Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,231 advisories

Loading
Zandereins Credited to Zandereins
Axios: Prototype Pollution Gadget in axios toFormData Options High
CVE-2026-101909 was published for axios (npm) Sep 30, 2026
chan154 Credited to chan154
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls High
CVE-2026-101898 was published for axios (npm) Sep 30, 2026
HamdaanAliQuatil Credited to HamdaanAliQuatil
HackingRepo Credited to HackingRepo
urllib3: Chunked Deflate streaming can enter an infinite loop Moderate
CVE-2026-97688 was published for urllib3 (pip) Sep 30, 2026
gnuletik Credited to gnuletik, illia-v, and pquentin illia-v illia-v
pquentin pquentin
Next.js: Remote Code Execution in next/og ImageResponse Critical
GHSA-vcvr-r3jv-pc5j was published for next (npm) Sep 30, 2026
RaghavMaheshwari124 Credited to RaghavMaheshwari124 and rafabd1 rafabd1 rafabd1
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory High
CVE-2026-97689 was published for urllib3 (pip) Sep 30, 2026
pquentin Credited to pquentin and illia-v illia-v illia-v
urllib3: HTTPS proxy TLS configuration may be ignored or overridden High
CVE-2026-97687 was published for urllib3 (pip) Sep 30, 2026
dhoepp Credited to dhoepp, shazow, fuyu0425, sethmlarson, illia-v, yonatanmgr, and pquentin shazow shazow
fuyu0425 fuyu0425 sethmlarson sethmlarson illia-v illia-v yonatanmgr yonatanmgr pquentin pquentin
Nest: Unbounded memory growth in the NestJS TCP microservice transport Moderate
GHSA-96h4-vgxj-gvm2 was published for @nestjs/microservices (npm) Sep 30, 2026
0xKirisame Credited to 0xKirisame
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets High
GHSA-9c5c-9qcx-q35q was published for @nestjs/platform-fastify (npm) Sep 30, 2026
zerovulnlabs Credited to zerovulnlabs
mmadersbacher Credited to mmadersbacher
PyJWT: ReDoS vulnerability when calling the `is_pem_format` function. Moderate
CVE-2026-102270 was published for pyjwt (pip) Sep 30, 2026
Yanni8 Credited to Yanni8
Nest: Remote process termination via a deeply nested microservice message pattern High
CVE-2026-102281 was published for @nestjs/microservices (npm) Sep 29, 2026
zerovulnlabs Credited to zerovulnlabs
fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets Moderate
CVE-2026-86472 was published for fast-uri (npm) Sep 29, 2026
fg0x0 Credited to fg0x0, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization Moderate
CVE-2026-86818 was published for fast-uri (npm) Sep 29, 2026
manus-use Credited to manus-use, mcollina, UlisesGascon, and manus-pi mcollina mcollina
UlisesGascon UlisesGascon manus-pi manus-pi
@xhmikosr/decompress: Path traversal via symlink chain Critical
CVE-2026-101894 was published for @xhmikosr/decompress (npm) Sep 29, 2026
umar0x Credited to umar0x and XhmikosR XhmikosR XhmikosR
moment vulnerable to Path Traversal via crafted non-string locale name Moderate
CVE-2026-17495 was published for moment (npm) Sep 29, 2026
zolbooo Credited to zolbooo, UlisesGascon, gilmoreorless, and mattjohnsonpint UlisesGascon UlisesGascon
gilmoreorless gilmoreorless mattjohnsonpint mattjohnsonpint
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service Moderate
CVE-2026-102277 was published for brace-expansion (npm) Sep 29, 2026
G-Rath Credited to G-Rath and katzj katzj katzj
brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion High
CVE-2026-102278 was published for brace-expansion (npm) Sep 29, 2026
G-Rath Credited to G-Rath and katzj katzj katzj
brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion High
CVE-2026-102276 was published for brace-expansion (npm) Sep 29, 2026
baeseungwon1010 Credited to baeseungwon1010, katzj, and G-Rath katzj katzj
G-Rath G-Rath
Socket.IO: Engine.IO Protocol Revision Mismatch DoS High
CVE-2026-102599 was published for engine.io (npm) Sep 29, 2026
sondt99 Credited to sondt99
Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing Moderate
GHSA-g57g-f23g-4646 was published for nodemailer (npm) Sep 29, 2026
ZeroXJacks Credited to ZeroXJacks
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service High
GHSA-v53p-9fqp-m79j was published for nodemailer (npm) Sep 29, 2026
ProTip! Advisories are also available from the GraphQL API