GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
26 advisories
Filter by severity
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
High
CVE-2026-73088
was published
for
browserslist
(npm)
Sep 1, 2026
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
High
CVE-2026-13697
was published
for
undici
(npm)
Aug 3, 2026
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
High
CVE-2026-59892
was published
for
@opentelemetry/propagator-jaeger
(npm)
Jul 21, 2026
@grpc/grpc-js: A malformed request can cause a server crash
High
CVE-2026-48068
was published
for
@grpc/grpc-js
(npm)
Jun 11, 2026
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
High
CVE-2026-48069
was published
for
@grpc/grpc-js
(npm)
Jun 11, 2026
multiparty: Denial of Service via Prototype Pollution leads to Uncaught Exception
High
CVE-2026-8161
was published
for
multiparty
(npm)
May 18, 2026
vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
High
CVE-2026-44001
was published
for
vm2
(npm)
May 7, 2026
Haraka affected by DoS via `__proto__` email header
High
CVE-2026-34752
was published
for
Haraka
(npm)
Apr 1, 2026
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
High
CVE-2026-2229
was published
for
undici
(npm)
Mar 13, 2026
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
High
CVE-2026-1528
was published
for
undici
(npm)
Mar 13, 2026
fast-xml-parser has RangeError DoS Numeric Entities Bug
High
CVE-2026-25128
was published
for
fast-xml-parser
(npm)
Jan 30, 2026
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
High
CVE-2025-67647
was published
for
@sveltejs/adapter-node
(npm)
Jan 15, 2026
HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service
High
CVE-2025-54134
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
Multer vulnerable to Denial of Service via unhandled exception from malformed request
High
CVE-2025-7338
was published
for
multer
(npm)
Jul 17, 2025
Multer vulnerable to Denial of Service via unhandled exception
High
CVE-2025-48997
was published
for
multer
(npm)
Jun 5, 2025
Multer vulnerable to Denial of Service from maliciously crafted requests
High
CVE-2025-47944
was published
for
multer
(npm)
May 19, 2025
tRPC 11 WebSocket DoS Vulnerability
High
CVE-2025-43855
was published
for
@trpc/server
(npm)
Apr 24, 2025
DoS vulnerability for apps with sockets enabled
High
CVE-2023-38504
was published
for
sails
(npm)
Jul 27, 2023
fastify/websocket vulnerable to uncaught exception via crash on malformed packet
High
CVE-2022-39386
was published
for
@fastify/websocket
(npm)
Nov 7, 2022
Denial-of-Service when binding invalid parameters in sqlite3
High
CVE-2022-21227
was published
for
sqlite3
(npm)
Apr 28, 2022
Denial of Service vulnerability in @podium/layout and @podium/proxy
High
CVE-2022-24822
was published
for
@podium/layout
(npm)
Apr 7, 2022
DOS and Open Redirect with user input
High
CVE-2021-22964
was published
for
fastify-static
(npm)
Oct 12, 2021
ProTip!
Advisories are also available from the
GraphQL API