GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
86 advisories
Filter by severity
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
High
CVE-2026-33894
was published
for
node-forge
(npm)
Mar 26, 2026
LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern
High
CVE-2026-33287
was published
for
liquidjs
(npm)
Mar 25, 2026
LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash
High
CVE-2026-33285
was published
for
liquidjs
(npm)
Mar 25, 2026
@fastify/middie has Improper Path Normalization when Using Path-Scoped Middleware
High
CVE-2026-2880
was published
for
@fastify/middie
(npm)
Feb 28, 2026
Koa has Host Header Injection via ctx.hostname
High
CVE-2026-27959
was published
for
koa
(npm)
Feb 26, 2026
TerriaJS-Server has a domain validation bypass vulnerability in its proxy allowlist
High
CVE-2026-27818
was published
for
terriajs-server
(npm)
Feb 26, 2026
CediPay Affected by Improper Input Validation in Payment Processing
High
CVE-2026-26063
was published
for
cedipay-core
(npm)
Feb 12, 2026
Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictions
High
CVE-2026-25723
was published
for
@anthropic-ai/claude-code
(npm)
Feb 6, 2026
Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection
High
CVE-2026-25722
was published
for
@anthropic-ai/claude-code
(npm)
Feb 6, 2026
OpenClaw vulnerable to Unauthenticated Local RCE via WebSocket config.apply
High
CVE-2026-25593
was published
for
openclaw
(npm)
Feb 4, 2026
jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder
High
CVE-2026-24133
was published
for
jspdf
(npm)
Feb 2, 2026
fast-xml-parser has RangeError DoS Numeric Entities Bug
High
CVE-2026-25128
was published
for
fast-xml-parser
(npm)
Jan 30, 2026
Duplicate Advisory: Wrangler affected by OS Command Injection in `wrangler pages deploy`
High
GHSA-8h3q-9fpp-c883
was published
for
wrangler
(npm)
Jan 21, 2026
•
withdrawn
Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parse
High
CVE-2026-22774
was published
for
devalue
(npm)
Jan 15, 2026
Claude Code Command Validation Bypass Allows Arbitrary Code Execution
High
CVE-2025-66032
was published
for
@anthropic-ai/claude-code
(npm)
Dec 3, 2025
Codex has sandbox bypass due to bug in path configuration logic
High
CVE-2025-59532
was published
for
@openai/codex
(npm)
Sep 19, 2025
HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service
High
CVE-2025-54134
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
@discordjs/opus vulnerable to Denial of Service
High
CVE-2024-21521
was published
for
@discordjs/opus
(npm)
Jul 10, 2024
ejson shell parser in MongoDB Compass maybe bypassed
High
CVE-2024-6376
was published
for
@mongodb-js/connection-form
(npm)
Jul 1, 2024
Uptime Kuma vulnerable to authenticated remote code execution via malicious plugin installation
High
CVE-2023-36821
was published
for
uptime-kuma
(npm)
May 1, 2024
Sending a GET or HEAD request with a body crashes SvelteKit
High
CVE-2024-23641
was published
for
@sveltejs/adapter-node
(npm)
Jan 24, 2024
json-web-token library is vulnerable to a JWT algorithm confusion attack
High
CVE-2023-48238
was published
for
json-web-token
(npm)
Nov 17, 2023
import-in-the-middle has unsanitized user controlled input in module generation
High
CVE-2023-38704
was published
for
import-in-the-middle
(npm)
Aug 8, 2023
keep-module-latest vulnerable to Command Injection due to missing input sanitization
High
CVE-2023-26128
was published
for
keep-module-latest
(npm)
May 27, 2023
ProTip!
Advisories are also available from the
GraphQL API