Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,637 advisories

Loading
miauzxw Credited to miauzxw and geo-chen geo-chen geo-chen
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution Moderate
CVE-2026-86073 was published for n8n (npm) Sep 10, 2026
bariskececi Credited to bariskececi
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content Moderate
CVE-2026-86074 was published for n8n (npm) Sep 10, 2026
nlgbao1340 Credited to nlgbao1340
Masofgon Credited to Masofgon
mtholmquist Credited to mtholmquist
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check Moderate
CVE-2026-86993 was published for n8n (npm) Sep 10, 2026
nlgbao1340 Credited to nlgbao1340
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions Moderate
CVE-2026-86084 was published for n8n (npm) Sep 10, 2026
vonypeto Credited to vonypeto
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers Moderate
CVE-2026-86079 was published for n8n (npm) Sep 10, 2026
vonypeto Credited to vonypeto
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service Moderate
CVE-2026-86078 was published for n8n (npm) Sep 10, 2026
Masofgon Credited to Masofgon
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter Moderate
CVE-2026-86994 was published for n8n (npm) Sep 10, 2026
tr4ce-ju Credited to tr4ce-ju
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket Moderate
CVE-2026-86077 was published for n8n (npm) Sep 10, 2026
tr4ce-ju Credited to tr4ce-ju
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent` Moderate
CVE-2026-88059 was published for @angular/common (npm) Sep 10, 2026
JeanMeche Credited to JeanMeche, alan-agius4, and SkyZeroZx alan-agius4 alan-agius4
SkyZeroZx SkyZeroZx
SkyZeroZx Credited to SkyZeroZx, josephperrott, alan-agius4, and JeanMeche josephperrott josephperrott
alan-agius4 alan-agius4 JeanMeche JeanMeche
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy Moderate
CVE-2026-86996 was published for n8n (npm) Sep 8, 2026
vonypeto Credited to vonypeto
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain Moderate
GHSA-wmmp-3585-3rmp was published for nodemailer (npm) Sep 8, 2026
e1abrador Credited to e1abrador
e1abrador Credited to e1abrador
morgan vulnerable to Log Forging via unescaped Unicode line separators Moderate
CVE-2026-15603 was published for morgan (npm) Sep 8, 2026
mfazrinizar Credited to mfazrinizar, UlisesGascon, jonchurch, bjohansebas, and iaohkut-from-NightWolf-Team UlisesGascon UlisesGascon
jonchurch jonchurch bjohansebas bjohansebas iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
Ryoga-exe Credited to Ryoga-exe
pacocartones Credited to pacocartones and LeonMAG LeonMAG LeonMAG
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion Moderate
CVE-2026-84364 was published for hono (npm) Sep 8, 2026
Rikuxx0 Credited to Rikuxx0
SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements Moderate
CVE-2026-84369 was published for svgo (npm) Sep 8, 2026
Alopsis Credited to Alopsis
Hcamael Credited to Hcamael
karfau Credited to karfau
ProTip! Advisories are also available from the GraphQL API