Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12 advisories

Loading
undici vulnerable to downstream response splitting via retry interceptor Low
CVE-2026-18540 was published for undici (npm) Sep 29, 2026
samuel871211 Credited to samuel871211, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
undici vulnerable to caching and replay of unsafe HTTP method responses Low
CVE-2026-85008 was published for undici (npm) Sep 29, 2026
MegaManSec Credited to MegaManSec, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
multer vulnerable to file size limit bypass via async fileFilter race condition Low
CVE-2026-77063 was published for multer (npm) Sep 8, 2026
ThinkerHao Credited to ThinkerHao, bjohansebas, and UlisesGascon bjohansebas bjohansebas
UlisesGascon UlisesGascon
Phillip9587 Credited to Phillip9587, efekrskl, UlisesGascon, and bjohansebas efekrskl efekrskl
UlisesGascon UlisesGascon bjohansebas bjohansebas
UlisesGascon Credited to UlisesGascon, KhafraDev, and mcollina KhafraDev KhafraDev
mcollina mcollina
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse Low
CVE-2026-6733 was published for undici (npm) Jun 19, 2026
mcollina Credited to mcollina, UlisesGascon, and EchoTydes UlisesGascon UlisesGascon
EchoTydes EchoTydes
Withdrawn Advisory: express improperly controls modification of query properties Low
CVE-2024-51999 was published for express (npm) Dec 1, 2025 • withdrawn
ctcpip Credited to ctcpip, wesleytodd, jonchurch, bjohansebas, and UlisesGascon wesleytodd wesleytodd
jonchurch jonchurch bjohansebas bjohansebas UlisesGascon UlisesGascon
on-headers is vulnerable to http response header manipulation Low
CVE-2025-7339 was published for on-headers (npm) Jul 17, 2025
ctcpip Credited to ctcpip, jonchurch, SPodjasek, UlisesGascon, sheplu, and Zen-cronic jonchurch jonchurch
SPodjasek SPodjasek UlisesGascon UlisesGascon sheplu sheplu Zen-cronic Zen-cronic
send vulnerable to template injection that can lead to XSS Low
CVE-2024-43799 was published for send (npm) Sep 10, 2024
AdamKorcz Credited to AdamKorcz, UlisesGascon, ctcpip, and wesleytodd UlisesGascon UlisesGascon
ctcpip ctcpip wesleytodd wesleytodd
serve-static vulnerable to template injection that can lead to XSS Low
CVE-2024-43800 was published for serve-static (npm) Sep 10, 2024
AdamKorcz Credited to AdamKorcz, UlisesGascon, ctcpip, and wesleytodd UlisesGascon UlisesGascon
ctcpip ctcpip wesleytodd wesleytodd
express vulnerable to XSS via response.redirect() Low
CVE-2024-43796 was published for express (npm) Sep 10, 2024
AdamKorcz Credited to AdamKorcz, UlisesGascon, ctcpip, and wesleytodd UlisesGascon UlisesGascon
ctcpip ctcpip wesleytodd wesleytodd
ProTip! Advisories are also available from the GraphQL API