GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
55 advisories
Filter by severity
compression vulnerable to Denial of Service via memory leak on premature response close
High
CVE-2026-87776
was published
for
compression
(npm)
Oct 5, 2026
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
High
CVE-2026-19484
was published
for
@fastify/busboy
(npm)
Oct 2, 2026
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
High
CVE-2026-19481
was published
for
@fastify/busboy
(npm)
Oct 2, 2026
fastify vulnerable to request body replacement via an async validation result collision
High
CVE-2026-84504
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
High
CVE-2026-76169
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to request validation bypass via skipped boolean false schemas
High
CVE-2026-84469
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to header validation bypass via incomplete schema case normalization
High
CVE-2026-84428
was published
for
fastify
(npm)
Sep 30, 2026
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
High
CVE-2026-19534
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
High
CVE-2026-84961
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
High
CVE-2026-85152
was published
for
undici
(npm)
Sep 29, 2026
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
High
CVE-2026-76844
was published
for
webpack-dev-middleware
(npm)
Sep 29, 2026
fast-uri vulnerable to authority injection via an unvalidated port in serialize
High
CVE-2026-84292
was published
for
fast-uri
(npm)
Sep 28, 2026
fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
High
CVE-2026-84394
was published
for
fast-uri
(npm)
Sep 28, 2026
fast-uri vulnerable to host confusion via failed IDN canonicalization
High
CVE-2026-13676
was published
for
fast-uri
(npm)
Jul 21, 2026
multer vulnerable to Denial of Service via crafted multipart field names
High
CVE-2026-77078
was published
for
multer
(npm)
Sep 8, 2026
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
High
CVE-2026-77037
was published
for
multer
(npm)
Sep 8, 2026
multer vulnerable to Denial of Service via oversized array index in field names
High
CVE-2026-82333
was published
for
multer
(npm)
Sep 8, 2026
fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
High
CVE-2026-75931
was published
for
fast-uri
(npm)
Sep 2, 2026
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
High
CVE-2026-75975
was published
for
fast-uri
(npm)
Sep 2, 2026
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
High
CVE-2026-75899
was published
for
fast-uri
(npm)
Sep 2, 2026
fast-uri vulnerable to host confusion via percent-encoded scheme normalization
High
CVE-2026-76172
was published
for
fast-uri
(npm)
Sep 2, 2026
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
High
CVE-2026-6322
was published
for
fast-uri
(npm)
May 8, 2026
fast-uri vulnerable to path traversal via percent-encoded dot segments
High
CVE-2026-6321
was published
for
fast-uri
(npm)
May 8, 2026
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
High
CVE-2026-13697
was published
for
undici
(npm)
Aug 3, 2026
fast-uri vulnerable to host confusion via backslash authority introducer
High
CVE-2026-18446
was published
for
fast-uri
(npm)
Aug 3, 2026
ProTip!
Advisories are also available from the
GraphQL API