Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

119 advisories

Loading
Next.js: Unbounded Server Action payload in Edge runtime Moderate
CVE-2026-64646 was published for next (npm) Jul 22, 2026
n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads Moderate
CVE-2026-58661 was published for n8n (npm) Jul 22, 2026
CodeByMoriarty Credited to CodeByMoriarty
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake Moderate
GHSA-9mqv-5hh9-4cgg was published for @hono/node-server (npm) Jul 21, 2026
TarPeg007 Credited to TarPeg007
Phillip9587 Credited to Phillip9587, efekrskl, UlisesGascon, and bjohansebas efekrskl efekrskl
UlisesGascon UlisesGascon bjohansebas bjohansebas
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength` Moderate
GHSA-jqh4-m9w3-8hp9 was published for axios (npm) Jul 20, 2026
asadeddin Credited to asadeddin
node-tar: Decompression/parse DoS via unlimited input Critical
CVE-2026-59873 was published for tar (npm) Jul 20, 2026
Jvr2022 Credited to Jvr2022
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml Moderate
CVE-2026-59868 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA Moderate
CVE-2026-59870 was published for js-yaml (npm) Jul 20, 2026
usama0x01 Credited to usama0x01
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service Moderate
GHSA-pmv8-rq9r-6j72 was published for axios (npm) Jul 20, 2026
sam-caldwell Credited to sam-caldwell
dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS High
CVE-2026-50272 was published for dd-trace (npm) Jul 15, 2026
websocket-driver: Resource limit bypass via message compression Moderate
CVE-2026-54490 was published for websocket-driver (npm) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays High
CVE-2026-49866 was published for @libp2p/gossipsub (npm) Jul 10, 2026
tahaafarooq Credited to tahaafarooq
Duplicate Advisory: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads Moderate
GHSA-2vww-6p9h-5g8j was published for n8n (npm) Jul 10, 2026 withdrawn
@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url Low
GHSA-rp72-5v5q-2446 was published for @cardano402/mcp-server (npm) Jun 26, 2026
MorganOnCode Credited to MorganOnCode
undici WebSocket client vulnerable to denial of service via fragment count bypass High
CVE-2026-12151 was published for undici (npm) Jun 19, 2026
lpinca Credited to lpinca, Nadav0077, and UlisesGascon Nadav0077 Nadav0077
UlisesGascon UlisesGascon
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass High
CVE-2026-9675 was published for undici (npm) Jun 18, 2026
mauriceng98 Credited to mauriceng98, Str1ckl4nd, mcollina, and UlisesGascon Str1ckl4nd Str1ckl4nd
mcollina mcollina UlisesGascon UlisesGascon
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation Moderate
CVE-2026-54285 was published for @opentelemetry/core (npm) Jun 15, 2026
tonghuaroot Credited to tonghuaroot, pichlermarc, trentm, and arminru pichlermarc pichlermarc
trentm trentm arminru arminru
protobufjs: Memory amplification from preserved unknown fields in binary decode Moderate
CVE-2026-54270 was published for protobufjs (npm) Jun 15, 2026
sondt99 Credited to sondt99 and dcodeIO dcodeIO dcodeIO
ws: Memory exhaustion DoS from tiny fragments and data chunks High
CVE-2026-48779 was published for ws (npm) Jun 15, 2026
Nadav0077 Credited to Nadav0077
React Router vulnerable to Denial of Service via reflected user input in single-fetch High
CVE-2026-34077 was published for react-router (npm) Jun 4, 2026
Oceandust Credited to Oceandust
Allocation of Resources Without Limits or Throttling in Axios High
CVE-2026-44488 was published for axios (npm) Jun 4, 2026
asadeddin Credited to asadeddin
NocoDB: Attachment Size Limit Bypass via Upload-by-URL Low
CVE-2026-46553 was published for nocodb (npm) May 21, 2026
bugbunny-research Credited to bugbunny-research
NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion Moderate
CVE-2026-46551 was published for nocodb (npm) May 21, 2026
ik0z Credited to ik0z
Svelte devalue: DoS via sparse array deserialization High
CVE-2026-42570 was published for devalue (npm) May 14, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github, dummdidumm, and kq5y dummdidumm dummdidumm
kq5y kq5y
ProTip! Advisories are also available from the GraphQL API