npm vulnerability intelligence

flatted NPM Package
Vulnerability Check

A super light and fast circular JSON parser.

High severity ISC v3.4.2
Vulnerability Analysis OSV Live

flatted

v3.4.2 · ISC · 129,438,433 dl/wk

Advisory Breakdown

Critical 0
High 2
Moderate 0
Low 0

Severity Rating

High severity

2 advisories

High severity

Weekly downloads

129,438,433

Total advisories

2

Latest version

3.4.2

License

ISC

Known advisories

OSV records for the npm ecosystem

2
GHSA-25h7-pfq9-p65f CVE-2026-32141 high

flatted vulnerable to unbounded recursion DoS in parse() revive phase

Affected: >=0 <3.4.0 Fixed in: 3.4.0 Updated Mar 17, 2026
View source
GHSA-rf6f-7fwh-wjgh CVE-2026-33228 high

Prototype Pollution via parse() in NodeJS flatted

Affected: >=0 <3.4.2 Fixed in: 3.4.2 Updated Mar 25, 2026
View source

Checked Jun 15, 2026, 11:43 AM from npm and OSV.dev

Package metadata

From the npm registry

Package name
flatted
Ecosystem
npm
Latest version
3.4.2
License
ISC
Weekly downloads
129,438,433

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 6/15/2026, 11:43:24 AM