https://reddit.com/r/cybersecurity/comments/1tp3ycb/12_npmpypisupplychain_threats_today_20260527/: 12 npm/PyPI/supply-chain threats today (2026-05-27): CVE-2026-43945 (FUXA), CVE-2026-43947 (FUXA), Laravel Lang, durabletask, AntV, node-ipc, TanStack, lightning, ...
Published May 27, 2026
·Updated
Affected Software
12 affected components
npm/fuxa
composer/laravel-lang
pypi/durabletask
npm/antv
npm/node-ipc
npm/tanstack
pypi/lightning
npm/yeoman-environment>=2.9.0<6.0.1
Armoli Technology Cargo Tracking System
Apache Log4j 1.x JMSSink
pypi/langflow
Argo CD Argo CD
Frequently Asked Questions
1
What is the severity of CVE-2026-43945?
CVE-2026-43945 has been classified as a critical security vulnerability.
2
How do I fix CVE-2026-43945?
To fix CVE-2026-43945, users are advised to update to the latest version of the FUXA package.
3
What impact does CVE-2026-43945 have on my application?
CVE-2026-43945 can potentially allow unauthorized access or manipulation of application data.
4
When was CVE-2026-43945 discovered?
CVE-2026-43945 was identified on May 27, 2026.
5
Is CVE-2026-43945 being actively exploited?
There are indications that CVE-2026-43945 is actively targeted by attackers.