Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,412 advisories

Loading
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy Moderate
CVE-2026-86996 was published for n8n (npm) Sep 8, 2026
vonypeto Credited to vonypeto
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain Moderate
GHSA-wmmp-3585-3rmp was published for nodemailer (npm) Sep 8, 2026
e1abrador Credited to e1abrador
e1abrador Credited to e1abrador
e1abrador Credited to e1abrador
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree High
GHSA-2q42-4q24-7rgv was published for @typespec/compiler (npm) Sep 8, 2026
NLx64 Credited to NLx64
multer vulnerable to Denial of Service via crafted multipart field names High
CVE-2026-77078 was published for multer (npm) Sep 8, 2026
O4FDev Credited to O4FDev and UlisesGascon UlisesGascon UlisesGascon
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads High
CVE-2026-77037 was published for multer (npm) Sep 8, 2026
dkoazw Credited to dkoazw, EmirCobanOfficial, bjohansebas, and UlisesGascon EmirCobanOfficial EmirCobanOfficial
bjohansebas bjohansebas UlisesGascon UlisesGascon
multer vulnerable to file size limit bypass via async fileFilter race condition Low
CVE-2026-77063 was published for multer (npm) Sep 8, 2026
ThinkerHao Credited to ThinkerHao, bjohansebas, and UlisesGascon bjohansebas bjohansebas
UlisesGascon UlisesGascon
multer vulnerable to Denial of Service via oversized array index in field names High
CVE-2026-82333 was published for multer (npm) Sep 8, 2026
O4FDev Credited to O4FDev, UlisesGascon, and arpitjain099 UlisesGascon UlisesGascon
arpitjain099 arpitjain099
morgan vulnerable to Log Forging via unescaped Unicode line separators Moderate
CVE-2026-15603 was published for morgan (npm) Sep 8, 2026
mfazrinizar Credited to mfazrinizar, UlisesGascon, jonchurch, bjohansebas, and iaohkut-from-NightWolf-Team UlisesGascon UlisesGascon
jonchurch jonchurch bjohansebas bjohansebas iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
Windows ML CLI: CORS misconfig enables localhost RCE High
CVE-2026-84452 was published for winml-cli (pip) Sep 8, 2026
mongodb: Reject "." and NUL bytes in database and collection names High
CVE-2026-81525 was published for mongodb/mongodb (Composer) Sep 8, 2026
Astro: Remote code execution through AVIF image optimization Critical
GHSA-26w7-cxv4-gfx2 was published for astro (npm) Sep 8, 2026
cn-panda Credited to cn-panda
Ryoga-exe Credited to Ryoga-exe
Composer arbitrary command execution via a malicious package's Perforce source URL High
CVE-2026-84361 was published for composer/composer (Composer) Sep 8, 2026
Saku0512 Credited to Saku0512
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545 High
GHSA-rgj7-g3m4-5g8c was published for sharp (npm) Sep 8, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources High
CVE-2026-84375 was published for js-yaml (npm) Sep 8, 2026
phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery Moderate
CVE-2026-84308 was published for phpseclib (Composer) Sep 8, 2026
geostergiop Credited to geostergiop
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing High
GHSA-j95f-988m-3j2f was published for @tiptap/core (npm) Sep 8, 2026
joostgrunwald Credited to joostgrunwald
pacocartones Credited to pacocartones and LeonMAG LeonMAG LeonMAG
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion Moderate
CVE-2026-84364 was published for hono (npm) Sep 8, 2026
Rikuxx0 Credited to Rikuxx0
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers High
CVE-2026-84445 was published for google.golang.org/grpc (Go) Sep 8, 2026
matiasinsaurralde Credited to matiasinsaurralde
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used Critical
GHSA-2xp9-vwfh-vxw4 was published for next (npm) Sep 8, 2026
NotAFlightRisk Credited to NotAFlightRisk
ProTip! Advisories are also available from the GraphQL API