Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

13,355 advisories

Loading
fastify vulnerable to request body replacement via an async validation result collision High
CVE-2026-84504 was published for fastify (npm) Sep 30, 2026
velgusgus599 Credited to velgusgus599, UlisesGascon, climba03003, and mcollina UlisesGascon UlisesGascon
climba03003 climba03003 mcollina mcollina
fastify vulnerable to request validation bypass via skipped boolean false schemas High
CVE-2026-84469 was published for fastify (npm) Sep 30, 2026
schecthellraiser606 Credited to schecthellraiser606, mcollina, UlisesGascon, and climba03003 mcollina mcollina
UlisesGascon UlisesGascon climba03003 climba03003
sonicnew Credited to sonicnew
Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing Moderate
GHSA-g57g-f23g-4646 was published for nodemailer (npm) Sep 29, 2026
ZeroXJacks Credited to ZeroXJacks
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer High
CVE-2026-102677 was published for electron (npm) Sep 29, 2026
varisys Credited to varisys
ProTip! Advisories are also available from the GraphQL API