npm v12’s Biggest Security Change: From Implicit to Explicit Trust
June 18, 2026 | 14 min read
June 22, 2026
23 min read
JFrog Security Research recently discovered and disclosed a critical vulnerability in FFmpeg, the world's most widely deployed media processing framework. The discovered vulnerability, which we've named PixelSmash, is CVE-2026-8461 - a heap out-of-bounds write in the MagicYUV decoder (CVSS 8.8 High). We escalated this vulnerability from a simple crash all the way to reliable remote…
June 18, 2026 | 14 min read
June 18, 2026 | 5 min read
June 12, 2026 | 5 min read
June 11, 2026 | 6 min read
June 10, 2026 | 4 min read
June 2, 2026 | 6 min read
May 27, 2026 | 6 min read
May 20, 2026 | 8 min read
May 19, 2026 | 9 min read
May 11, 2026 | 11 min read