Vulnerabilities/

Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()

Severity:
Medium

Description

##EVIDENCE

Screenshot_2026-03-25_090729 <img width=”1919” height=”947” alt=”Screenshot_2026-03-25_090715” src=”https://github.

Recommendation

Update the unhead package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
unhead
Anything's wrong? Let us know Last updated on April 09, 2026