GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,752
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,571
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
7,405 advisories
Filter by severity
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
High
CVE-2026-86081
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
High
CVE-2026-86075
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
High
CVE-2026-86076
was published
for
n8n
(npm)
Sep 10, 2026
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
High
GHSA-x7m8-jrm8-hpvx
was published
for
@eigenpal/docx-editor-core
(npm)
Sep 10, 2026
@openhop/server: Path Traversal in Flow ID File Operations
High
CVE-2026-59179
was published
for
@openhop/server
(npm)
Sep 9, 2026
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
High
CVE-2026-59176
was published
for
functype-mcp-server
(npm)
Sep 9, 2026
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
High
CVE-2026-59160
was published
for
@yeger/turbo-graph
(npm)
Sep 9, 2026
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
High
CVE-2026-59158
was published
for
nuxt-ollama
(npm)
Sep 9, 2026
smol-toml: Denial of Service via malformed TOML documents
High
CVE-2026-85730
was published
for
smol-toml
(npm)
Sep 9, 2026
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
Moderate
CVE-2026-86996
was published
for
n8n
(npm)
Sep 8, 2026
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
Moderate
GHSA-wmmp-3585-3rmp
was published
for
nodemailer
(npm)
Sep 8, 2026
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
High
GHSA-2x7j-588g-ccc2
was published
for
nodemailer
(npm)
Sep 8, 2026
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
Moderate
GHSA-cc9r-2j5m-2m83
was published
for
nodemailer
(npm)
Sep 8, 2026
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
High
GHSA-2q42-4q24-7rgv
was published
for
@typespec/compiler
(npm)
Sep 8, 2026
multer vulnerable to Denial of Service via crafted multipart field names
High
CVE-2026-77078
was published
for
multer
(npm)
Sep 8, 2026
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
High
CVE-2026-77037
was published
for
multer
(npm)
Sep 8, 2026
multer vulnerable to file size limit bypass via async fileFilter race condition
Low
CVE-2026-77063
was published
for
multer
(npm)
Sep 8, 2026
multer vulnerable to Denial of Service via oversized array index in field names
High
CVE-2026-82333
was published
for
multer
(npm)
Sep 8, 2026
morgan vulnerable to Log Forging via unescaped Unicode line separators
Moderate
CVE-2026-15603
was published
for
morgan
(npm)
Sep 8, 2026
Astro: Remote code execution through AVIF image optimization
Critical
GHSA-26w7-cxv4-gfx2
was published
for
astro
(npm)
Sep 8, 2026
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
Moderate
CVE-2026-84376
was published
for
astro
(npm)
Sep 8, 2026
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
High
GHSA-rgj7-g3m4-5g8c
was published
for
sharp
(npm)
Sep 8, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
High
CVE-2026-84375
was published
for
js-yaml
(npm)
Sep 8, 2026
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
High
GHSA-j95f-988m-3j2f
was published
for
@tiptap/core
(npm)
Sep 8, 2026
Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
Moderate
CVE-2026-84365
was published
for
hono
(npm)
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API