Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,280 advisories

Loading
baeseungwon1010 Credited to baeseungwon1010, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization High
CVE-2026-75975 was published for fast-uri (npm) Sep 2, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding High
CVE-2026-75899 was published for fast-uri (npm) Sep 2, 2026
NotAFlightRisk Credited to NotAFlightRisk, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
fast-uri vulnerable to host confusion via percent-encoded scheme normalization High
CVE-2026-76172 was published for fast-uri (npm) Sep 2, 2026
YashvantHange Credited to YashvantHange, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization Moderate
CVE-2026-83610 was published for @xmldom/xmldom (npm) Sep 2, 2026
Paranoidgrinch Credited to Paranoidgrinch
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count Moderate
CVE-2026-16732 was published for fastify (npm) Sep 2, 2026
alimony Credited to alimony, mcollina, climba03003, and UlisesGascon mcollina mcollina
climba03003 climba03003 UlisesGascon UlisesGascon
fastify vulnerable to schema validation bypass via root primitive coercion mismatch Moderate
CVE-2026-18504 was published for fastify (npm) Sep 2, 2026
velgusgus599 Credited to velgusgus599, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS High
CVE-2026-71553 was published for apostrophe (npm) Sep 2, 2026
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal Moderate
CVE-2026-63667 was published for @apostrophecms/import-export (npm) Sep 2, 2026
kah-ja Credited to kah-ja and luuhung1217 luuhung1217 luuhung1217
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref High
CVE-2026-62680 was published for orval (npm) Sep 2, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via query-parameter default -> zod module-level template literal Critical
CVE-2026-72716 was published for orval (npm) Sep 2, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`) Moderate
CVE-2026-73845 was published for @aborruso/ckan-mcp-server (npm) Sep 2, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
qs array-limit bypass via bracket-key comma parsing Moderate
CVE-2026-82562 was published for qs (npm) Sep 2, 2026
Vectrain51 Credited to Vectrain51, Fcmam5, and ljharb Fcmam5 Fcmam5
ljharb ljharb
qs: Denial of Service via Attacker Controlled isBuffer Moderate
CVE-2026-82417 was published for qs (npm) Sep 2, 2026
waydeshi Credited to waydeshi and ljharb ljharb ljharb
Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes Moderate
GHSA-cp6q-959q-f8rh was published for @tiptap/core (npm) Sep 2, 2026
joostgrunwald Credited to joostgrunwald
manus-use Credited to manus-use
humanfs: Recursive copy follows symlinked files and copies data from outside the source tree Moderate
GHSA-p498-v437-472g was published for @humanfs/node (npm) Sep 2, 2026
Jvr2022 Credited to Jvr2022
Faker: helpers.fake exploitable into arbritary code execution High
CVE-2026-73231 was published for @faker-js/faker (npm) Sep 2, 2026
ST-DDT Credited to ST-DDT and Shinigami92 Shinigami92 Shinigami92
ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass Moderate
CVE-2026-84371 was published for sanitize-html (npm) Sep 1, 2026
koyokr Credited to koyokr
nanoid: Integer Overflow or Wraparound High
CVE-2026-73086 was published for nanoid (npm) Sep 1, 2026
alanzabihi Credited to alanzabihi
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project High
GHSA-2rx9-3g3h-c2jv was published for pnpm (npm) Sep 1, 2026
Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes Moderate
CVE-2026-58191 was published for @appium/base-driver (npm) Sep 1, 2026
nikkoenggaliano Credited to nikkoenggaliano
ProTip! Advisories are also available from the GraphQL API