Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,020 advisories

Loading
ry2811 Credited to ry2811
mcollina Credited to mcollina, krsecu, and UlisesGascon krsecu krsecu
UlisesGascon UlisesGascon
multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads Moderate
CVE-2026-88932 was published for multer (npm) Sep 28, 2026
euriconicacio Credited to euriconicacio, UlisesGascon, and bjohansebas UlisesGascon UlisesGascon
bjohansebas bjohansebas
morgan vulnerable to Log Injection via unescaped double quote in quoted log fields Moderate
CVE-2026-87859 was published for morgan (npm) Sep 28, 2026
iRevivalx Credited to iRevivalx, UlisesGascon, and jonchurch UlisesGascon UlisesGascon
jonchurch jonchurch
Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE High
CVE-2026-101895 was published for @angular/platform-server (npm) Sep 28, 2026
SkyZeroZx Credited to SkyZeroZx and alan-agius4 alan-agius4 alan-agius4
fast-uri vulnerable to authority injection via an unvalidated port in serialize High
CVE-2026-84292 was published for fast-uri (npm) Sep 28, 2026
YashvantHange Credited to YashvantHange, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority High
CVE-2026-84394 was published for fast-uri (npm) Sep 28, 2026
YashvantHange Credited to YashvantHange, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist) Moderate
CVE-2026-83557 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Sep 28, 2026
prvazsahnazarov Credited to prvazsahnazarov
euriconicacio Credited to euriconicacio
cruzryan Credited to cruzryan
Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements High
CVE-2026-88058 was published for @angular/platform-server (npm) Sep 28, 2026
VenkatKwest Credited to VenkatKwest and alan-agius4 alan-agius4 alan-agius4
jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS High
CVE-2026-68497 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Sep 28, 2026
waydeshi Credited to waydeshi
jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution Moderate
CVE-2026-19032 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Sep 28, 2026
waydeshi Credited to waydeshi
jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization Moderate
CVE-2026-77310 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Sep 28, 2026
thientd Credited to thientd and pussycat0x pussycat0x pussycat0x
@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches Moderate
CVE-2026-101914 was published for @grpc/grpc-js-xds (npm) Sep 28, 2026
manqingzhou Credited to manqingzhou
scim-patch: Mutation of Inherited Built-in Method Objects Moderate
CVE-2026-61834 was published for scim-patch (npm) Sep 28, 2026
mountainousmolehill Credited to mountainousmolehill and Kairos-T Kairos-T Kairos-T
code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78) High
GHSA-456v-xq2p-r4cj was published for code-ollama (npm) Sep 28, 2026
remarkablemark Credited to remarkablemark
SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests High
CVE-2026-57443 was published for scbe-aethermoore (pip) Sep 25, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
mpp vulnerable to Gas Draining with low gas limit High
GHSA-vj8p-hp9x-gh47 was published for mpp (Erlang) Sep 25, 2026
kai-kka Credited to kai-kka
mpp vulnerable to Gas Draining with access list Moderate
GHSA-qpxh-ff8m-c62v was published for mpp (Erlang) Sep 25, 2026
kai-kka Credited to kai-kka
mpp vulnerable to Gas Draining with no limit High
GHSA-vv77-66rf-pm86 was published for mpp (Erlang) Sep 25, 2026
kai-kka Credited to kai-kka
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers High
CVE-2026-100368 was published for AlastairLundy.CliInvoke.Specializations (NuGet) Sep 25, 2026
CliInvoke: Argument Injection in Extensibility Runner Factory High
CVE-2026-100369 was published for AlastairLundy.CliInvoke (NuGet) Sep 25, 2026
bulmax9797-sketch Credited to bulmax9797-sketch
uziii2208 Credited to uziii2208 and hoanggxyuuki hoanggxyuuki hoanggxyuuki
ProTip! Advisories are also available from the GraphQL API