Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,465 advisories

Loading
aws-cdk-lib: OS Command Injection in NodejsFunction Bundling High
CVE-2026-11417 was published for aws-cdk-lib (npm) Jun 15, 2026
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations Moderate
CVE-2026-48988 was published for markdown-it (npm) Jun 15, 2026
tndud042713 Credited to tndud042713
OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation Moderate
CVE-2026-54285 was published for @opentelemetry/core (npm) Jun 15, 2026
tonghuaroot Credited to tonghuaroot, pichlermarc, trentm, and arminru pichlermarc pichlermarc
trentm trentm arminru arminru
Nest: Middleware Bypass on Fastify via Trailing Slash High
CVE-2026-54281 was published for @nestjs/platform-fastify (npm) Jun 15, 2026
a-tt-om Credited to a-tt-om and kamilmysliwiec kamilmysliwiec kamilmysliwiec
Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow Critical
CVE-2026-54257 was published for electron (npm) Jun 15, 2026
UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()` Moderate
CVE-2026-48125 was published for ua-parser-js (npm) Jun 15, 2026
sondt99 Credited to sondt99
protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names High
CVE-2026-54271 was published for protobufjs-cli (npm) Jun 15, 2026
JacobBrackett Credited to JacobBrackett and dcodeIO dcodeIO dcodeIO
protobufjs: Memory amplification from preserved unknown fields in binary decode Moderate
CVE-2026-54270 was published for protobufjs (npm) Jun 15, 2026
sondt99 Credited to sondt99 and dcodeIO dcodeIO dcodeIO
offset Credited to offset
React Router: Potential CSRF via PUT/PATCH/DELETE document requests Low
CVE-2026-53663 was published for @remix-run/server-runtime (npm) Jun 15, 2026
gasbugs Credited to gasbugs
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE Critical
CVE-2026-53633 was published for @vitest/browser (npm) Jun 15, 2026
IamLeandrooooo Credited to IamLeandrooooo
DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content Moderate
CVE-2026-49978 was published for dompurify (npm) Jun 15, 2026
GameZoneHacker Credited to GameZoneHacker
offset Credited to offset
offset Credited to offset
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection Moderate
GHSA-268h-hp4c-crq3 was published for nodemailer (npm) Jun 15, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization Moderate
GHSA-wqvq-jvpq-h66f was published for nodemailer (npm) Jun 15, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception Moderate
GHSA-r7g4-qg5f-qqm2 was published for nodemailer (npm) Jun 15, 2026
Venukamatchi Credited to Venukamatchi
protobufjs: Denial of service through unbounded Any expansion during JSON conversion High
CVE-2026-48712 was published for protobufjs (npm) Jun 15, 2026
EchoSkorJjj Credited to EchoSkorJjj, yueyueL, and dcodeIO yueyueL yueyueL
dcodeIO dcodeIO
protobufjs : Schema-derived names can shadow runtime-significant properties Moderate
CVE-2026-54269 was published for protobufjs (npm) Jun 15, 2026
acorn421 Credited to acorn421 and dcodeIO dcodeIO dcodeIO
form-data: CRLF injection in form-data via unescaped multipart field names and filenames High
CVE-2026-12143 was published for form-data (npm) Jun 15, 2026
yueyueL Credited to yueyueL
@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker High
CVE-2026-54264 was published for @angular/service-worker (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, alan-agius4, JeanMeche, and josephperrott alan-agius4 alan-agius4
JeanMeche JeanMeche josephperrott josephperrott
ProTip! Advisories are also available from the GraphQL API