GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,604 advisories
Filter by severity
danger allows local OS command injection through crafted file paths
Moderate
CVE-2026-16629
was published
for
danger
(npm)
Jul 23, 2026
Payload CMS default account-unlock access allows authenticated users to reset other accounts' lockouts
Moderate
CVE-2026-11779
was published
for
payload
(npm)
Jun 26, 2026
Phoenix: Presence keys colliding with `Object.prototype` members break existence checks
Moderate
CVE-2026-56812
was published
for
phoenix
(Erlang)
Sep 3, 2026
stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)
Moderate
CVE-2026-71429
was published
for
stream-json
(npm)
Sep 3, 2026
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
Moderate
CVE-2026-63670
was published
for
sanitize-html
(npm)
Sep 3, 2026
ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
Moderate
CVE-2026-63669
was published
for
apostrophe
(npm)
Sep 3, 2026
fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives
Moderate
CVE-2026-45820
was published
for
fflate
(npm)
Jul 22, 2026
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
Moderate
CVE-2026-73846
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 3, 2026
DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
Moderate
CVE-2026-68921
was published
for
@dicebear/core
(npm)
Sep 2, 2026
MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS
Moderate
GHSA-rgwj-5xj2-c3m3
was published
for
mysql2
(npm)
Aug 31, 2026
xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
Moderate
CVE-2026-83610
was published
for
@xmldom/xmldom
(npm)
Sep 2, 2026
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
Moderate
CVE-2026-16732
was published
for
fastify
(npm)
Sep 2, 2026
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
Moderate
CVE-2026-18504
was published
for
fastify
(npm)
Sep 2, 2026
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
Moderate
CVE-2026-63667
was published
for
@apostrophecms/import-export
(npm)
Sep 2, 2026
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
Moderate
CVE-2026-73845
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 2, 2026
qs array-limit bypass via bracket-key comma parsing
Moderate
CVE-2026-82562
was published
for
qs
(npm)
Sep 2, 2026
qs: Denial of Service via Attacker Controlled isBuffer
Moderate
CVE-2026-82417
was published
for
qs
(npm)
Sep 2, 2026
Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes
Moderate
GHSA-cp6q-959q-f8rh
was published
for
@tiptap/core
(npm)
Sep 2, 2026
humanfs: Recursive copy follows symlinked files and copies data from outside the source tree
Moderate
GHSA-p498-v437-472g
was published
for
@humanfs/node
(npm)
Sep 2, 2026
Flowise: Incomplete Credential Redaction Exposes Secrets via API
Moderate
GHSA-rwrp-9823-p2xq
was published
for
flowise
(npm)
Aug 4, 2026
Cross-site Scripting (XSS) in serialize-javascript
Moderate
CVE-2024-11831
was published
for
serialize-javascript
(npm)
Feb 10, 2025
ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
Moderate
CVE-2026-84371
was published
for
sanitize-html
(npm)
Sep 1, 2026
Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
Moderate
CVE-2026-58191
was published
for
@appium/base-driver
(npm)
Sep 1, 2026
Axios: Nested axios option objects can consume polluted prototype values
Moderate
CVE-2026-67319
was published
for
axios
(npm)
Jul 20, 2026
Duplicate Advisory: Axios: Nested axios option objects can consume polluted prototype values
Moderate
GHSA-9wx3-p993-35vp
was published
for
axios
(npm)
Aug 1, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API