GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,629
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,149
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
7,280 advisories
Filter by severity
fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
High
CVE-2026-75931
was published
for
fast-uri
(npm)
Sep 2, 2026
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
High
CVE-2026-75975
was published
for
fast-uri
(npm)
Sep 2, 2026
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
High
CVE-2026-75899
was published
for
fast-uri
(npm)
Sep 2, 2026
fast-uri vulnerable to host confusion via percent-encoded scheme normalization
High
CVE-2026-76172
was published
for
fast-uri
(npm)
Sep 2, 2026
xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
Moderate
CVE-2026-83610
was published
for
@xmldom/xmldom
(npm)
Sep 2, 2026
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
Moderate
CVE-2026-16732
was published
for
fastify
(npm)
Sep 2, 2026
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
Moderate
CVE-2026-18504
was published
for
fastify
(npm)
Sep 2, 2026
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
High
CVE-2026-71553
was published
for
apostrophe
(npm)
Sep 2, 2026
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
Moderate
CVE-2026-63667
was published
for
@apostrophecms/import-export
(npm)
Sep 2, 2026
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
High
CVE-2026-62680
was published
for
orval
(npm)
Sep 2, 2026
Orval: Import-time RCE via query-parameter default -> zod module-level template literal
Critical
CVE-2026-72716
was published
for
orval
(npm)
Sep 2, 2026
Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client
Critical
CVE-2026-71866
was published
for
orval
(npm)
Sep 2, 2026
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
Moderate
CVE-2026-73845
was published
for
@aborruso/ckan-mcp-server
(npm)
Sep 2, 2026
qs array-limit bypass via bracket-key comma parsing
Moderate
CVE-2026-82562
was published
for
qs
(npm)
Sep 2, 2026
qs: Denial of Service via Attacker Controlled isBuffer
Moderate
CVE-2026-82417
was published
for
qs
(npm)
Sep 2, 2026
Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes
Moderate
GHSA-cp6q-959q-f8rh
was published
for
@tiptap/core
(npm)
Sep 2, 2026
pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph
High
CVE-2026-82392
was published
for
pnpm
(npm)
Sep 2, 2026
pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
High
CVE-2026-82393
was published
for
pnpm
(npm)
Sep 2, 2026
humanfs: Recursive copy follows symlinked files and copies data from outside the source tree
Moderate
GHSA-p498-v437-472g
was published
for
@humanfs/node
(npm)
Sep 2, 2026
Faker: helpers.fake exploitable into arbritary code execution
High
CVE-2026-73231
was published
for
@faker-js/faker
(npm)
Sep 2, 2026
ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
Moderate
CVE-2026-84371
was published
for
sanitize-html
(npm)
Sep 1, 2026
nanoid: Integer Overflow or Wraparound
High
CVE-2026-73086
was published
for
nanoid
(npm)
Sep 1, 2026
pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
High
GHSA-vx52-2968-3vc6
was published
for
pnpm
(npm)
Sep 1, 2026
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
High
GHSA-2rx9-3g3h-c2jv
was published
for
pnpm
(npm)
Sep 1, 2026
Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
Moderate
CVE-2026-58191
was published
for
@appium/base-driver
(npm)
Sep 1, 2026
ProTip!
Advisories are also available from the
GraphQL API