GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,800 advisories
Filter by severity
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
High
CVE-2026-55157
was published
for
@ooples/token-optimizer-mcp
(npm)
Aug 14, 2026
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
High
CVE-2026-59880
was published
for
immutable
(npm)
Jul 21, 2026
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
High
CVE-2026-35219
was published
for
@budibase/server
(npm)
Aug 14, 2026
fast-uri vulnerable to host confusion via failed IDN canonicalization
High
CVE-2026-13676
was published
for
fast-uri
(npm)
Jul 21, 2026
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
High
CVE-2026-73654
was published
for
@trigger.dev/core
(npm)
Aug 13, 2026
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
High
CVE-2026-73418
was published
for
@auth/core
(npm)
Jul 23, 2026
Genql: inject arbitrary JavaScript or TypeScript via a GraphQL schema
High
CVE-2026-63397
was published
for
@genql/cli
(npm)
Jul 16, 2026
SVGO removeScripts plugin leaves some executable scripts intact
High
CVE-2026-73650
was published
for
svgo
(npm)
Jul 21, 2026
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
High
CVE-2026-73646
was published
for
postcss
(npm)
Jul 24, 2026
js-yaml: Exponential parsing time in flow collections leads to denial of service
High
CVE-2026-73643
was published
for
js-yaml
(npm)
Jul 24, 2026
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
High
CVE-2026-73569
was published
for
fast-xml-parser
(npm)
Jul 21, 2026
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
High
CVE-2026-73561
was published
for
@anephenix/hub
(npm)
Jul 24, 2026
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
High
CVE-2026-55697
was published
for
pnpm
(npm)
Jun 26, 2026
nanoid: custom generators can loop indefinitely when size is zero
High
CVE-2026-67213
was published
for
nanoid
(npm)
Jul 29, 2026
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
High
CVE-2026-6322
was published
for
fast-uri
(npm)
May 8, 2026
Astro: Host header SSRF in prerendered error page fetch
High
CVE-2026-54299
was published
for
astro
(npm)
Jun 16, 2026
Astro: Reflected XSS via unescaped slot name
High
CVE-2026-50146
was published
for
astro
(npm)
Jun 16, 2026
Shescape: Quadratic-time denial of service in the flag-protection
High
CVE-2026-73413
was published
for
shescape
(npm)
Jul 24, 2026
Budibase: SSRF via DNS rebinding in the REST datasource integration
High
CVE-2026-73410
was published
for
@budibase/server
(npm)
Jul 24, 2026
extract-zip unvalidated symlink path traversal
High
CVE-2026-56876
was published
for
extract-zip
(npm)
Jun 26, 2026
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
High
CVE-2026-73409
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
High
CVE-2026-73406
was published
for
@budibase/server
(npm)
Jul 24, 2026
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
High
CVE-2026-54353
was published
for
@budibase/backend-core
(npm)
Jun 22, 2026
Budibase: Privilege escalation via public role assignment API missing app-level authorization
High
CVE-2026-73305
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
High
CVE-2026-73303
was published
for
@budibase/server
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API