CVEs affecting projects tracked on Release Alert, from NVD & OSV.
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor