GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
2,443 advisories
Filter by severity
FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations
High
CVE-2026-47717
was published
for
fuxa-server
(npm)
May 27, 2026
LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
High
CVE-2026-45617
was published
for
liquidjs
(npm)
May 27, 2026
LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)
High
CVE-2026-45357
was published
for
liquidjs
(npm)
May 27, 2026
@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters
High
CVE-2026-44974
was published
for
@hapi/content
(npm)
May 27, 2026
tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape
High
CVE-2026-44705
was published
for
tmp
(npm)
May 27, 2026
FUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass
High
CVE-2026-43947
was published
for
fuxa-server
(npm)
May 26, 2026
FUXA has an unauthenticated arbitrary tag value disclosure via /api/getTagValue
High
CVE-2026-43946
was published
for
fuxa-server
(npm)
May 26, 2026
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
High
CVE-2026-43945
was published
for
@frangoteam/fuxa
(npm)
May 26, 2026
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
High
CVE-2026-42462
was published
for
@fedify/fedify
(npm)
May 26, 2026
yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation
High
CVE-2026-42089
was published
for
yeoman-environment
(npm)
May 26, 2026
Typebot has Stored XSS via Rating Block Custom Icon that Bypasses isUnsafe Sandbox in Builder Preview
High
CVE-2026-28445
was published
for
@typebot.io/js
(npm)
May 26, 2026
Parse Server: Pre-authentication denial of service via client version header regex backtracking
High
CVE-2026-47138
was published
for
parse-server
(npm)
May 23, 2026
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
High
CVE-2026-46701
was published
for
network-ai
(npm)
May 21, 2026
@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty
High
CVE-2026-46681
was published
for
@nevware21/ts-utils
(npm)
May 21, 2026
js-libp2p: Memory DoS via subscription flood of unique topics
High
CVE-2026-46679
was published
for
@libp2p/gossipsub
(npm)
May 21, 2026
JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
High
CVE-2026-46625
was published
for
js-cookie
(npm)
May 21, 2026
@hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails
High
GHSA-59f3-7227-wmh4
was published
for
@hulumi/policies
(npm)
May 21, 2026
@hulumi/policies: CIS 1.16 admin policy bypass for inline and attached IAM policies
High
GHSA-4xrh-5m3m-328w
was published
for
@hulumi/policies
(npm)
May 21, 2026
@hulumi/policies: HULUMI-H1 SecureBucket parent spoof bypass
High
GHSA-g43v-9x7q-83pq
was published
for
@hulumi/policies
(npm)
May 21, 2026
@hulumi/drift: Orphan reconciler accepted externally supplied execute plans
High
GHSA-2ffm-hxrq-qqmm
was published
for
@hulumi/drift
(npm)
May 21, 2026
MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement
High
CVE-2026-46519
was published
for
mcp-server-kubernetes
(npm)
May 21, 2026
md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
High
CVE-2026-46492
was published
for
md-fileserver
(npm)
May 21, 2026
samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
High
CVE-2026-46490
was published
for
samlify
(npm)
May 21, 2026
@angular/platform-server: SSRF via Hostname Hijacking
High
CVE-2026-46417
was published
for
@angular/platform-server
(npm)
May 19, 2026
CamoFox MCP: Unauthenticated HTTP MCP browser-control surface
High
GHSA-7hgr-7h44-33w2
was published
for
camofox-mcp
(npm)
May 19, 2026
ProTip!
Advisories are also available from the
GraphQL API