Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2 advisories

Loading
Handlebars: JavaScript Injection via AST Type Confusion in compile (bypass of CVE-2026-33937) Critical
CVE-2026-106446 was published for handlebars (npm) Oct 8, 2026
ndelphit Credited to ndelphit, bhaswanthc, dinhvaren, jmoritzc53, n0tra4e, hibrian827, sondt99, nikolakojic-rasit, Ahmed-Elmahgob, vk-can, PellaML, shenhuanageshei, kagebunsher, kustundag, ffasterss, and sanmatte bhaswanthc bhaswanthc
dinhvaren dinhvaren jmoritzc53 jmoritzc53 n0tra4e n0tra4e hibrian827 hibrian827 sondt99 sondt99 nikolakojic-rasit nikolakojic-rasit Ahmed-Elmahgob Ahmed-Elmahgob vk-can vk-can PellaML PellaML shenhuanageshei shenhuanageshei kagebunsher kagebunsher kustundag kustundag ffasterss ffasterss sanmatte sanmatte
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors High
CVE-2026-85152 was published for undici (npm) Sep 29, 2026
nikolakojic-rasit Credited to nikolakojic-rasit, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
ProTip! Advisories are also available from the GraphQL API