Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

13,137 advisories

Loading
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization High
CVE-2026-75975 was published for fast-uri (npm) Sep 2, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
fastify vulnerable to schema validation bypass via root primitive coercion mismatch Moderate
CVE-2026-18504 was published for fastify (npm) Sep 2, 2026
velgusgus599 Credited to velgusgus599, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`) Moderate
CVE-2026-73845 was published for @aborruso/ckan-mcp-server (npm) Sep 2, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. Critical Unreviewed
CVE-2026-84135 was published Sep 1, 2026
Socket.IO: Engine.IO WebTransport SID DoS High
CVE-2026-59724 was published for engine.io (npm) Aug 31, 2026
ni8walk3r Credited to ni8walk3r
A malicious actor with access to the network could exploit an Improper Input Validation... Critical Unreviewed
CVE-2026-77554 was published Aug 28, 2026
A malicious actor with access to the network could exploit an Improper Input Validation... Critical Unreviewed
CVE-2026-77537 was published Aug 28, 2026
ProTip! Advisories are also available from the GraphQL API