Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,604 advisories

Loading
danger allows local OS command injection through crafted file paths Moderate
CVE-2026-16629 was published for danger (npm) Jul 23, 2026
Phoenix: Presence keys colliding with `Object.prototype` members break existence checks Moderate
CVE-2026-56812 was published for phoenix (Erlang) Sep 3, 2026
PJUllrich Credited to PJUllrich, maennchen, and SteffenDE maennchen maennchen
SteffenDE SteffenDE
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close Moderate
CVE-2026-63670 was published for sanitize-html (npm) Sep 3, 2026
bibu123456 Credited to bibu123456
fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives Moderate
CVE-2026-45820 was published for fflate (npm) Jul 22, 2026
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning Moderate
CVE-2026-73846 was published for @aborruso/ckan-mcp-server (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
rz1027 Credited to rz1027
MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS Moderate
GHSA-rgwj-5xj2-c3m3 was published for mysql2 (npm) Aug 31, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization Moderate
CVE-2026-83610 was published for @xmldom/xmldom (npm) Sep 2, 2026
Paranoidgrinch Credited to Paranoidgrinch
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count Moderate
CVE-2026-16732 was published for fastify (npm) Sep 2, 2026
alimony Credited to alimony, mcollina, climba03003, and UlisesGascon mcollina mcollina
climba03003 climba03003 UlisesGascon UlisesGascon
fastify vulnerable to schema validation bypass via root primitive coercion mismatch Moderate
CVE-2026-18504 was published for fastify (npm) Sep 2, 2026
velgusgus599 Credited to velgusgus599, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal Moderate
CVE-2026-63667 was published for @apostrophecms/import-export (npm) Sep 2, 2026
kah-ja Credited to kah-ja and luuhung1217 luuhung1217 luuhung1217
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`) Moderate
CVE-2026-73845 was published for @aborruso/ckan-mcp-server (npm) Sep 2, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
qs array-limit bypass via bracket-key comma parsing Moderate
CVE-2026-82562 was published for qs (npm) Sep 2, 2026
Vectrain51 Credited to Vectrain51, Fcmam5, and ljharb Fcmam5 Fcmam5
ljharb ljharb
qs: Denial of Service via Attacker Controlled isBuffer Moderate
CVE-2026-82417 was published for qs (npm) Sep 2, 2026
waydeshi Credited to waydeshi and ljharb ljharb ljharb
Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes Moderate
GHSA-cp6q-959q-f8rh was published for @tiptap/core (npm) Sep 2, 2026
joostgrunwald Credited to joostgrunwald
humanfs: Recursive copy follows symlinked files and copies data from outside the source tree Moderate
GHSA-p498-v437-472g was published for @humanfs/node (npm) Sep 2, 2026
Jvr2022 Credited to Jvr2022
Flowise: Incomplete Credential Redaction Exposes Secrets via API Moderate
GHSA-rwrp-9823-p2xq was published for flowise (npm) Aug 4, 2026
yuvalo1212 Credited to yuvalo1212
Cross-site Scripting (XSS) in serialize-javascript Moderate
CVE-2024-11831 was published for serialize-javascript (npm) Feb 10, 2025
mhassan1 Credited to mhassan1
ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass Moderate
CVE-2026-84371 was published for sanitize-html (npm) Sep 1, 2026
koyokr Credited to koyokr
Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes Moderate
CVE-2026-58191 was published for @appium/base-driver (npm) Sep 1, 2026
nikkoenggaliano Credited to nikkoenggaliano
Axios: Nested axios option objects can consume polluted prototype values Moderate
CVE-2026-67319 was published for axios (npm) Jul 20, 2026
asadeddin Credited to asadeddin
Duplicate Advisory: Axios: Nested axios option objects can consume polluted prototype values Moderate
GHSA-9wx3-p993-35vp was published for axios (npm) Aug 1, 2026 withdrawn
ProTip! Advisories are also available from the GraphQL API