A newly disclosed zero-day in a widely-used dependency resolution tool affects over 14,000 packages across the npm ecosystem.
| CVE ID | Package | Severity | SBOM Impact |
|---|---|---|---|
| CVE-2026-1847 | npm-resolver | 9.8 | Direct dependency |
| CVE-2026-1832 | libxml2 | 7.5 | Transitive |
| CVE-2026-1819 | openssl | 7.2 | Direct dependency |
| CVE-2026-1804 | log4j-core | 5.3 | Transitive |
| CVE-2026-1791 | flask | 3.1 | Dev dependency |
This week's CISA mandate announcement marks a turning point: 92% of federal agencies now have SBOM generation pipelines in place, up from just 34% in 2024. The mandate's Q4 deadline for contractor compliance will impact an estimated 8,400 vendors.
On the standards front, CycloneDX 1.7's addition of ML model transparency fields positions it as the first SBOM format to address AI supply-chain risks — a space where 67% of organizations report zero visibility.