Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

20 advisories

Loading
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys High
CVE-2026-54511 was published for @logtape/syslog (npm) Aug 26, 2026
undici vulnerable to CRLF Injection via blob-like body 'type' property Moderate
CVE-2026-15157 was published for undici (npm) Aug 3, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding Moderate
CVE-2026-9679 was published for undici (npm) Jun 19, 2026
tndud042713 Credited to tndud042713, mcollina, KhafraDev, and UlisesGascon mcollina mcollina
KhafraDev KhafraDev UlisesGascon UlisesGascon
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody` High
CVE-2026-55603 was published for http-proxy-middleware (npm) Jun 18, 2026
RamiAltai Credited to RamiAltai
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection Moderate
GHSA-268h-hp4c-crq3 was published for nodemailer (npm) Jun 15, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
form-data: CRLF injection in form-data via unescaped multipart field names and filenames High
CVE-2026-12143 was published for form-data (npm) Jun 15, 2026
yueyueL Credited to yueyueL
eventsource-encoder vulnerable to SSE event injection via unsanitized `event` and `id` fields Moderate
CVE-2026-44214 was published for eventsource-encoder (npm) May 8, 2026
sse-channel: SSE Injection via unsanitized event fields Moderate
CVE-2026-44217 was published for sse-channel (npm) May 5, 2026
SnailSploit Credited to SnailSploit
Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream Moderate
CVE-2026-42037 was published for axios (npm) May 5, 2026
kobi-s Credited to kobi-s
offset Credited to offset
basic-ftp has FTP Command Injection via CRLF High
CVE-2026-39983 was published for basic-ftp (npm) Apr 8, 2026
zebbern Credited to zebbern
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO) Moderate
GHSA-vvjj-xcjg-gr5g was published for nodemailer (npm) Apr 8, 2026
tndud042713 Credited to tndud042713
Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter Low
GHSA-c7w3-x93f-qmm8 was published for nodemailer (npm) Mar 26, 2026
esquilichi Credited to esquilichi
h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields High
CVE-2026-33128 was published for h3 (npm) Mar 18, 2026
0xkakash1 Credited to 0xkakash1
Undici has CRLF Injection in undici via `upgrade` option Moderate
CVE-2026-1527 was published for undici (npm) Mar 13, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
CRLF Injection in Nodejs ‘undici’ via host Moderate
CVE-2023-23936 was published for undici (npm) Feb 16, 2023
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type Moderate
CVE-2022-35948 was published for undici (npm) Aug 18, 2022
happyhacking-k Credited to happyhacking-k
undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect Low
CVE-2022-31151 was published for undici (npm) Jul 21, 2022
Haxatron Credited to Haxatron
undici before v5.8.0 vulnerable to CRLF injection in request headers Moderate
CVE-2022-31150 was published for undici (npm) Jul 21, 2022
Haxatron Credited to Haxatron
Improper handling of multiline messages in node-irc High
GHSA-52rh-5rpj-c3w6 was published for matrix-org-irc (npm) May 5, 2022
kurt-r2c Credited to kurt-r2c and sunnypatell sunnypatell sunnypatell
ProTip! Advisories are also available from the GraphQL API