GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,549 advisories
Filter by severity
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
Moderate
CVE-2026-55156
was published
for
@ooples/token-optimizer-mcp
(npm)
Aug 14, 2026
hashi-vault-js: Vault token and secret values exposed in thrown errors
Moderate
CVE-2026-55102
was published
for
hashi-vault-js
(npm)
Aug 13, 2026
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
Moderate
CVE-2026-55088
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
Moderate
CVE-2026-55086
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
Moderate
CVE-2026-55087
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
Moderate
GHSA-4jjw-pwvw-q6w3
was published
for
nuxt
(npm)
Aug 11, 2026
•
withdrawn
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
Moderate
CVE-2026-71850
was published
for
hono
(npm)
Aug 7, 2026
Hono: Algorithmic Complexity DoS in Language Middleware
Moderate
CVE-2026-71848
was published
for
hono
(npm)
Aug 7, 2026
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
Moderate
CVE-2026-66062
was published
for
@sveltejs/kit
(npm)
Aug 7, 2026
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
Moderate
CVE-2026-72744
was published
for
nuxt
(npm)
Aug 7, 2026
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
Moderate
GHSA-55q2-fjhq-7xh7
was published
for
dompurify
(npm)
Aug 7, 2026
node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
Moderate
CVE-2026-71498
was published
for
re2
(npm)
Aug 6, 2026
node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
Moderate
CVE-2026-71430
was published
for
re2
(npm)
Aug 6, 2026
Mermaid radar diagrams are vulnerable to DoS
Moderate
CVE-2026-71439
was published
for
mermaid
(npm)
Aug 6, 2026
Mermaid allows CSS injection applying to sibling elements of the diagram
Moderate
CVE-2026-50159
was published
for
mermaid
(npm)
Aug 6, 2026
Mermaid Architecture diagrams are vulnerable to prototype pollution
Moderate
CVE-2026-71437
was published
for
mermaid
(npm)
Aug 6, 2026
Mermaid XY Charts are vulnerable to an infinite loop DoS
Moderate
CVE-2026-71436
was published
for
mermaid
(npm)
Aug 6, 2026
Nuxt: Unauthorized Component Instantiation via Server Island Props
Moderate
CVE-2026-71318
was published
for
nuxt
(npm)
Aug 5, 2026
Electron: Sandboxed iframes can launch external protocol handlers
Moderate
CVE-2026-70612
was published
for
electron
(npm)
Aug 5, 2026
Electron: DevTools embedder handler executes arbitrary files via shell open
Moderate
CVE-2026-70611
was published
for
electron
(npm)
Aug 5, 2026
Electron: contextBridge object copy honors prototype setters
Moderate
CVE-2026-70610
was published
for
electron
(npm)
Aug 5, 2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Moderate
CVE-2026-70609
was published
for
electron
(npm)
Aug 5, 2026
Electron: window.open features string controls some window options considered privileged
Moderate
CVE-2026-70607
was published
for
electron
(npm)
Aug 5, 2026
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
Moderate
CVE-2026-70606
was published
for
electron
(npm)
Aug 5, 2026
Electron: HTTP redirect followed into local file loader
Moderate
CVE-2026-70605
was published
for
electron
(npm)
Aug 5, 2026
ProTip!
Advisories are also available from the
GraphQL API