Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,603 advisories

Loading
Phoenix: Presence keys colliding with `Object.prototype` members break existence checks Moderate
CVE-2026-56812 was published for phoenix (Erlang) Sep 3, 2026
PJUllrich Credited to PJUllrich, maennchen, and SteffenDE maennchen maennchen
SteffenDE SteffenDE
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close Moderate
CVE-2026-63670 was published for sanitize-html (npm) Sep 3, 2026
bibu123456 Credited to bibu123456
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning Moderate
CVE-2026-73846 was published for @aborruso/ckan-mcp-server (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
rz1027 Credited to rz1027
xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization Moderate
CVE-2026-83610 was published for @xmldom/xmldom (npm) Sep 2, 2026
Paranoidgrinch Credited to Paranoidgrinch
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count Moderate
CVE-2026-16732 was published for fastify (npm) Sep 2, 2026
alimony Credited to alimony, mcollina, climba03003, and UlisesGascon mcollina mcollina
climba03003 climba03003 UlisesGascon UlisesGascon
fastify vulnerable to schema validation bypass via root primitive coercion mismatch Moderate
CVE-2026-18504 was published for fastify (npm) Sep 2, 2026
velgusgus599 Credited to velgusgus599, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal Moderate
CVE-2026-63667 was published for @apostrophecms/import-export (npm) Sep 2, 2026
kah-ja Credited to kah-ja and luuhung1217 luuhung1217 luuhung1217
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`) Moderate
CVE-2026-73845 was published for @aborruso/ckan-mcp-server (npm) Sep 2, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
qs array-limit bypass via bracket-key comma parsing Moderate
CVE-2026-82562 was published for qs (npm) Sep 2, 2026
Vectrain51 Credited to Vectrain51, Fcmam5, and ljharb Fcmam5 Fcmam5
ljharb ljharb
qs: Denial of Service via Attacker Controlled isBuffer Moderate
CVE-2026-82417 was published for qs (npm) Sep 2, 2026
waydeshi Credited to waydeshi and ljharb ljharb ljharb
Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes Moderate
GHSA-cp6q-959q-f8rh was published for @tiptap/core (npm) Sep 2, 2026
joostgrunwald Credited to joostgrunwald
humanfs: Recursive copy follows symlinked files and copies data from outside the source tree Moderate
GHSA-p498-v437-472g was published for @humanfs/node (npm) Sep 2, 2026
Jvr2022 Credited to Jvr2022
ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass Moderate
CVE-2026-84371 was published for sanitize-html (npm) Sep 1, 2026
koyokr Credited to koyokr
Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes Moderate
CVE-2026-58191 was published for @appium/base-driver (npm) Sep 1, 2026
nikkoenggaliano Credited to nikkoenggaliano
MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS Moderate
GHSA-rgwj-5xj2-c3m3 was published for mysql2 (npm) Aug 31, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input Moderate
CVE-2026-45822 was published for decode-uri-component (npm) Aug 31, 2026
bnbdr Credited to bnbdr
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking Moderate
CVE-2026-81888 was published for @hono/oauth-providers (npm) Aug 31, 2026
TarPeg007 Credited to TarPeg007
fg0x0 Credited to fg0x0
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials Moderate
CVE-2026-55854 was published for mariadb (npm) Aug 28, 2026
fg0x0 Credited to fg0x0
libreoffice-convert vulnerable to path traversal / arbitrary file write Moderate
CVE-2026-54732 was published for libreoffice-convert (npm) Aug 27, 2026
Santoshkumarpuppala Credited to Santoshkumarpuppala
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter) Moderate
CVE-2026-54687 was published for n8n-nodes-sqlite3 (npm) Aug 27, 2026
dyingman1 Credited to dyingman1
@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint Moderate
CVE-2026-55605 was published for @arikusi/deepseek-mcp-server (npm) Aug 25, 2026
SungPilHan Credited to SungPilHan and arikusi arikusi arikusi
ProTip! Advisories are also available from the GraphQL API