GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
7,706 advisories
Filter by severity
@vue/server-renderer: XSS via missing CR in attribute-name blacklist
High
GHSA-g2v6-rqmx-r4w6
was published
for
@vue/server-renderer
(npm)
Oct 5, 2026
Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution
Critical
CVE-2026-104848
was published
for
tinypool
(npm)
Oct 5, 2026
Tinypool: Prototype Pollution Gadget to RCE in run() options
Critical
CVE-2026-104849
was published
for
tinypool
(npm)
Oct 5, 2026
stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk
Moderate
CVE-2026-104182
was published
for
stream-json
(npm)
Oct 5, 2026
stream-json has a prototype pollution issue: Assembler writes this.current[this.key] on plain objects
Moderate
CVE-2026-104183
was published
for
stream-json
(npm)
Oct 5, 2026
vm2: `allowAsync: false` can be bypassed through Promise thenable assimilation in VM and NodeVM
High
CVE-2026-92959
was published
for
vm2
(npm)
Oct 5, 2026
vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
Critical
CVE-2026-92954
was published
for
vm2
(npm)
Oct 5, 2026
vm2: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix
Critical
CVE-2026-92953
was published
for
vm2
(npm)
Oct 5, 2026
vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
Critical
CVE-2026-92934
was published
for
vm2
(npm)
Oct 5, 2026
vm2: util.getCallSites() bypasses GHSA-v27g-jcqj-v8rw host-frame redaction, leaks host call stack
Moderate
CVE-2026-92933
was published
for
vm2
(npm)
Oct 5, 2026
ProseMirror has a XSS vulnerability in prosemirror-view's paste handling
High
CVE-2026-104847
was published
for
prosemirror-view
(npm)
Oct 5, 2026
vm2 leaks absolute host filesystem paths to sandbox code via error stack formatting
Moderate
CVE-2026-92936
was published
for
vm2
(npm)
Oct 5, 2026
vm2: timeout Option Bypass via FinalizationRegistry Cleanup Callback (Unbounded Host Event-Loop Block)
High
CVE-2026-92942
was published
for
vm2
(npm)
Oct 5, 2026
vm2: NodeVM `require.external` without an explicit `require.root` grants unrestricted host filesystem access and full RCE
Critical
CVE-2026-92946
was published
for
vm2
(npm)
Oct 5, 2026
vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool
Critical
CVE-2026-92947
was published
for
vm2
(npm)
Oct 5, 2026
vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass
Critical
CVE-2026-92956
was published
for
vm2
(npm)
Oct 5, 2026
@fastify/busboy vulnerable to CRLF injection via multipart Content-Disposition filename and name
Moderate
CVE-2026-74866
was published
for
@fastify/busboy
(npm)
Oct 5, 2026
@orpc/zod: Prototype injection in smart coercion
Moderate
CVE-2026-103918
was published
for
@orpc/zod
(npm)
Oct 5, 2026
probe-image-size: Quadratic-time Denial of Service in the SVG Parser
High
CVE-2026-104861
was published
for
probe-image-size
(npm)
Oct 2, 2026
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
High
CVE-2026-19481
was published
for
@fastify/busboy
(npm)
Oct 2, 2026
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
High
CVE-2026-19484
was published
for
@fastify/busboy
(npm)
Oct 2, 2026
@a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions
Critical
CVE-2026-10032
was published
for
@a2ui/web_core
(npm)
Oct 2, 2026
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values
Moderate
GHSA-fj2x-mqqp-3v2w
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Cross-environment deployment cancel
Moderate
GHSA-4672-hwv6-gq62
was published
for
trigger.dev
(npm)
Oct 2, 2026
ProTip!
Advisories are also available from the
GraphQL API