GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
7,145 advisories
Filter by severity
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
Critical
CVE-2026-71851
was published
for
crypto-js
(npm)
Aug 7, 2026
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
Moderate
CVE-2026-71850
was published
for
hono
(npm)
Aug 7, 2026
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
Low
CVE-2026-71849
was published
for
hono
(npm)
Aug 7, 2026
Hono: Algorithmic Complexity DoS in Language Middleware
Moderate
CVE-2026-71848
was published
for
hono
(npm)
Aug 7, 2026
jsii-diff: Command Injection via npm: package argument
High
CVE-2026-15895
was published
for
jsii-diff
(npm)
Aug 7, 2026
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
Moderate
CVE-2026-66062
was published
for
@sveltejs/kit
(npm)
Aug 7, 2026
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
Moderate
GHSA-7c4v-fwgw-9rf7
was published
for
nuxt
(npm)
Aug 7, 2026
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
Moderate
GHSA-55q2-fjhq-7xh7
was published
for
dompurify
(npm)
Aug 7, 2026
node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
Moderate
CVE-2026-71498
was published
for
re2
(npm)
Aug 6, 2026
node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
Moderate
CVE-2026-71430
was published
for
re2
(npm)
Aug 6, 2026
ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
High
GHSA-w9hm-4m3m-fxmm
was published
for
ngx-extended-pdf-viewer
(npm)
Aug 6, 2026
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
High
CVE-2026-16633
was published
for
pdfjs-dist
(npm)
Aug 6, 2026
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
High
GHSA-5p4m-2wfm-xmqj
was published
for
js-yaml
(npm)
Aug 6, 2026
Nx: Zip-Slip in the self-hosted remote cache
High
CVE-2026-71476
was published
for
@nx/azure-cache
(npm)
Aug 6, 2026
Mermaid radar diagrams are vulnerable to DoS
Moderate
CVE-2026-71439
was published
for
mermaid
(npm)
Aug 6, 2026
Mermaid configuration APIs allow prototype pollution
Low
CVE-2026-71438
was published
for
mermaid
(npm)
Aug 6, 2026
Mermaid allows CSS injection applying to sibling elements of the diagram
Moderate
CVE-2026-50159
was published
for
mermaid
(npm)
Aug 6, 2026
Mermaid Architecture diagrams are vulnerable to prototype pollution
Moderate
CVE-2026-71437
was published
for
mermaid
(npm)
Aug 6, 2026
Mermaid XY Charts are vulnerable to an infinite loop DoS
Moderate
CVE-2026-71436
was published
for
mermaid
(npm)
Aug 6, 2026
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
High
CVE-2026-71321
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
High
CVE-2026-71320
was published
for
nuxt
(npm)
Aug 5, 2026
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
Critical
CVE-2026-71319
was published
for
@nuxt/devtools
(npm)
Aug 5, 2026
Nuxt: Unauthorized Component Instantiation via Server Island Props
Moderate
CVE-2026-71318
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
High
CVE-2026-71316
was published
for
nuxt
(npm)
Aug 5, 2026
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
High
CVE-2026-71315
was published
for
nuxt
(npm)
Aug 5, 2026
ProTip!
Advisories are also available from the
GraphQL API