Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

42 advisories

Loading
qs: Denial of Service via Attacker Controlled isBuffer Moderate
CVE-2026-82417 was published for qs (npm) Sep 2, 2026
waydeshi Credited to waydeshi and ljharb ljharb ljharb
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
mcollina Credited to mcollina, UlisesGascon, and h0rk1p UlisesGascon UlisesGascon
h0rk1p h0rk1p
SvelteKit: Big remote form function payloads can cause Node process to crash Moderate
GHSA-wqjv-9729-c5q2 was published for @sveltejs/kit (npm) Jul 24, 2026
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header High
CVE-2026-59892 was published for @opentelemetry/propagator-jaeger (npm) Jul 21, 2026
EQSTLab Credited to EQSTLab and pichlermarc pichlermarc pichlermarc
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header Moderate
CVE-2026-14631 was published for webpack-dev-server (npm) Jul 20, 2026
Str1ckl4nd Credited to Str1ckl4nd, bjohansebas, Zyy0530, 7thParkk, and UlisesGascon bjohansebas bjohansebas
Zyy0530 Zyy0530 7thParkk 7thParkk UlisesGascon UlisesGascon
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records Moderate
CVE-2026-59875 was published for tar (npm) Jul 20, 2026
Kayiz-PT Credited to Kayiz-PT and bibu123456 bibu123456 bibu123456
ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes Moderate
CVE-2026-53496 was published for exifreader (npm) Jul 17, 2026
YHalo-wyh Credited to YHalo-wyh
ts-deepmerge: Prototype Method Override leads to DoS Moderate
CVE-2026-12644 was published for ts-deepmerge (npm) Jun 19, 2026
@grpc/grpc-js: A malformed request can cause a server crash High
CVE-2026-48068 was published for @grpc/grpc-js (npm) Jun 11, 2026
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash High
CVE-2026-48069 was published for @grpc/grpc-js (npm) Jun 11, 2026
joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas Moderate
CVE-2026-48038 was published for joi (npm) Jun 11, 2026
kexwin Credited to kexwin
multiparty: Denial of Service via Prototype Pollution leads to Uncaught Exception High
CVE-2026-8161 was published for multiparty (npm) May 18, 2026
Ser0n-ath Credited to Ser0n-ath, bjohansebas, kq5y, ByamB4, blakeembrey, ljharb, and UlisesGascon bjohansebas bjohansebas
kq5y kq5y ByamB4 ByamB4 blakeembrey blakeembrey ljharb ljharb UlisesGascon UlisesGascon
vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS) High
CVE-2026-44001 was published for vm2 (npm) May 7, 2026
koDove Credited to koDove
Haraka affected by DoS via `__proto__` email header High
CVE-2026-34752 was published for Haraka (npm) Apr 1, 2026
sebastianosrt Credited to sebastianosrt and msimerson msimerson msimerson
Parse Server LiveQuery subscription with invalid regular expression crashes server Moderate
CVE-2026-32770 was published for parse-server (npm) Mar 17, 2026
fancymalware Credited to fancymalware and mtrezza mtrezza mtrezza
aisle-research Credited to aisle-research, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client High
CVE-2026-1528 was published for undici (npm) Mar 13, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
fast-xml-parser has RangeError DoS Numeric Entities Bug High
CVE-2026-25128 was published for fast-xml-parser (npm) Jan 30, 2026
mistersiddd Credited to mistersiddd
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering High
CVE-2025-67647 was published for @sveltejs/adapter-node (npm) Jan 15, 2026
cold-try Credited to cold-try, teemingc, benmccann, and d-xuan teemingc teemingc
benmccann benmccann d-xuan d-xuan
HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service High
CVE-2025-54134 was published for @haxtheweb/haxcms-nodejs (npm) Jul 21, 2025
asareynolds Credited to asareynolds
Multer vulnerable to Denial of Service via unhandled exception from malformed request High
CVE-2025-7338 was published for multer (npm) Jul 17, 2025
ctcpip Credited to ctcpip, UlisesGascon, and LinusU UlisesGascon UlisesGascon
LinusU LinusU
Qwik's unhandled exception vulnerabilty can cause server crashes from malicious requests Critical
CVE-2025-53620 was published for @builder.io/qwik-city (npm) Jul 9, 2025
finalgamer Credited to finalgamer
Multer vulnerable to Denial of Service via unhandled exception High
CVE-2025-48997 was published for multer (npm) Jun 5, 2025
bjohansebas Credited to bjohansebas, ctcpip, Markiz9999, UlisesGascon, wesleytodd, and LinusU ctcpip ctcpip
Markiz9999 Markiz9999 UlisesGascon UlisesGascon wesleytodd wesleytodd LinusU LinusU
Multer vulnerable to Denial of Service from maliciously crafted requests High
CVE-2025-47944 was published for multer (npm) May 19, 2025
max-mathieu Credited to max-mathieu, wesleytodd, ctcpip, UlisesGascon, marco-ippolito, and jonchurch wesleytodd wesleytodd
ctcpip ctcpip UlisesGascon UlisesGascon marco-ippolito marco-ippolito jonchurch jonchurch
ProTip! Advisories are also available from the GraphQL API