GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36,078 advisories
Filter by severity
Nest: Remote process termination via a deeply nested microservice message pattern
High
CVE-2026-102281
was published
for
@nestjs/microservices
(npm)
Sep 29, 2026
fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
Moderate
CVE-2026-86472
was published
for
fast-uri
(npm)
Sep 29, 2026
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
Moderate
CVE-2026-86818
was published
for
fast-uri
(npm)
Sep 29, 2026
@xhmikosr/decompress: Path traversal via symlink chain
Critical
CVE-2026-101894
was published
for
@xhmikosr/decompress
(npm)
Sep 29, 2026
ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
Moderate
CVE-2026-101912
was published
for
ip-address
(npm)
Sep 29, 2026
ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process
Moderate
CVE-2026-101911
was published
for
ip-address
(npm)
Sep 29, 2026
moment vulnerable to Path Traversal via crafted non-string locale name
Moderate
CVE-2026-17495
was published
for
moment
(npm)
Sep 29, 2026
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
Moderate
CVE-2026-102277
was published
for
brace-expansion
(npm)
Sep 29, 2026
brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
High
CVE-2026-102278
was published
for
brace-expansion
(npm)
Sep 29, 2026
brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
High
CVE-2026-102276
was published
for
brace-expansion
(npm)
Sep 29, 2026
Socket.IO: Engine.IO Protocol Revision Mismatch DoS
High
CVE-2026-102599
was published
for
engine.io
(npm)
Sep 29, 2026
Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing
Moderate
GHSA-g57g-f23g-4646
was published
for
nodemailer
(npm)
Sep 29, 2026
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
High
GHSA-v53p-9fqp-m79j
was published
for
nodemailer
(npm)
Sep 29, 2026
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
High
CVE-2026-102266
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
Moderate
CVE-2026-102265
was published
for
pyJWT
(pip)
Sep 29, 2026
PyJWT: Non-canonical signature segments enable raw-token revocation bypass
Moderate
CVE-2026-102269
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
Critical
CVE-2026-102268
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT accepts public JWK containers as HMAC secrets
High
CVE-2026-102273
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT: PyJWKClient follows redirects when fetching JWKS
High
CVE-2026-102267
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
High
CVE-2026-102271
was published
for
pyjwt
(pip)
Sep 29, 2026
PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
Moderate
CVE-2026-101917
was published
for
pyjwt
(pip)
Sep 29, 2026
adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
Moderate
GHSA-p634-w6r4-rjp2
was published
for
adm-zip
(npm)
Sep 29, 2026
adm-zip: getDataAsync() bypasses the maxOutputLength size guard enforced by the synchronous getData() path
Moderate
GHSA-c6fg-446q-cg94
was published
for
adm-zip
(npm)
Sep 29, 2026
adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS)
High
GHSA-8238-w5pm-2374
was published
for
adm-zip
(npm)
Sep 29, 2026
ProTip!
Advisories are also available from the
GraphQL API