm » Esm.sh » Version: 87
    cpe:2.3:a:esm:esm.sh:87
  • Esm » Esm.sh » Version: 88
    cpe:2.3:a:esm:esm.sh:88
  • Esm » Esm.sh » Version: 89
    cpe:2.3:a:esm:esm.sh:89
  • Esm » Esm.sh » Version: 90
    cpe:2.3:a:esm:esm.sh:90
  • Esm » Esm.sh » Version: 91
    cpe:2.3:a:esm:esm.sh:91
  • Esm » Esm.sh » Version: 92
    cpe:2.3:a:esm:esm.sh:92
  • Esm » Esm.sh » Version: 93
    cpe:2.3:a:esm:esm.sh:93
  • Esm » Esm.sh » Version: 94
    cpe:2.3:a:esm:esm.sh:94
  • Esm » Esm.sh » Version: 95
    cpe:2.3:a:esm:esm.sh:95
  • Esm » Esm.sh » Version: 96
    cpe:2.3:a:esm:esm.sh:96
  • Esm » Esm.sh » Version: 97
    cpe:2.3:a:esm:esm.sh:97
  • Esm » Esm.sh » Version: 98
    cpe:2.3:a:esm:esm.sh:98
  • Esm » Esm.sh » Version: 99
    cpe:2.3:a:esm:esm.sh:99


Contact Us

Shodan ® - All rights reserved