GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
171 advisories
Filter by severity
Apollo Federation vulnerable to prototype pollution via incomplete key sanitization
Critical
CVE-2026-32621
was published
for
@apollo/federation-internals
(npm)
Mar 13, 2026
`@orpc/client` has Prototype Pollution via `StandardRPCJsonSerializer` Deserialization
Critical
CVE-2026-28794
was published
for
@orpc/client
(npm)
Mar 2, 2026
set-in Affected by Prototype Pollution
Critical
CVE-2026-26021
was published
for
set-in
(npm)
Feb 11, 2026
CASL Ability is Vulnerable to Prototype Pollution
Critical
CVE-2026-1774
was published
for
@casl/ability
(npm)
Feb 10, 2026
@nyariv/sandboxjs has host prototype pollution from sandbox via array intermediary (sandbox escape)
Critical
CVE-2026-25881
was published
for
@nyariv/sandboxjs
(npm)
Feb 10, 2026
Prototype Pollution via FormData Processing in Qwik City
Critical
CVE-2026-25150
was published
for
@builder.io/qwik-city
(npm)
Feb 3, 2026
locutus is vulnerable to Prototype Pollution
Critical
CVE-2026-25521
was published
for
locutus
(npm)
Feb 2, 2026
SandboxJS Vulnerable to Prototype Pollution -> Sandbox Escape -> RCE
Critical
CVE-2026-25142
was published
for
@nyariv/sandboxjs
(npm)
Feb 2, 2026
deepHas vulnerable to Prototype Pollution via constructor.prototype
Critical
CVE-2026-25047
was published
for
deephas
(npm)
Jan 29, 2026
apidoc-core has a prototype pollution vulnerability
Critical
CVE-2025-13158
was published
for
apidoc-core
(npm)
Dec 26, 2025
Elysia vulnerable to prototype pollution with multiple standalone schema validation
Critical
CVE-2025-66456
was published
for
elysia
(npm)
Dec 9, 2025
happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript
Critical
CVE-2025-62410
was published
for
happy-dom
(npm)
Oct 15, 2025
A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within...
Critical
Unreviewed
CVE-2025-57347
was published
Sep 24, 2025
Spree has Remote Command Execution vulnerability in search functionality
Critical
CVE-2011-10019
was published
for
spree
(RubyGems)
Aug 13, 2025
billboard.js allows prototype pollution via the function generate
Critical
CVE-2025-49223
was published
for
billboard.js
(npm)
Jun 4, 2025
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP...
Critical
Unreviewed
CVE-2025-25014
was published
May 6, 2025
A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-24292
was published
Mar 28, 2025
Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and...
Critical
Unreviewed
CVE-2025-25015
was published
Mar 5, 2025
utils-extend Prototype Pollution
Critical
CVE-2024-57077
was published
for
utils-extend
(npm)
Feb 6, 2025
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')...
Critical
Unreviewed
CVE-2024-56059
was published
Dec 18, 2024
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')...
Critical
Unreviewed
CVE-2024-52441
was published
Nov 20, 2024
DOMPurify vulnerable to tampering by prototype polution
Critical
CVE-2024-48910
was published
for
dompurify
(npm)
Oct 31, 2024
Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function.
Critical
Unreviewed
CVE-2024-45435
was published
Aug 29, 2024
A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML...
Critical
Unreviewed
CVE-2024-37287
was published
Aug 13, 2024
ProTip!
Advisories are also available from the
GraphQL API