Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

9 advisories

Loading
RabbitMQ: JSONReader in the default JSON-RPC mapper never terminates on truncated input, causing DoS Moderate
CVE-2026-106121 was published for com.rabbitmq:amqp-client (Maven) Oct 7, 2026
NotAFlightRisk Credited to NotAFlightRisk
simple-git allows command execution through unblocked Git configuration includes High
CVE-2026-102826 was published for simple-git (npm) Oct 5, 2026
bhaswanthc Credited to bhaswanthc and NotAFlightRisk NotAFlightRisk NotAFlightRisk
smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line Moderate
GHSA-r4xh-jqrq-34v2 was published for smol-toml (npm) Oct 5, 2026
NotAFlightRisk Credited to NotAFlightRisk
Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization High
CVE-2026-104845 was published for seroval (npm) Oct 5, 2026
NotAFlightRisk Credited to NotAFlightRisk
stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk Moderate
CVE-2026-104182 was published for stream-json (npm) Oct 5, 2026
NotAFlightRisk Credited to NotAFlightRisk
NotAFlightRisk Credited to NotAFlightRisk
NotAFlightRisk Credited to NotAFlightRisk and lissy93 lissy93 lissy93
NotAFlightRisk Credited to NotAFlightRisk
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding High
CVE-2026-75899 was published for fast-uri (npm) Sep 2, 2026
NotAFlightRisk Credited to NotAFlightRisk, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
ProTip! Advisories are also available from the GraphQL API