GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
975
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
14 advisories
Filter by severity
protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names
High
CVE-2026-54271
was published
for
protobufjs-cli
(npm)
Jun 15, 2026
protobufjs: Memory amplification from preserved unknown fields in binary decode
Moderate
CVE-2026-54270
was published
for
protobufjs
(npm)
Jun 15, 2026
protobufjs: Denial of service through unbounded Any expansion during JSON conversion
High
CVE-2026-48712
was published
for
protobufjs
(npm)
Jun 15, 2026
protobufjs : Schema-derived names can shadow runtime-significant properties
Moderate
CVE-2026-54269
was published
for
protobufjs
(npm)
Jun 15, 2026
protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
Moderate
CVE-2026-45740
was published
for
protobufjs
(npm)
May 19, 2026
protobuf.js: Code injection in pbjs static output from crafted schema names
High
CVE-2026-44295
was published
for
protobufjs-cli
(npm)
May 12, 2026
protobuf.js: Denial of service from crafted field names in generated code
Moderate
CVE-2026-44294
was published
for
protobufjs
(npm)
May 12, 2026
protobuf.js: Code injection through bytes field defaults in generated toObject code
High
CVE-2026-44293
was published
for
protobufjs
(npm)
May 12, 2026
protobuf.js: Prototype injection in generated message constructors
Moderate
CVE-2026-44292
was published
for
protobufjs
(npm)
May 12, 2026
protobuf.js: Code generation gadget after prototype pollution
High
CVE-2026-44291
was published
for
protobufjs
(npm)
May 12, 2026
protobuf.js: Process-wide denial of service through unsafe option paths
High
CVE-2026-44290
was published
for
protobufjs
(npm)
May 12, 2026
protobuf.js: Denial of service through unbounded protobuf recursion
High
CVE-2026-44289
was published
for
protobufjs
(npm)
May 12, 2026
protobufjs has overlong UTF-8 decoding
Moderate
CVE-2026-44288
was published
for
@protobufjs/utf8
(npm)
May 12, 2026
protobuf.js is Vulnerable to OS Command Injection in the CLI
High
CVE-2026-42290
was published
for
protobufjs-cli
(npm)
May 12, 2026
ProTip!
Advisories are also available from the
GraphQL API