Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

468 advisories

Loading
multer vulnerable to file size limit bypass via async fileFilter race condition Low
CVE-2026-77063 was published for multer (npm) Sep 8, 2026
ThinkerHao Credited to ThinkerHao, bjohansebas, and UlisesGascon bjohansebas bjohansebas
UlisesGascon UlisesGascon
joi: Prototype pollution via a `__proto__` language key in custom messages Low
CVE-2026-84368 was published for @hapi/joi (npm) Sep 8, 2026
tihanyin Credited to tihanyin and mordamin mordamin mordamin
joi: object().rename() with a template target can set the validated object's prototype Low
CVE-2026-84367 was published for joi (npm) Sep 8, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, and 7thParkk Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk
Josh-TantoSec Credited to Josh-TantoSec
CKAN MCP Server: Information disclosure via verbose error reflection Low
CVE-2026-73844 was published for @aborruso/ckan-mcp-server (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
sondt99 Credited to sondt99
Hono: Proxy Helper does not remove response headers listed in the `Connection` header Low
CVE-2026-71849 was published for hono (npm) Aug 7, 2026
morgan-coded Credited to morgan-coded
Mermaid configuration APIs allow prototype pollution Low
CVE-2026-71438 was published for mermaid (npm) Aug 6, 2026
Str1ckl4nd Credited to Str1ckl4nd, Zyy0530, 7thParkk, mauriceng98, and aloisklink Zyy0530 Zyy0530
7thParkk 7thParkk mauriceng98 mauriceng98 aloisklink aloisklink
Electron: Cross-origin iframe can position native autofill popup Low
CVE-2026-70600 was published for electron (npm) Aug 5, 2026
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size Low
CVE-2026-70598 was published for electron (npm) Aug 5, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header Low
CVE-2026-53607 was published for apostrophe (npm) Jul 31, 2026
EchoSkorJjj Credited to EchoSkorJjj
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate Low
GHSA-pc2w-4mq8-32qw was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 29, 2026
yotampe-pluto Credited to yotampe-pluto
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion Low
GHSA-464c-974j-9xm6 was published for @aws-cdk/aws-codebuild (Go) Jul 24, 2026
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. Low
GHSA-c2j3-45gr-mqc4 was published for dompurify (npm) Jul 21, 2026
Rikuxx0 Credited to Rikuxx0
sec-reex Credited to sec-reex and LlewxamDev LlewxamDev LlewxamDev
Phillip9587 Credited to Phillip9587, efekrskl, UlisesGascon, and bjohansebas efekrskl efekrskl
UlisesGascon UlisesGascon bjohansebas bjohansebas
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect Low
CVE-2026-59730 was published for @astrojs/node (npm) Jul 20, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands Low
CVE-2026-59727 was published for astro (npm) Jul 20, 2026
jlgore Credited to jlgore
Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__ Low
CVE-2026-54335 was published for @feathersjs/commons (npm) Jul 14, 2026
ridingsa Credited to ridingsa
Waku has an Open Redirect via `unstable_redirect` Helper Low
CVE-2026-49456 was published for waku (npm) Jul 8, 2026
j0hndo Credited to j0hndo
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows Low
GHSA-2vg6-77g8-24mp was published for @better-auth/scim (npm) Jul 7, 2026
iruizsalinas Credited to iruizsalinas
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement Low
GHSA-3wqp-prf6-2m72 was published for openclaw (npm) Jul 2, 2026
zsxsoft Credited to zsxsoft, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url Low
GHSA-rp72-5v5q-2446 was published for @cardano402/mcp-server (npm) Jun 26, 2026
MorganOnCode Credited to MorganOnCode
neotoma has tenant isolation gap in relationship query endpoints Low
GHSA-wrr4-782v-jhwh was published for neotoma (npm) Jun 25, 2026
Duplicate Advisory: Cross-site scripting via <NoScript> slot content in Nuxt's head components Low
GHSA-xppm-jmw6-fhmf was published for nuxt (npm) Jun 20, 2026 withdrawn
ProTip! Advisories are also available from the GraphQL API