Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5,740 advisories

Loading
gzm0 Credited to gzm0 and viceice viceice viceice
LangSmith SDK: Streaming token events bypass output redaction Moderate
GHSA-rr7j-v2q5-chgv was published for langsmith (npm) Apr 16, 2026
Ryu7zz Credited to Ryu7zz
FredKSchott Credited to FredKSchott, mcollina, UlisesGascon, and climba03003 mcollina mcollina
UlisesGascon UlisesGascon climba03003 climba03003
@fastify/express's middleware path doubling causes authentication bypass in child plugin scopes Critical
CVE-2026-33807 was published for @fastify/express (npm) Apr 16, 2026
FredKSchott Credited to FredKSchott, mcollina, UlisesGascon, and climba03003 mcollina mcollina
UlisesGascon UlisesGascon climba03003 climba03003
Fastify's connection header abuse enables stripping of proxy-added headers Critical
CVE-2026-33805 was published for @fastify/http-proxy (npm) Apr 16, 2026
FredKSchott Credited to FredKSchott, mcollina, UlisesGascon, and climba03003 mcollina mcollina
UlisesGascon UlisesGascon climba03003 climba03003
Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME High
GHSA-33r3-4whc-44c2 was published for vite-plus (npm) Apr 16, 2026
Jvr2022 Credited to Jvr2022
hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR Moderate
GHSA-458j-xx4x-4375 was published for hono (npm) Apr 16, 2026
tndud042713 Credited to tndud042713
DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation Moderate
GHSA-39q2-94rc-95cp was published for dompurify (npm) Apr 16, 2026
NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins Moderate
CVE-2026-40346 was published for @nocobase/plugin-workflow-request (npm) Apr 15, 2026
Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header High
CVE-2026-33806 was published for fastify (npm) Apr 15, 2026
mcollina Credited to mcollina, climba03003, jsumners, and UlisesGascon climba03003 climba03003
jsumners jsumners UlisesGascon UlisesGascon
Sync-in Server has Username Enumeration via Timing Attack Moderate
GHSA-43fj-qp3h-hrh5 was published for @sync-in/server (npm) Apr 15, 2026
ppfeister Credited to ppfeister and 7185 7185 7185
Novu has a XSS sanitization bypass High
GHSA-26wg-9xf2-q495 was published for novu/api (npm) Apr 14, 2026
JorianWoltjer Credited to JorianWoltjer
Novu has SSRF via conditions filter webhook bypasses validateUrlSsrf() protection High
GHSA-4x48-cgf9-q33f was published for @novu/api (npm) Apr 14, 2026
kodareef5 Credited to kodareef5
@vendure/core has a SQL Injection vulnerability Critical
CVE-2026-40887 was published for @vendure/core (npm) Apr 14, 2026
jacobfrantz1 Credited to jacobfrantz1
MCP Server Kubernetes has an Argument Injection in port_forward tool via space-splitting High
CVE-2026-39884 was published for mcp-server-kubernetes (npm) Apr 14, 2026
TharVid Credited to TharVid
@adonisjs/http-server has an Open Redirect vulnerability Moderate
CVE-2026-40255 was published for @adonisjs/core (npm) Apr 14, 2026
thetutlage Credited to thetutlage
MCPHub has an authentication bypass Moderate
CVE-2025-13822 was published for @samanhappy/mcphub (npm) Apr 14, 2026
follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets Moderate
GHSA-r4q5-vmmm-2653 was published for follow-redirects (npm) Apr 14, 2026
Den-Sec Credited to Den-Sec
Nest Affected by DoS via Recursive handleData in JsonSocket (TCP Transport) High
CVE-2026-40879 was published for @nestjs/microservices (npm) Apr 14, 2026
hwpark6804-gif Credited to hwpark6804-gif and kamilmysliwiec kamilmysliwiec kamilmysliwiec
SSH/SCP option injection allowing local RCE in @aiondadotcom/mcp-ssh High
GHSA-p4h8-56qp-hpgv was published for @aiondadotcom/mcp-ssh (npm) Apr 14, 2026
DbGate has cross site scripting via the SVG Icon String Handler component Low
CVE-2026-6216 was published for dbgate-web (npm) Apr 13, 2026
simple-git Affected by Command Execution via Option-Parsing Bypass High
CVE-2026-28291 was published for simple-git (npm) Apr 13, 2026
JuHwiSang Credited to JuHwiSang and adnanrahim110 adnanrahim110 adnanrahim110
mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes High
GHSA-jvff-x2qm-6286 was published for mathjs (npm) Apr 10, 2026
CykuTW Credited to CykuTW and marado marado marado
unhead: Streaming SSR `streamKey` injected into inline script without identifier validation Low
GHSA-x7mm-9vvv-64w8 was published for unhead (npm) Apr 10, 2026
Jvr2022 Credited to Jvr2022
paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass Critical
GHSA-68qg-g8mg-6pr7 was published for @paperclipai/server (npm) Apr 10, 2026
sagilayani Credited to sagilayani
ProTip! Advisories are also available from the GraphQL API