Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,405 advisories

Loading
Orval: Import-time RCE via schema default -> zod module-level template literal Critical
CVE-2026-72717 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via array-items default -> zod module-level template literal Critical
CVE-2026-71869 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via header-parameter default -> zod module-level template literal Critical
CVE-2026-71871 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator Critical
CVE-2026-71867 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via enum-typed default -> zod module-level template literal Critical
CVE-2026-71868 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli Critical
CVE-2026-71865 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Gal3m Credited to Gal3m, mrostamipoor, aqeelat, and mohammad228 mrostamipoor mrostamipoor
aqeelat aqeelat mohammad228 mohammad228
LiquidJS has an infinite loop vulnerability in its `strip_html` filter High
CVE-2026-61556 was published for liquidjs (npm) Sep 3, 2026
NariyoshiChida Credited to NariyoshiChida
OpenClaw Feishu permission tools could ignore per-account disablement High
GHSA-w8wf-3qvj-6xqf was published for @openclaw/feishu (npm) Sep 3, 2026
rexpository Credited to rexpository
OpenClaw Feishu tools could ignore per-account disablement High
GHSA-2q7j-2vhx-56g8 was published for @openclaw/feishu (npm) Sep 3, 2026
rexpository Credited to rexpository
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning Moderate
CVE-2026-73846 was published for @aborruso/ckan-mcp-server (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
CKAN MCP Server: Information disclosure via verbose error reflection Low
CVE-2026-73844 was published for @aborruso/ckan-mcp-server (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
rz1027 Credited to rz1027
Plate: SSRF with response disclosure in DOCX image embedding High
CVE-2026-65842 was published for @platejs/docx-io (npm) Sep 2, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897 High
CVE-2026-61704 was published for link-preview-js (npm) Sep 2, 2026
ahmet-sahiner Credited to ahmet-sahiner
baeseungwon1010 Credited to baeseungwon1010, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization High
CVE-2026-75975 was published for fast-uri (npm) Sep 2, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding High
CVE-2026-75899 was published for fast-uri (npm) Sep 2, 2026
NotAFlightRisk Credited to NotAFlightRisk, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
fast-uri vulnerable to host confusion via percent-encoded scheme normalization High
CVE-2026-76172 was published for fast-uri (npm) Sep 2, 2026
YashvantHange Credited to YashvantHange, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization Moderate
CVE-2026-83610 was published for @xmldom/xmldom (npm) Sep 2, 2026
Paranoidgrinch Credited to Paranoidgrinch
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count Moderate
CVE-2026-16732 was published for fastify (npm) Sep 2, 2026
alimony Credited to alimony, mcollina, climba03003, and UlisesGascon mcollina mcollina
climba03003 climba03003 UlisesGascon UlisesGascon
fastify vulnerable to schema validation bypass via root primitive coercion mismatch Moderate
CVE-2026-18504 was published for fastify (npm) Sep 2, 2026
velgusgus599 Credited to velgusgus599, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS High
CVE-2026-71553 was published for apostrophe (npm) Sep 2, 2026
breakingsystems Credited to breakingsystems
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal Moderate
CVE-2026-63667 was published for @apostrophecms/import-export (npm) Sep 2, 2026
kah-ja Credited to kah-ja and luuhung1217 luuhung1217 luuhung1217
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref High
CVE-2026-62680 was published for orval (npm) Sep 2, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
ProTip! Advisories are also available from the GraphQL API