Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,428 advisories

Loading
File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer High
CVE-2026-91127 was published for @file-viewer/doc (npm) Sep 18, 2026
shashank420 Credited to shashank420
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS) High
CVE-2026-77301 was published for adm-zip (npm) Sep 18, 2026
joszamama Credited to joszamama
md-editor-v3: XSS via fenced-code language rendering bypass Moderate
CVE-2026-84992 was published for md-editor-v3 (npm) Sep 18, 2026
koyokr Credited to koyokr
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text High
CVE-2026-77615 was published for org.opencastproject:opencast-engage-paella-player-7 (Maven) Sep 18, 2026
kah-ja Credited to kah-ja
@platejs/core HTML deserialization can trigger browser behavior during parsing Moderate
CVE-2026-88976 was published for @platejs/core (npm) Sep 17, 2026
1diot9 Credited to 1diot9
Svelte devalue: DoS via malformed input Moderate
CVE-2026-81176 was published for devalue (npm) Sep 17, 2026
Rich-Harris Credited to Rich-Harris, kq5y, and elliott-with-the-longest-name-on-github kq5y kq5y
elliott-with-the-longest-name-on-github elliott-with-the-longest-name-on-github
Alleysira Credited to Alleysira
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID High
CVE-2026-86038 was published for @libp2p/gossipsub (npm) Sep 17, 2026
Alleysira Credited to Alleysira
ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion High
CVE-2026-85715 was published for exifreader (npm) Sep 17, 2026
alienkeric Credited to alienkeric
Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site High
CVE-2026-63506 was published for @tinacms/auth (npm) Sep 17, 2026
riodrwn Credited to riodrwn
Redocly CLI: Path traversal when using `split` command Moderate
CVE-2026-63225 was published for @redocly/cli (npm) Sep 17, 2026
thegr1ffyn Credited to thegr1ffyn
oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass Moderate
CVE-2026-77360 was published for @orpc/server (npm) Sep 17, 2026
@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows High
CVE-2026-71538 was published for @cyclonedx/cyclonedx-npm (npm) Sep 17, 2026
fortress07 Credited to fortress07 and jkowalleck jkowalleck jkowalleck
squinard1478 Credited to squinard1478
Vendure: Shop API list queries can return non-public entities when filterOperator is OR Moderate
CVE-2026-63461 was published for @vendure/core (npm) Sep 17, 2026
pavelkohout396 Credited to pavelkohout396
Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends High
CVE-2026-63460 was published for vendure/core (npm) Sep 17, 2026
de3erve Credited to de3erve
Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions High
CVE-2026-63459 was published for @vendure/dashboard (npm) Sep 17, 2026
squinard1478 Credited to squinard1478
Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter Moderate
CVE-2026-61793 was published for nuxt-og-image (npm) Sep 17, 2026
hypnguyen1209 Credited to hypnguyen1209
node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion High
CVE-2026-68904 was published for node-opcua (npm) Sep 16, 2026
Velluso Credited to Velluso and erossignon erossignon erossignon
gil-maman-p Credited to gil-maman-p and hodaya-prz hodaya-prz hodaya-prz
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery Critical
CVE-2026-61559 was published for @zereight/mcp-gitlab (npm) Sep 15, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport Critical
CVE-2026-61568 was published for @zereight/mcp-gitlab (npm) Sep 15, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
yayson: Prototype pollution in Store/LegacyStore deserialization Critical
CVE-2026-61534 was published for yayson (npm) Sep 11, 2026
hackchang Credited to hackchang and jede jede jede
ProTip! Advisories are also available from the GraphQL API