GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
7,706 advisories
Filter by severity
devalue: Residual sparse-array CPU amplification in uneval
Moderate
GHSA-hx4r-w6wj-j8fg
was published
for
devalue
(npm)
Oct 1, 2026
devalue: Repeated primitive strings cause quadratic expansion in uneval
High
GHSA-mcm9-63f2-9j32
was published
for
devalue
(npm)
Oct 1, 2026
devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
Low
GHSA-wf3x-273g-mvxv
was published
for
devalue
(npm)
Oct 1, 2026
devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
High
GHSA-x5rw-q4pp-hg5g
was published
for
devalue
(npm)
Oct 1, 2026
devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
Moderate
GHSA-4q55-j62x-fr9h
was published
for
devalue
(npm)
Oct 1, 2026
piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env
Critical
CVE-2026-102992
was published
for
piscina
(npm)
Oct 1, 2026
basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)
High
CVE-2026-102990
was published
for
basic-ftp
(npm)
Oct 1, 2026
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
Moderate
CVE-2026-92081
was published
for
fastify
(npm)
Sep 30, 2026
hono/jsx renders plain strings unescaped in boundary components, leading to XSS
Moderate
CVE-2026-93981
was published
for
hono
(npm)
Sep 30, 2026
fastify vulnerable to request body replacement via an async validation result collision
High
CVE-2026-84504
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
High
CVE-2026-76169
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to request validation bypass via skipped boolean false schemas
High
CVE-2026-84469
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to header validation bypass via incomplete schema case normalization
High
CVE-2026-84428
was published
for
fastify
(npm)
Sep 30, 2026
Astro: Netlify Image CDN allowlist bypass enables SSRF
Moderate
CVE-2026-102983
was published
for
@astrojs/netlify
(npm)
Sep 30, 2026
Astro: Malformed port in the Host header can crash the Node adapter
High
CVE-2026-102984
was published
for
@astrojs/node
(npm)
Sep 30, 2026
Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
High
CVE-2026-101896
was published
for
@angular/router
(npm)
Sep 30, 2026
Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies
Low
CVE-2026-97711
was published
for
serialize-javascript
(npm)
Sep 30, 2026
DOMPurify: IN_PLACE: node-removing afterSanitize hook leaves detached subtree event handlers armed, causing DOM XSS
Low
GHSA-p98j-92pf-mc4p
was published
for
dompurify
(npm)
Sep 30, 2026
@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
High
CVE-2026-101916
was published
for
@grpc/grpc-js
(npm)
Sep 30, 2026
@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages
Low
CVE-2026-101915
was published
for
@grpc/grpc-js
(npm)
Sep 30, 2026
Axios: Header Injection via Inherited headers After Minimal Interceptor
Moderate
CVE-2026-101904
was published
for
axios
(npm)
Sep 30, 2026
Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders
Moderate
CVE-2026-101900
was published
for
axios
(npm)
Sep 30, 2026
Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection
High
CVE-2026-101905
was published
for
axios
(npm)
Sep 30, 2026
Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges
Moderate
CVE-2026-101899
was published
for
axios
(npm)
Sep 30, 2026
Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
High
CVE-2026-101907
was published
for
axios
(npm)
Sep 30, 2026
ProTip!
Advisories are also available from the
GraphQL API