GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
7,257 advisories
Filter by severity
undici vulnerable to CRLF Injection via blob-like body 'type' property
Moderate
CVE-2026-15157
was published
for
undici
(npm)
Aug 3, 2026
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
Moderate
CVE-2026-14643
was published
for
undici
(npm)
Aug 3, 2026
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
Moderate
CVE-2026-16729
was published
for
undici
(npm)
Aug 3, 2026
undici vulnerable to downstream response desynchronization via retry interceptor
Moderate
CVE-2026-16728
was published
for
undici
(npm)
Aug 3, 2026
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
High
CVE-2026-13697
was published
for
undici
(npm)
Aug 3, 2026
fast-uri vulnerable to host confusion via backslash authority introducer
High
CVE-2026-18446
was published
for
fast-uri
(npm)
Aug 3, 2026
Socket.IO: Zero-attachment Memory Exhaustion
High
CVE-2026-69185
was published
for
socket.io-parser
(npm)
Aug 3, 2026
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
Moderate
CVE-2026-69153
was published
for
postcss
(npm)
Aug 3, 2026
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
High
CVE-2026-69152
was published
for
brace-expansion
(npm)
Aug 3, 2026
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
High
CVE-2026-69151
was published
for
@angular/compiler
(npm)
Aug 3, 2026
Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)
High
CVE-2026-69149
was published
for
@angular/platform-server
(npm)
Aug 3, 2026
Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
High
CVE-2026-68945
was published
for
@angular/common
(npm)
Aug 3, 2026
Duplicate Advisory: better-auth has an external request basePath modification DoS
Critical
GHSA-3q45-2fh7-66cj
was published
for
better-auth
(npm)
Aug 2, 2026
•
withdrawn
Duplicate Advisory: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
High
GHSA-68jp-44vc-2x5h
was published
for
axios
(npm)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Axios: Nested axios option objects can consume polluted prototype values
Moderate
GHSA-9wx3-p993-35vp
was published
for
axios
(npm)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Axios: Prototype pollution auth subfields can inject Basic auth
Moderate
GHSA-38gx-cfqf-f652
was published
for
axios
(npm)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Axios: Prototype pollution gadgets can alter axios request construction
Moderate
GHSA-f2r5-pqh9-r8f8
was published
for
axios
(npm)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
Moderate
GHSA-4ww2-rjh2-xpv9
was published
for
axios
(npm)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
Moderate
GHSA-fqj3-h9pc-443h
was published
for
axios
(npm)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Axios: Excessive recursion in formDataToJSON can cause denial of service
Moderate
GHSA-fq2j-3j99-rx65
was published
for
axios
(npm)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
Moderate
GHSA-6hqm-hm2v-3p2p
was published
for
axios
(npm)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
Moderate
GHSA-39j5-w47m-2gmv
was published
for
axios
(npm)
Aug 1, 2026
•
withdrawn
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
High
CVE-2026-53608
was published
for
@apostrophecms/seo
(npm)
Jul 31, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Low
CVE-2026-53607
was published
for
apostrophe
(npm)
Jul 31, 2026
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
Critical
CVE-2026-53609
was published
for
apostrophe
(npm)
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API