GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,714
Maven
5,000+
npm
5,000+
NuGet
1,110
pip
5,000+
Pub
13
RubyGems
1,151
Rust
1,567
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
35,412 advisories
Filter by severity
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
Moderate
CVE-2026-86996
was published
for
n8n
(npm)
Sep 8, 2026
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
Moderate
GHSA-wmmp-3585-3rmp
was published
for
nodemailer
(npm)
Sep 8, 2026
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
High
GHSA-2x7j-588g-ccc2
was published
for
nodemailer
(npm)
Sep 8, 2026
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
Moderate
GHSA-cc9r-2j5m-2m83
was published
for
nodemailer
(npm)
Sep 8, 2026
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
High
GHSA-2q42-4q24-7rgv
was published
for
@typespec/compiler
(npm)
Sep 8, 2026
multer vulnerable to Denial of Service via crafted multipart field names
High
CVE-2026-77078
was published
for
multer
(npm)
Sep 8, 2026
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
High
CVE-2026-77037
was published
for
multer
(npm)
Sep 8, 2026
multer vulnerable to file size limit bypass via async fileFilter race condition
Low
CVE-2026-77063
was published
for
multer
(npm)
Sep 8, 2026
multer vulnerable to Denial of Service via oversized array index in field names
High
CVE-2026-82333
was published
for
multer
(npm)
Sep 8, 2026
morgan vulnerable to Log Forging via unescaped Unicode line separators
Moderate
CVE-2026-15603
was published
for
morgan
(npm)
Sep 8, 2026
Windows ML CLI: CORS misconfig enables localhost RCE
High
CVE-2026-84452
was published
for
winml-cli
(pip)
Sep 8, 2026
mongodb: Reject "." and NUL bytes in database and collection names
High
CVE-2026-81525
was published
for
mongodb/mongodb
(Composer)
Sep 8, 2026
Astro: Remote code execution through AVIF image optimization
Critical
GHSA-26w7-cxv4-gfx2
was published
for
astro
(npm)
Sep 8, 2026
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
Moderate
CVE-2026-84376
was published
for
astro
(npm)
Sep 8, 2026
Composer arbitrary command execution via a malicious package's Perforce source URL
High
CVE-2026-84361
was published
for
composer/composer
(Composer)
Sep 8, 2026
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
High
GHSA-rgj7-g3m4-5g8c
was published
for
sharp
(npm)
Sep 8, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
High
CVE-2026-84375
was published
for
js-yaml
(npm)
Sep 8, 2026
phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery
Moderate
CVE-2026-84308
was published
for
phpseclib
(Composer)
Sep 8, 2026
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
High
GHSA-j95f-988m-3j2f
was published
for
@tiptap/core
(npm)
Sep 8, 2026
Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
Moderate
CVE-2026-84365
was published
for
hono
(npm)
Sep 8, 2026
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
Moderate
CVE-2026-84364
was published
for
hono
(npm)
Sep 8, 2026
Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
Moderate
CVE-2026-84363
was published
for
hono
(npm)
Sep 8, 2026
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
High
CVE-2026-84445
was published
for
google.golang.org/grpc
(Go)
Sep 8, 2026
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Critical
GHSA-2xp9-vwfh-vxw4
was published
for
next
(npm)
Sep 8, 2026
SVGO: removeScripts allows executable links through namespace and control-character bypasses
High
CVE-2026-84370
was published
for
svgo
(npm)
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API