GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,866
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36,231 advisories
Filter by severity
Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
High
CVE-2026-101906
was published
for
axios
(npm)
Sep 30, 2026
Axios: Prototype Pollution Gadget in axios toFormData Options
High
CVE-2026-101909
was published
for
axios
(npm)
Sep 30, 2026
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
High
CVE-2026-101898
was published
for
axios
(npm)
Sep 30, 2026
Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
High
CVE-2026-101901
was published
for
axios
(npm)
Sep 30, 2026
urllib3: Chunked Deflate streaming can enter an infinite loop
Moderate
CVE-2026-97688
was published
for
urllib3
(pip)
Sep 30, 2026
Next.js: Remote Code Execution in next/og ImageResponse
Critical
GHSA-vcvr-r3jv-pc5j
was published
for
next
(npm)
Sep 30, 2026
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
High
CVE-2026-97689
was published
for
urllib3
(pip)
Sep 30, 2026
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
High
CVE-2026-97687
was published
for
urllib3
(pip)
Sep 30, 2026
Nest: Unbounded memory growth in the NestJS TCP microservice transport
Moderate
GHSA-96h4-vgxj-gvm2
was published
for
@nestjs/microservices
(npm)
Sep 30, 2026
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets
High
GHSA-9c5c-9qcx-q35q
was published
for
@nestjs/platform-fastify
(npm)
Sep 30, 2026
Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
High
GHSA-prgh-xp8r-p3m5
was published
for
nodemailer
(npm)
Sep 30, 2026
PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
Moderate
CVE-2026-102270
was published
for
pyjwt
(pip)
Sep 30, 2026
Nest: Remote process termination via a deeply nested microservice message pattern
High
CVE-2026-102281
was published
for
@nestjs/microservices
(npm)
Sep 29, 2026
fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
Moderate
CVE-2026-86472
was published
for
fast-uri
(npm)
Sep 29, 2026
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
Moderate
CVE-2026-86818
was published
for
fast-uri
(npm)
Sep 29, 2026
@xhmikosr/decompress: Path traversal via symlink chain
Critical
CVE-2026-101894
was published
for
@xhmikosr/decompress
(npm)
Sep 29, 2026
ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
Moderate
CVE-2026-101912
was published
for
ip-address
(npm)
Sep 29, 2026
ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process
Moderate
CVE-2026-101911
was published
for
ip-address
(npm)
Sep 29, 2026
moment vulnerable to Path Traversal via crafted non-string locale name
Moderate
CVE-2026-17495
was published
for
moment
(npm)
Sep 29, 2026
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
Moderate
CVE-2026-102277
was published
for
brace-expansion
(npm)
Sep 29, 2026
brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
High
CVE-2026-102278
was published
for
brace-expansion
(npm)
Sep 29, 2026
brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
High
CVE-2026-102276
was published
for
brace-expansion
(npm)
Sep 29, 2026
Socket.IO: Engine.IO Protocol Revision Mismatch DoS
High
CVE-2026-102599
was published
for
engine.io
(npm)
Sep 29, 2026
Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing
Moderate
GHSA-g57g-f23g-4646
was published
for
nodemailer
(npm)
Sep 29, 2026
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
High
GHSA-v53p-9fqp-m79j
was published
for
nodemailer
(npm)
Sep 29, 2026
ProTip!
Advisories are also available from the
GraphQL API