GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,413
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,656
Pub
13
RubyGems
1,027
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
536 advisories
Filter by severity
defu: Prototype pollution via `__proto__` key in defaults argument
High
CVE-2026-35209
was published
for
defu
(npm)
Apr 4, 2026
@stablelib/cbor: Prototype poisoning via `__proto__` map keys in CBOR decoding
High
GHSA-w48f-fwg7-ww6p
was published
for
@stablelib/cbor
(npm)
Apr 4, 2026
DOMPurify USE_PROFILES prototype pollution allows event handlers
Moderate
GHSA-cj63-jhhr-wcxv
was published
for
dompurify
(npm)
Apr 3, 2026
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`
Moderate
CVE-2026-2950
was published
for
lodash
(npm)
Apr 1, 2026
MikroORM has Prototype Pollution in Utils.merge
High
CVE-2026-34221
was published
for
@mikro-orm/core
(npm)
Mar 29, 2026
Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry
Moderate
GHSA-7rx3-28cr-v5wh
was published
for
handlebars
(npm)
Mar 29, 2026
Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521
Moderate
CVE-2026-33994
was published
for
locutus
(npm)
Mar 27, 2026
Locutus has Prototype Pollution via __proto__ Key Injection in unserialize()
Moderate
CVE-2026-33993
was published
for
locutus
(npm)
Mar 27, 2026
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
Moderate
CVE-2026-33916
was published
for
handlebars
(npm)
Mar 26, 2026
Convict has Prototype Pollution via startsWith() function
Critical
CVE-2026-33864
was published
for
convict
(npm)
Mar 26, 2026
Convict has prototype pollution via load(), loadFile(), and schema initialization
Critical
CVE-2026-33863
was published
for
convict
(npm)
Mar 26, 2026
n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE
Critical
CVE-2026-33696
was published
for
n8n
(npm)
Mar 26, 2026
Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
Moderate
CVE-2026-33672
was published
for
picomatch
(npm)
Mar 25, 2026
Prototype Pollution via parse() in NodeJS flatted
High
CVE-2026-33228
was published
for
flatted
(npm)
Mar 19, 2026
Parse Server vulnerable to schema poisoning via prototype pollution in deep copy
Moderate
CVE-2026-32878
was published
for
parse-server
(npm)
Mar 17, 2026
Parse Server's Cloud function dispatch crashes server via prototype chain traversal
High
CVE-2026-32886
was published
for
parse-server
(npm)
Mar 17, 2026
Elysia Cookie Value Prototype Pollution
Moderate
CVE-2026-31865
was published
for
elysia
(npm)
Mar 17, 2026
Apollo Federation vulnerable to prototype pollution via incomplete key sanitization
Critical
CVE-2026-32621
was published
for
@apollo/federation-internals
(npm)
Mar 13, 2026
Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own properties
Low
GHSA-mwv9-gp5h-frr4
was published
for
devalue
(npm)
Mar 12, 2026
devalue has prototype pollution in devalue.parse and devalue.unflatten
Moderate
CVE-2026-30226
was published
for
devalue
(npm)
Mar 12, 2026
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
Moderate
GHSA-v8w9-8mx6-g223
was published
for
hono
(npm)
Mar 11, 2026
Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution
High
CVE-2026-30939
was published
for
parse-server
(npm)
Mar 10, 2026
Immutable is vulnerable to Prototype Pollution
High
CVE-2026-29063
was published
for
immutable
(npm)
Mar 4, 2026
OpenClaw's runtime /debug override path accepted prototype-reserved keys
Low
CVE-2026-27524
was published
for
openclaw
(npm)
Mar 3, 2026
`@orpc/client` has Prototype Pollution via `StandardRPCJsonSerializer` Deserialization
Critical
CVE-2026-28794
was published
for
@orpc/client
(npm)
Mar 2, 2026
ProTip!
Advisories are also available from the
GraphQL API