GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
413 advisories
Filter by severity
esbuild allows arbitrary file read when running the development server on Windows
Low
GHSA-g7r4-m6w7-qqqr
was published
for
esbuild
(npm)
Jun 12, 2026
Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
Low
CVE-2026-48051
was published
for
@papra/webhooks
(npm)
Jun 10, 2026
NocoDB: Missing Ownership Check in MCP Attachment Read
Low
CVE-2026-47388
was published
for
nocodb
(npm)
Jun 5, 2026
NocoDB: User Enumeration via Sign-In Timing
Low
CVE-2026-47380
was published
for
nocodb
(npm)
Jun 5, 2026
vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter
Low
GHSA-q3fm-4wcw-g57x
was published
for
vm2
(npm)
May 29, 2026
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
Low
CVE-2026-44489
was published
for
axios
(npm)
May 29, 2026
NocoDB: Stale Auth Cache After API Token Deletion
Low
CVE-2026-46554
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Attachment Size Limit Bypass via Upload-by-URL
Low
CVE-2026-46553
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
Low
CVE-2026-46549
was published
for
nocodb
(npm)
May 21, 2026
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
Low
CVE-2026-46342
was published
for
@nuxt/nitro-server
(npm)
May 19, 2026
Turbo: Unexpected local code execution during Yarn Berry detection
Low
CVE-2026-45772
was published
for
@turbo/codemod
(npm)
May 19, 2026
Summarize contains a missing authorization vulnerability
Low
CVE-2026-45244
was published
for
@steipete/summarize
(npm)
May 18, 2026
Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp
Low
GHSA-jgg6-4rpr-wfh7
was published
for
@mistralai/mistralai
(npm)
May 18, 2026
Sveltia CMS: Stored XSS in entry summary rendering via entity-decoded HTML
Low
GHSA-97r8-rf7q-wmjw
was published
for
@sveltia/cms
(npm)
May 18, 2026
@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
Low
CVE-2026-8769
was published
for
@ai-sdk/provider-utils
(npm)
May 18, 2026
@kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Low
CVE-2026-8766
was published
for
@kilocode/cli
(npm)
May 18, 2026
Strapi: Password Reset Does Not Revoke Existing Refresh Sessions
Low
CVE-2026-22706
was published
for
@strapi/admin
(npm)
May 13, 2026
Astro: Server island encrypted parameters vulnerable to cross-component replay
Low
CVE-2026-45028
was published
for
astro
(npm)
May 13, 2026
Duplicate Advisory: OpenClaw's ACP child sessions inherit subagent security envelope constraints
Low
GHSA-w626-296m-8f85
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Duplicate Advisory: OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners
Low
GHSA-p3pv-c954-9m6f
was published
for
openclaw
(npm)
May 11, 2026
•
withdrawn
Next.js's Middleware / Proxy redirects can be cache-poisoned
Low
CVE-2026-44572
was published
for
next
(npm)
May 11, 2026
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
Low
CVE-2026-44582
was published
for
next
(npm)
May 11, 2026
Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
Low
CVE-2026-44459
was published
for
hono
(npm)
May 9, 2026
nuxt-og-image SSRF — bypass of GHSA-pqhr-mp3f-hrpp / v6.2.5 fix (IPv6 + redirect)
Low
CVE-2026-44589
was published
for
nuxt-og-image
(npm)
May 7, 2026
mcp-data-vis vulnerable to denial of service via unsanitized `select` key lookup on `Object.prototype` with `precompile: true`
Low
GHSA-r27j-894h-3w3p
was published
for
icu-minify
(npm)
May 6, 2026
ProTip!
Advisories are also available from the
GraphQL API