GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
7,706 advisories
Filter by severity
Axios: Prototype pollution gadget in fetch adapter can alter outbound requests
Moderate
CVE-2026-101908
was published
for
axios
(npm)
Sep 30, 2026
Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method
Moderate
CVE-2026-101902
was published
for
axios
(npm)
Sep 30, 2026
Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
High
CVE-2026-101903
was published
for
axios
(npm)
Sep 30, 2026
Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
High
CVE-2026-101906
was published
for
axios
(npm)
Sep 30, 2026
Axios: Prototype Pollution Gadget in axios toFormData Options
High
CVE-2026-101909
was published
for
axios
(npm)
Sep 30, 2026
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
High
CVE-2026-101898
was published
for
axios
(npm)
Sep 30, 2026
Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
High
CVE-2026-101901
was published
for
axios
(npm)
Sep 30, 2026
Next.js: Remote Code Execution in next/og ImageResponse
Critical
GHSA-vcvr-r3jv-pc5j
was published
for
next
(npm)
Sep 30, 2026
Nest: Unbounded memory growth in the NestJS TCP microservice transport
Moderate
GHSA-96h4-vgxj-gvm2
was published
for
@nestjs/microservices
(npm)
Sep 30, 2026
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets
High
GHSA-9c5c-9qcx-q35q
was published
for
@nestjs/platform-fastify
(npm)
Sep 30, 2026
Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
High
CVE-2026-90776
was published
for
nodemailer
(npm)
Sep 30, 2026
Nest: Remote process termination via a deeply nested microservice message pattern
High
CVE-2026-102281
was published
for
@nestjs/microservices
(npm)
Sep 29, 2026
fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
Moderate
CVE-2026-86472
was published
for
fast-uri
(npm)
Sep 29, 2026
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
Moderate
CVE-2026-86818
was published
for
fast-uri
(npm)
Sep 29, 2026
@xhmikosr/decompress: Path traversal via symlink chain
Critical
CVE-2026-101894
was published
for
@xhmikosr/decompress
(npm)
Sep 29, 2026
ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
Moderate
CVE-2026-101912
was published
for
ip-address
(npm)
Sep 29, 2026
ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process
Moderate
CVE-2026-101911
was published
for
ip-address
(npm)
Sep 29, 2026
moment vulnerable to Path Traversal via crafted non-string locale name
Moderate
CVE-2026-17495
was published
for
moment
(npm)
Sep 29, 2026
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
Moderate
CVE-2026-102277
was published
for
brace-expansion
(npm)
Sep 29, 2026
brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
High
CVE-2026-102278
was published
for
brace-expansion
(npm)
Sep 29, 2026
brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
High
CVE-2026-102276
was published
for
brace-expansion
(npm)
Sep 29, 2026
Socket.IO: Engine.IO Protocol Revision Mismatch DoS
High
CVE-2026-102599
was published
for
engine.io
(npm)
Sep 29, 2026
Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing
Moderate
GHSA-g57g-f23g-4646
was published
for
nodemailer
(npm)
Sep 29, 2026
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
High
GHSA-v53p-9fqp-m79j
was published
for
nodemailer
(npm)
Sep 29, 2026
adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
Moderate
GHSA-p634-w6r4-rjp2
was published
for
adm-zip
(npm)
Sep 29, 2026
ProTip!
Advisories are also available from the
GraphQL API