Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

132,034 advisories

Loading
node-tar: Negative tar entry size causes infinite loop in archive replace High
CVE-2026-59874 was published for tar (npm) Jul 20, 2026
Jvr2022 Credited to Jvr2022
Socket.IO: Engine.IO Polling Transport Connection Exhaustion High
CVE-2026-59725 was published for engine.io (npm) Jul 20, 2026
hibrian827 Credited to hibrian827
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) High
CVE-2026-13311 was published for shell-quote (npm) Jul 20, 2026
bibu123456 Credited to bibu123456, Kayiz-PT, and ljharb Kayiz-PT Kayiz-PT
ljharb ljharb
Directus: Authorization-dependent response served from unsegmented cache key High
CVE-2026-61836 was published for directus (npm) Jul 20, 2026
tr4ce-ju Credited to tr4ce-ju
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import High
CVE-2026-61835 was published for directus (npm) Jul 20, 2026
kakarotsec Credited to kakarotsec
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend High
CVE-2026-44020 was published for docling (pip) Jun 3, 2026
Docling: Unsafe Zip Extraction in EasyOCR Model Download High
CVE-2026-44017 was published for docling (pip) Jun 3, 2026
Docling: Unsafe Playwright-based HTML Rendering High
CVE-2026-44016 was published for docling (pip) Jun 3, 2026
brodmart Credited to brodmart
offset Credited to offset
ProTip! Advisories are also available from the GraphQL API