Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,706 advisories

Loading
Axios: Prototype pollution gadget in fetch adapter can alter outbound requests Moderate
CVE-2026-101908 was published for axios (npm) Sep 30, 2026
iruizsalinas Credited to iruizsalinas
hash3liZer Credited to hash3liZer and eros938 eros938 eros938
Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) High
CVE-2026-101903 was published for axios (npm) Sep 30, 2026
Frentzen Credited to Frentzen
Zandereins Credited to Zandereins
Axios: Prototype Pollution Gadget in axios toFormData Options High
CVE-2026-101909 was published for axios (npm) Sep 30, 2026
chan154 Credited to chan154
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls High
CVE-2026-101898 was published for axios (npm) Sep 30, 2026
HamdaanAliQuatil Credited to HamdaanAliQuatil
HackingRepo Credited to HackingRepo
Next.js: Remote Code Execution in next/og ImageResponse Critical
GHSA-vcvr-r3jv-pc5j was published for next (npm) Sep 30, 2026
RaghavMaheshwari124 Credited to RaghavMaheshwari124 and rafabd1 rafabd1 rafabd1
Nest: Unbounded memory growth in the NestJS TCP microservice transport Moderate
GHSA-96h4-vgxj-gvm2 was published for @nestjs/microservices (npm) Sep 30, 2026
0xKirisame Credited to 0xKirisame
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets High
GHSA-9c5c-9qcx-q35q was published for @nestjs/platform-fastify (npm) Sep 30, 2026
zerovulnlabs Credited to zerovulnlabs
mmadersbacher Credited to mmadersbacher
Nest: Remote process termination via a deeply nested microservice message pattern High
CVE-2026-102281 was published for @nestjs/microservices (npm) Sep 29, 2026
zerovulnlabs Credited to zerovulnlabs
fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets Moderate
CVE-2026-86472 was published for fast-uri (npm) Sep 29, 2026
fg0x0 Credited to fg0x0, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization Moderate
CVE-2026-86818 was published for fast-uri (npm) Sep 29, 2026
manus-use Credited to manus-use, mcollina, UlisesGascon, and manus-pi mcollina mcollina
UlisesGascon UlisesGascon manus-pi manus-pi
@xhmikosr/decompress: Path traversal via symlink chain Critical
CVE-2026-101894 was published for @xhmikosr/decompress (npm) Sep 29, 2026
umar0x Credited to umar0x and XhmikosR XhmikosR XhmikosR
moment vulnerable to Path Traversal via crafted non-string locale name Moderate
CVE-2026-17495 was published for moment (npm) Sep 29, 2026
zolbooo Credited to zolbooo, UlisesGascon, gilmoreorless, and mattjohnsonpint UlisesGascon UlisesGascon
gilmoreorless gilmoreorless mattjohnsonpint mattjohnsonpint
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service Moderate
CVE-2026-102277 was published for brace-expansion (npm) Sep 29, 2026
G-Rath Credited to G-Rath and katzj katzj katzj
brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion High
CVE-2026-102278 was published for brace-expansion (npm) Sep 29, 2026
G-Rath Credited to G-Rath and katzj katzj katzj
brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion High
CVE-2026-102276 was published for brace-expansion (npm) Sep 29, 2026
baeseungwon1010 Credited to baeseungwon1010, katzj, and G-Rath katzj katzj
G-Rath G-Rath
Socket.IO: Engine.IO Protocol Revision Mismatch DoS High
CVE-2026-102599 was published for engine.io (npm) Sep 29, 2026
sondt99 Credited to sondt99
Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing Moderate
GHSA-g57g-f23g-4646 was published for nodemailer (npm) Sep 29, 2026
ZeroXJacks Credited to ZeroXJacks
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service High
GHSA-v53p-9fqp-m79j was published for nodemailer (npm) Sep 29, 2026
adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content Moderate
GHSA-p634-w6r4-rjp2 was published for adm-zip (npm) Sep 29, 2026
zikk090 Credited to zikk090
ProTip! Advisories are also available from the GraphQL API