GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
7,258 advisories
Filter by severity
Mermaid configuration APIs allow prototype pollution
Low
CVE-2026-71438
was published
for
mermaid
(npm)
Aug 6, 2026
Mermaid allows CSS injection applying to sibling elements of the diagram
Moderate
CVE-2026-50159
was published
for
mermaid
(npm)
Aug 6, 2026
Mermaid Architecture diagrams are vulnerable to prototype pollution
Moderate
CVE-2026-71437
was published
for
mermaid
(npm)
Aug 6, 2026
Mermaid XY Charts are vulnerable to an infinite loop DoS
Moderate
CVE-2026-71436
was published
for
mermaid
(npm)
Aug 6, 2026
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
High
CVE-2026-71321
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
High
CVE-2026-71320
was published
for
nuxt
(npm)
Aug 5, 2026
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
Critical
CVE-2026-71319
was published
for
@nuxt/devtools
(npm)
Aug 5, 2026
Nuxt: Unauthorized Component Instantiation via Server Island Props
Moderate
CVE-2026-71318
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
High
CVE-2026-71316
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
High
CVE-2026-71315
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
High
CVE-2026-71314
was published
for
nuxt
(npm)
Aug 5, 2026
Electron: Sandboxed iframes can launch external protocol handlers
Moderate
CVE-2026-70612
was published
for
electron
(npm)
Aug 5, 2026
Electron: DevTools embedder handler executes arbitrary files via shell open
Moderate
CVE-2026-70611
was published
for
electron
(npm)
Aug 5, 2026
Electron: contextBridge object copy honors prototype setters
Moderate
CVE-2026-70610
was published
for
electron
(npm)
Aug 5, 2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Moderate
CVE-2026-70609
was published
for
electron
(npm)
Aug 5, 2026
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
High
CVE-2026-70608
was published
for
electron
(npm)
Aug 5, 2026
Electron: window.open features string controls some window options considered privileged
Moderate
CVE-2026-70607
was published
for
electron
(npm)
Aug 5, 2026
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
Moderate
CVE-2026-70606
was published
for
electron
(npm)
Aug 5, 2026
Electron: HTTP redirect followed into local file loader
Moderate
CVE-2026-70605
was published
for
electron
(npm)
Aug 5, 2026
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
High
CVE-2026-70604
was published
for
electron
(npm)
Aug 5, 2026
Electron: Extension tab APIs operate across session boundaries
Moderate
CVE-2026-70602
was published
for
electron
(npm)
Aug 5, 2026
Electron: shell.openPath path validation bypass via embedded null byte
Moderate
CVE-2026-70603
was published
for
electron
(npm)
Aug 5, 2026
Electron: Context isolation bypass via Function.prototype.bind hijack
High
CVE-2026-70601
was published
for
electron
(npm)
Aug 5, 2026
Electron: Cross-origin iframe can position native autofill popup
Low
CVE-2026-70600
was published
for
electron
(npm)
Aug 5, 2026
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
Moderate
CVE-2026-70599
was published
for
electron
(npm)
Aug 5, 2026
ProTip!
Advisories are also available from the
GraphQL API