Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,706 advisories

Loading
devalue: Residual sparse-array CPU amplification in uneval Moderate
GHSA-hx4r-w6wj-j8fg was published for devalue (npm) Oct 1, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
devalue: Repeated primitive strings cause quadratic expansion in uneval High
GHSA-mcm9-63f2-9j32 was published for devalue (npm) Oct 1, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated Low
GHSA-wf3x-273g-mvxv was published for devalue (npm) Oct 1, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise High
GHSA-x5rw-q4pp-hg5g was published for devalue (npm) Oct 1, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion Moderate
GHSA-4q55-j62x-fr9h was published for devalue (npm) Oct 1, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
Fcmam5 Credited to Fcmam5
NotAFlightRisk Credited to NotAFlightRisk
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses Moderate
CVE-2026-92081 was published for fastify (npm) Sep 30, 2026
zerovulnlabs Credited to zerovulnlabs, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
hono/jsx renders plain strings unescaped in boundary components, leading to XSS Moderate
CVE-2026-93981 was published for hono (npm) Sep 30, 2026
ggmolly Credited to ggmolly
fastify vulnerable to request body replacement via an async validation result collision High
CVE-2026-84504 was published for fastify (npm) Sep 30, 2026
velgusgus599 Credited to velgusgus599, UlisesGascon, climba03003, and mcollina UlisesGascon UlisesGascon
climba03003 climba03003 mcollina mcollina
vvvvvvvvvvitel Credited to vvvvvvvvvvitel, mcollina, UlisesGascon, schecthellraiser606, and B1gN0Se mcollina mcollina
UlisesGascon UlisesGascon schecthellraiser606 schecthellraiser606 B1gN0Se B1gN0Se
fastify vulnerable to request validation bypass via skipped boolean false schemas High
CVE-2026-84469 was published for fastify (npm) Sep 30, 2026
schecthellraiser606 Credited to schecthellraiser606, mcollina, UlisesGascon, and climba03003 mcollina mcollina
UlisesGascon UlisesGascon climba03003 climba03003
fastify vulnerable to header validation bypass via incomplete schema case normalization High
CVE-2026-84428 was published for fastify (npm) Sep 30, 2026
schecthellraiser606 Credited to schecthellraiser606, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Astro: Netlify Image CDN allowlist bypass enables SSRF Moderate
CVE-2026-102983 was published for @astrojs/netlify (npm) Sep 30, 2026
pacocartones Credited to pacocartones
Astro: Malformed port in the Host header can crash the Node adapter High
CVE-2026-102984 was published for @astrojs/node (npm) Sep 30, 2026
Celggar Credited to Celggar
Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters High
CVE-2026-101896 was published for @angular/router (npm) Sep 30, 2026
SkyZeroZx Credited to SkyZeroZx, alan-agius4, and atscott alan-agius4 alan-agius4
atscott atscott
Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies Low
CVE-2026-97711 was published for serialize-javascript (npm) Sep 30, 2026
manus-pi Credited to manus-pi
manqingzhou Credited to manqingzhou
manqingzhou Credited to manqingzhou
Axios: Header Injection via Inherited headers After Minimal Interceptor Moderate
CVE-2026-101904 was published for axios (npm) Sep 30, 2026
0xEr3n Credited to 0xEr3n
Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders Moderate
CVE-2026-101900 was published for axios (npm) Sep 30, 2026
0xEr3n Credited to 0xEr3n
DavidCarliez Credited to DavidCarliez
Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges Moderate
CVE-2026-101899 was published for axios (npm) Sep 30, 2026
mcdubhghlas Credited to mcdubhghlas
Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF High
CVE-2026-101907 was published for axios (npm) Sep 30, 2026
mcdubhghlas Credited to mcdubhghlas
ProTip! Advisories are also available from the GraphQL API