GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,752
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,571
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
2,637 advisories
Filter by severity
@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
Moderate
CVE-2026-59149
was published
for
@mockoon/cli
(npm)
Sep 11, 2026
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
Moderate
CVE-2026-86073
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
Moderate
CVE-2026-86074
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
Moderate
CVE-2026-86995
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
Moderate
CVE-2026-86085
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
Moderate
CVE-2026-86993
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
Moderate
CVE-2026-86084
was published
for
n8n
(npm)
Sep 10, 2026
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
Moderate
CVE-2026-86080
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
Moderate
CVE-2026-86079
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
Moderate
CVE-2026-86078
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
Moderate
CVE-2026-86994
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
Moderate
CVE-2026-86077
was published
for
n8n
(npm)
Sep 10, 2026
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
Moderate
CVE-2026-88059
was published
for
@angular/common
(npm)
Sep 10, 2026
Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler
Moderate
CVE-2026-88057
was published
for
@angular/compiler
(npm)
Sep 10, 2026
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
Moderate
CVE-2026-86996
was published
for
n8n
(npm)
Sep 8, 2026
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
Moderate
GHSA-wmmp-3585-3rmp
was published
for
nodemailer
(npm)
Sep 8, 2026
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
Moderate
GHSA-cc9r-2j5m-2m83
was published
for
nodemailer
(npm)
Sep 8, 2026
morgan vulnerable to Log Forging via unescaped Unicode line separators
Moderate
CVE-2026-15603
was published
for
morgan
(npm)
Sep 8, 2026
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
Moderate
CVE-2026-84376
was published
for
astro
(npm)
Sep 8, 2026
Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
Moderate
CVE-2026-84365
was published
for
hono
(npm)
Sep 8, 2026
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
Moderate
CVE-2026-84364
was published
for
hono
(npm)
Sep 8, 2026
Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
Moderate
CVE-2026-84363
was published
for
hono
(npm)
Sep 8, 2026
SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements
Moderate
CVE-2026-84369
was published
for
svgo
(npm)
Sep 8, 2026
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
Moderate
GHSA-8m3c-c648-2xjj
was published
for
nodemailer
(npm)
Sep 8, 2026
xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content
Moderate
CVE-2026-83611
was published
for
@xmldom/xmldom
(npm)
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API