Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
Path Traversal in superstatic High
GHSA-wm77-q74p-5763 was published for superstatic (npm) Jul 27, 2018
vercel/serve allows access to restricted files if filename is URL encoded. Moderate
CVE-2018-3718 was published for serve (npm) Aug 9, 2021
Fastify Middie Middleware Path Bypass High
CVE-2026-22031 was published for @fastify/middie (npm) Jan 20, 2026
rootxharsh Credited to rootxharsh, kamilmysliwiec, Eomm, and mcollina kamilmysliwiec kamilmysliwiec
Eomm Eomm mcollina mcollina
@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding) High
CVE-2026-22037 was published for @fastify/express (npm) Jan 20, 2026
rootxharsh Credited to rootxharsh, Eomm, and mcollina Eomm Eomm
mcollina mcollina
Hono vulnerable to arbitrary file access via serveStatic vulnerability High
CVE-2026-29045 was published for hono (npm) Mar 4, 2026
techfish-11 Credited to techfish-11 and EdamAme-x EdamAme-x EdamAme-x
@fastify/static vulnerable to route guard bypass via encoded path separators Moderate
CVE-2026-6414 was published for @fastify/static (npm) Apr 16, 2026
blakeembrey Credited to blakeembrey, mcollina, UlisesGascon, and climba03003 mcollina mcollina
UlisesGascon UlisesGascon climba03003 climba03003
ProTip! Advisories are also available from the GraphQL API