GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,494
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
72 advisories
Filter by severity
undici vulnerable to CRLF Injection via blob-like body 'type' property
Moderate
CVE-2026-15157
was published
for
undici
(npm)
Aug 3, 2026
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
Moderate
CVE-2026-14643
was published
for
undici
(npm)
Aug 3, 2026
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
Moderate
CVE-2026-16729
was published
for
undici
(npm)
Aug 3, 2026
undici vulnerable to downstream response desynchronization via retry interceptor
Moderate
CVE-2026-16728
was published
for
undici
(npm)
Aug 3, 2026
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
High
CVE-2026-13697
was published
for
undici
(npm)
Aug 3, 2026
fast-uri vulnerable to host confusion via backslash authority introducer
High
CVE-2026-18446
was published
for
fast-uri
(npm)
Aug 3, 2026
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
Moderate
CVE-2026-7120
was published
for
@fastify/static
(npm)
Jul 24, 2026
@fastify/static vulnerable to route guard bypass via path traversal
High
CVE-2026-15074
was published
for
@fastify/static
(npm)
Jul 24, 2026
fast-uri vulnerable to host confusion via literal backslash authority delimiter
High
CVE-2026-16221
was published
for
fast-uri
(npm)
Jul 21, 2026
fast-uri vulnerable to host confusion via failed IDN canonicalization
High
CVE-2026-13676
was published
for
fast-uri
(npm)
Jul 21, 2026
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
Low
CVE-2026-12590
was published
for
body-parser
(npm)
Jul 20, 2026
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
Moderate
CVE-2026-14631
was published
for
webpack-dev-server
(npm)
Jul 20, 2026
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
Moderate
CVE-2026-14620
was published
for
webpack-dev-server
(npm)
Jul 20, 2026
morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
Moderate
CVE-2026-5078
was published
for
morgan
(npm)
Jul 10, 2026
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
Low
CVE-2026-11525
was published
for
undici
(npm)
Jun 19, 2026
undici WebSocket client vulnerable to denial of service via fragment count bypass
High
CVE-2026-12151
was published
for
undici
(npm)
Jun 19, 2026
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
Moderate
CVE-2026-9679
was published
for
undici
(npm)
Jun 19, 2026
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
High
CVE-2026-6734
was published
for
undici
(npm)
Jun 19, 2026
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
Low
CVE-2026-6733
was published
for
undici
(npm)
Jun 19, 2026
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
High
CVE-2026-9697
was published
for
undici
(npm)
Jun 18, 2026
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
Moderate
CVE-2026-9678
was published
for
undici
(npm)
Jun 18, 2026
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
High
CVE-2026-9675
was published
for
undici
(npm)
Jun 18, 2026
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
Moderate
CVE-2026-9595
was published
for
webpack-dev-server
(npm)
Jun 17, 2026
Multer vulnerable to Denial of Service via deeply nested field names
High
CVE-2026-5079
was published
for
multer
(npm)
Jun 17, 2026
Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
Moderate
CVE-2026-5038
was published
for
multer
(npm)
Jun 17, 2026
ProTip!
Advisories are also available from the
GraphQL API