GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,883
Maven
5,000+
npm
4,522
NuGet
785
pip
4,262
Pub
12
RubyGems
975
Rust
1,105
Swift
49
Unreviewed advisories
All unreviewed
5,000+
4,523 advisories
Filter by severity
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
High
CVE-2026-23950
was published
for
tar
(npm)
Jan 21, 2026
Orval has a code injection via unsanitized x-enum-descriptions in enum generation
Critical
CVE-2026-23947
was published
for
@orval/core
(npm)
Jan 21, 2026
Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation
Moderate
CVE-2026-21852
was published
for
@anthropic-ai/claude-code
(npm)
Jan 21, 2026
Duplicate Advisory: Wrangler affected by OS Command Injection in `wrangler pages deploy`
High
GHSA-8h3q-9fpp-c883
was published
for
wrangler
(npm)
Jan 21, 2026
•
withdrawn
binary-parser library has a code injection vulnerability
Moderate
CVE-2026-1245
was published
for
binary-parser
(npm)
Jan 20, 2026
Turbo Frame responses can restore stale session cookies
Low
CVE-2025-66803
was published
for
@hotwired/turbo
(npm)
Jan 20, 2026
Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE)
Moderate
CVE-2026-23733
was published
for
@lobehub/chat
(npm)
Jan 20, 2026
Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion
Low
CVE-2026-23522
was published
for
@lobehub/chat
(npm)
Jan 20, 2026
@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)
High
CVE-2026-22037
was published
for
@fastify/express
(npm)
Jan 20, 2026
Fastify Middie Middleware Path Bypass
High
CVE-2026-22031
was published
for
@fastify/middie
(npm)
Jan 20, 2026
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
High
CVE-2026-23745
was published
for
tar
(npm)
Jan 16, 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
Critical
CVE-2026-23744
was published
for
@mcpjam/inspector
(npm)
Jan 16, 2026
GraphQL Modules has a Race Condition issue
High
CVE-2026-23735
was published
for
graphql-modules
(npm)
Jan 16, 2026
Veramo is Vulnerable to SQL Injection in Veramo Data Store ORM
Moderate
GHSA-38cw-85xc-xr9x
was published
for
@veramo/data-store
(npm)
Jan 16, 2026
svelte is vulnerable to XSS with textarea bind:value
High
GHSA-gw32-9rmw-qwww
was published
for
svelte
(npm)
Jan 16, 2026
Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2025-15104
was published
for
nu.validator:validator
(Maven)
Jan 16, 2026
devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse
High
CVE-2026-22775
was published
for
devalue
(npm)
Jan 15, 2026
Pepr Has Overly Permissive RBAC ClusterRole in Admin Mode
Low
CVE-2026-23634
was published
for
pepr
(npm)
Jan 15, 2026
svelte vulnerable to Cross-site Scripting
Moderate
CVE-2025-15265
was published
for
svelte
(npm)
Jan 15, 2026
h3 v1 has Request Smuggling (TE.TE) issue
High
CVE-2026-23527
was published
for
h3
(npm)
Jan 15, 2026
@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
High
CVE-2026-22803
was published
for
@sveltejs/kit
(npm)
Jan 15, 2026
Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parse
High
CVE-2026-22774
was published
for
devalue
(npm)
Jan 15, 2026
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
High
CVE-2025-67647
was published
for
@sveltejs/adapter-node
(npm)
Jan 15, 2026
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch
Low
CVE-2026-24001
was published
for
diff
(npm)
Jan 14, 2026
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
Moderate
CVE-2026-22036
was published
for
undici
(npm)
Jan 14, 2026
ProTip!
Advisories are also available from the
GraphQL API