Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,145 advisories

Loading
juli Credited to juli
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure Moderate
CVE-2026-71850 was published for hono (npm) Aug 7, 2026
raster0x2a Credited to raster0x2a
Hono: Proxy Helper does not remove response headers listed in the `Connection` header Low
CVE-2026-71849 was published for hono (npm) Aug 7, 2026
morgan-coded Credited to morgan-coded
Hono: Algorithmic Complexity DoS in Language Middleware Moderate
CVE-2026-71848 was published for hono (npm) Aug 7, 2026
jsii-diff: Command Injection via npm: package argument High
CVE-2026-15895 was published for jsii-diff (npm) Aug 7, 2026
Dremig Credited to Dremig
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header Moderate
CVE-2026-66062 was published for @sveltejs/kit (npm) Aug 7, 2026
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint Moderate
GHSA-7c4v-fwgw-9rf7 was published for nuxt (npm) Aug 7, 2026
Saku0512 Credited to Saku0512
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS Moderate
GHSA-55q2-fjhq-7xh7 was published for dompurify (npm) Aug 7, 2026
koyokr Credited to koyokr
ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633 High
GHSA-w9hm-4m3m-fxmm was published for ngx-extended-pdf-viewer (npm) Aug 6, 2026
calixteman Credited to calixteman
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF High
CVE-2026-16633 was published for pdfjs-dist (npm) Aug 6, 2026
wlayzz Credited to wlayzz
0xsharz Credited to 0xsharz
Nx: Zip-Slip in the self-hosted remote cache High
CVE-2026-71476 was published for @nx/azure-cache (npm) Aug 6, 2026
Mermaid radar diagrams are vulnerable to DoS Moderate
CVE-2026-71439 was published for mermaid (npm) Aug 6, 2026
aloisklink Credited to aloisklink
Mermaid configuration APIs allow prototype pollution Low
CVE-2026-71438 was published for mermaid (npm) Aug 6, 2026
Str1ckl4nd Credited to Str1ckl4nd, Zyy0530, 7thParkk, mauriceng98, and aloisklink Zyy0530 Zyy0530
7thParkk 7thParkk mauriceng98 mauriceng98 aloisklink aloisklink
Mermaid allows CSS injection applying to sibling elements of the diagram Moderate
CVE-2026-50159 was published for mermaid (npm) Aug 6, 2026
h3ri0s Credited to h3ri0s and aloisklink aloisklink aloisklink
Mermaid Architecture diagrams are vulnerable to prototype pollution Moderate
CVE-2026-71437 was published for mermaid (npm) Aug 6, 2026
ThomasRinsma Credited to ThomasRinsma, jkim-notion, and aloisklink jkim-notion jkim-notion
aloisklink aloisklink
Mermaid XY Charts are vulnerable to an infinite loop DoS Moderate
CVE-2026-71436 was published for mermaid (npm) Aug 6, 2026
aloisklink Credited to aloisklink
dinhvaren Credited to dinhvaren
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host Critical
CVE-2026-71319 was published for @nuxt/devtools (npm) Aug 5, 2026
TazmiDev Credited to TazmiDev and anzuukino anzuukino anzuukino
Nuxt: Unauthorized Component Instantiation via Server Island Props Moderate
CVE-2026-71318 was published for nuxt (npm) Aug 5, 2026
quantumshiro Credited to quantumshiro
Pig-Tail Credited to Pig-Tail, sec-reex, and DavidCarliez sec-reex sec-reex
DavidCarliez DavidCarliez
ProTip! Advisories are also available from the GraphQL API