Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion High
CVE-2026-34601 was published for @xmldom/xmldom (npm) Apr 1, 2026
thesmartshadow Credited to thesmartshadow and karfau karfau karfau
thesmartshadow Credited to thesmartshadow
thesmartshadow Credited to thesmartshadow
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning High
CVE-2026-67320 was published for axios (npm) Jul 20, 2026
thesmartshadow Credited to thesmartshadow
hono/jsx does not isolate context per request, leading to cross-request data disclosure Moderate
CVE-2026-59896 was published for hono (npm) Jul 21, 2026
thesmartshadow Credited to thesmartshadow
vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass Critical
CVE-2026-92956 was published for vm2 (npm) Oct 5, 2026
thesmartshadow Credited to thesmartshadow and zolbooo zolbooo zolbooo
ProTip! Advisories are also available from the GraphQL API