GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
43 advisories
Filter by severity
Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend
High
CVE-2026-106505
was published
for
@backstage/plugin-techdocs-node
(npm)
Oct 7, 2026
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets
High
GHSA-9c5c-9qcx-q35q
was published
for
@nestjs/platform-fastify
(npm)
Sep 30, 2026
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
Moderate
CVE-2026-86818
was published
for
fast-uri
(npm)
Sep 29, 2026
Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing
Moderate
GHSA-g57g-f23g-4646
was published
for
nodemailer
(npm)
Sep 29, 2026
adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
Moderate
GHSA-p634-w6r4-rjp2
was published
for
adm-zip
(npm)
Sep 29, 2026
fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
High
CVE-2026-84394
was published
for
fast-uri
(npm)
Sep 28, 2026
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
High
CVE-2026-56669
was published
for
elysia
(npm)
Sep 23, 2026
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
Moderate
GHSA-wmmp-3585-3rmp
was published
for
nodemailer
(npm)
Sep 8, 2026
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
Moderate
GHSA-cc9r-2j5m-2m83
was published
for
nodemailer
(npm)
Sep 8, 2026
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
Moderate
CVE-2026-73846
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 3, 2026
fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
High
CVE-2026-75931
was published
for
fast-uri
(npm)
Sep 2, 2026
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
Moderate
CVE-2026-14643
was published
for
undici
(npm)
Aug 3, 2026
fast-uri vulnerable to host confusion via backslash authority introducer
High
CVE-2026-18446
was published
for
fast-uri
(npm)
Aug 3, 2026
fast-uri vulnerable to host confusion via literal backslash authority delimiter
High
CVE-2026-16221
was published
for
fast-uri
(npm)
Jul 21, 2026
fast-uri vulnerable to host confusion via failed IDN canonicalization
High
CVE-2026-13676
was published
for
fast-uri
(npm)
Jul 21, 2026
@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation
High
CVE-2026-49473
was published
for
@cedar-policy/authorization-for-expressjs
(npm)
Jun 30, 2026
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
Moderate
CVE-2026-53655
was published
for
tar
(npm)
Jun 15, 2026
@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters
High
CVE-2026-44974
was published
for
@hapi/content
(npm)
May 27, 2026
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
High
CVE-2026-42462
was published
for
@fedify/fedify
(npm)
May 26, 2026
Next.js vulnerable to cache poisoning in React Server Component responses
Moderate
CVE-2026-44576
was published
for
next
(npm)
May 11, 2026
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
High
CVE-2026-6322
was published
for
fast-uri
(npm)
May 8, 2026
@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
Critical
CVE-2026-6270
was published
for
@fastify/middie
(npm)
Apr 16, 2026
@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
High
CVE-2026-33804
was published
for
@fastify/middie
(npm)
Apr 16, 2026
Official Clerk JavaScript SDKs: Middleware-based route protection bypass
Critical
CVE-2026-41248
was published
for
@clerk/astro
(npm)
Apr 16, 2026
@fastify/express has a middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)
Critical
CVE-2026-33808
was published
for
@fastify/express
(npm)
Apr 16, 2026
ProTip!
Advisories are also available from the
GraphQL API