GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,684
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,554
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
241 advisories
Filter by severity
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
High
CVE-2026-75975
was published
for
fast-uri
(npm)
Sep 2, 2026
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
Moderate
CVE-2026-18504
was published
for
fastify
(npm)
Sep 2, 2026
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
Moderate
CVE-2026-73845
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 2, 2026
Socket.IO: Engine.IO WebTransport SID DoS
High
CVE-2026-59724
was published
for
engine.io
(npm)
Aug 31, 2026
Keystone vulnerable to `graphql.maxTake` bypass with negative `take`
High
CVE-2026-63421
was published
for
@keystone-6/core
(npm)
Aug 21, 2026
MeshCentral has unsanitized data fields
High
GHSA-c7hr-448w-65px
was published
for
meshcentral
(npm)
Aug 18, 2026
Nuxt: Unauthorized Component Instantiation via Server Island Props
Moderate
CVE-2026-71318
was published
for
nuxt
(npm)
Aug 5, 2026
Electron: window.open features string controls some window options considered privileged
Moderate
CVE-2026-70607
was published
for
electron
(npm)
Aug 5, 2026
Electron: shell.openPath path validation bypass via embedded null byte
Moderate
CVE-2026-70603
was published
for
electron
(npm)
Aug 5, 2026
Ghost: Archived Offers can be Redeemed
Moderate
CVE-2026-70589
was published
for
ghost
(npm)
Aug 4, 2026
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
High
CVE-2026-69192
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-69198
was published
for
ip-address
(npm)
Aug 3, 2026
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
Moderate
CVE-2026-54272
was published
for
ip-address
(npm)
Aug 3, 2026
Socket.IO: Zero-attachment Memory Exhaustion
High
CVE-2026-69185
was published
for
socket.io-parser
(npm)
Aug 3, 2026
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
Moderate
CVE-2026-54663
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
Critical
GHSA-rjg6-39jm-rgg4
was published
for
@better-auth/scim
(npm)
Jul 24, 2026
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
High
CVE-2026-73418
was published
for
@auth/core
(npm)
Jul 23, 2026
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
Moderate
GHSA-9cmh-xcqm-5hqr
was published
for
n8n
(npm)
Jul 22, 2026
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
Moderate
CVE-2026-14631
was published
for
webpack-dev-server
(npm)
Jul 20, 2026
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
High
CVE-2026-49866
was published
for
@libp2p/gossipsub
(npm)
Jul 10, 2026
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
Critical
CVE-2026-53513
was published
for
@better-auth/sso
(npm)
Jul 7, 2026
OpenClaw: Trusted retry endpoint checks could match hostname prefixes
High
GHSA-77q5-rr5v-x43q
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
Moderate
CVE-2026-53859
was published
for
openclaw
(npm)
Jun 18, 2026
http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
Moderate
CVE-2026-55602
was published
for
http-proxy-middleware
(npm)
Jun 18, 2026
ProTip!
Advisories are also available from the
GraphQL API