VDB
Sign up

package

npm/@builder.io/qwik-city

pkg:npm/%40builder.io/qwik-city

MEDIUM5.9npm
GHSA-vm6g-8r4h-22x8· CVE-2026-25155

Qwik City CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)

Modified: 2/11/2026