GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
7,428 advisories
Filter by severity
File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
High
CVE-2026-91127
was published
for
@file-viewer/doc
(npm)
Sep 18, 2026
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
High
CVE-2026-77301
was published
for
adm-zip
(npm)
Sep 18, 2026
md-editor-v3: XSS via fenced-code language rendering bypass
Moderate
CVE-2026-84992
was published
for
md-editor-v3
(npm)
Sep 18, 2026
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text
High
CVE-2026-77615
was published
for
org.opencastproject:opencast-engage-paella-player-7
(Maven)
Sep 18, 2026
@platejs/core HTML deserialization can trigger browser behavior during parsing
Moderate
CVE-2026-88976
was published
for
@platejs/core
(npm)
Sep 17, 2026
Svelte devalue: DoS via malformed input
Moderate
CVE-2026-81176
was published
for
devalue
(npm)
Sep 17, 2026
libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses
High
CVE-2026-86039
was published
for
@libp2p/peer-store
(npm)
Sep 17, 2026
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
High
CVE-2026-86038
was published
for
@libp2p/gossipsub
(npm)
Sep 17, 2026
ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion
High
CVE-2026-85715
was published
for
exifreader
(npm)
Sep 17, 2026
Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
High
CVE-2026-63506
was published
for
@tinacms/auth
(npm)
Sep 17, 2026
Redocly CLI: Path traversal when using `split` command
Moderate
CVE-2026-63225
was published
for
@redocly/cli
(npm)
Sep 17, 2026
oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
Moderate
CVE-2026-77360
was published
for
@orpc/server
(npm)
Sep 17, 2026
@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows
High
CVE-2026-71538
was published
for
@cyclonedx/cyclonedx-npm
(npm)
Sep 17, 2026
Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
Critical
CVE-2026-63472
was published
for
@vendure/core
(npm)
Sep 17, 2026
Vendure: Shop API list queries can return non-public entities when filterOperator is OR
Moderate
CVE-2026-63461
was published
for
@vendure/core
(npm)
Sep 17, 2026
Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends
High
CVE-2026-63460
was published
for
vendure/core
(npm)
Sep 17, 2026
Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
High
CVE-2026-63459
was published
for
@vendure/dashboard
(npm)
Sep 17, 2026
Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter
Moderate
CVE-2026-61793
was published
for
nuxt-og-image
(npm)
Sep 17, 2026
@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
High
CVE-2026-63671
was published
for
@nuxtjs/mdc
(npm)
Sep 16, 2026
node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion
High
CVE-2026-68904
was published
for
node-opcua
(npm)
Sep 16, 2026
@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
Critical
CVE-2026-61560
was published
for
@zereight/mcp-gitlab
(npm)
Sep 16, 2026
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
Critical
CVE-2026-61559
was published
for
@zereight/mcp-gitlab
(npm)
Sep 15, 2026
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
Critical
CVE-2026-61568
was published
for
@zereight/mcp-gitlab
(npm)
Sep 15, 2026
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
High
GHSA-5648-rgj9-v224
was published
for
@zereight/mcp-gitlab
(npm)
Sep 15, 2026
yayson: Prototype pollution in Store/LegacyStore deserialization
Critical
CVE-2026-61534
was published
for
yayson
(npm)
Sep 11, 2026
ProTip!
Advisories are also available from the
GraphQL API