C2fo develops open-source data and file-processing utilities, with disclosures centered on the COMB and Fast-CSV products that handle user-supplied input and object manipulation. The recurring vulnerability classes—prototype pollution and uncontrolled resource consumption—reflect the parsing and object-handling demands inherent to these utility libraries. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by C2fo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23561CRITICAL All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function. | Dec 10, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-26256MEDIUM Fast-csv is an npm package for parsing and formatting CSVs or any other delimited value file in node. In fast-cvs before version 4.3.6 there is a possible ReDoS vulnerability (Regu | Dec 8, 2020 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by C2fo.
Media articles that mention a CVE ID that affects a product developed by C2fo — matched by CVE ID, not by vendor name.