PatchSiren

RebeccaStevens CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH RebeccaStevens CVE published 2026-08-20

CVE-2026-40345

CVE-2026-40345 is a high-severity vulnerability in the deepmerge-ts library, which can cause synchronous crashes or repeated worker restarts when merging attacker-controlled recursive object graphs. This issue arises from the library's failure to track visited objects or object pairs during recursive merging, leading to a RangeError: Maximum call stack size exceeded. Developers and administrators using de [truncated]