GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,849
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
107 advisories
Filter by severity
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
Moderate
CVE-2026-92081
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to request body replacement via an async validation result collision
High
CVE-2026-84504
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
High
CVE-2026-76169
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to request validation bypass via skipped boolean false schemas
High
CVE-2026-84469
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to header validation bypass via incomplete schema case normalization
High
CVE-2026-84428
was published
for
fastify
(npm)
Sep 30, 2026
fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
Moderate
CVE-2026-86472
was published
for
fast-uri
(npm)
Sep 29, 2026
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
Moderate
CVE-2026-86818
was published
for
fast-uri
(npm)
Sep 29, 2026
moment vulnerable to Path Traversal via crafted non-string locale name
Moderate
CVE-2026-17495
was published
for
moment
(npm)
Sep 29, 2026
undici vulnerable to Denial of Service via orphaned RetryHandler response body
Moderate
CVE-2026-18149
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to downstream response splitting via retry interceptor
Low
CVE-2026-18540
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
High
CVE-2026-19534
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to Denial of Service via unbounded decompression of compressed responses
Moderate
CVE-2026-84890
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
Moderate
CVE-2026-84933
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
Low
CVE-2026-84947
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
High
CVE-2026-84961
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to caching and replay of unsafe HTTP method responses
Low
CVE-2026-85008
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
High
CVE-2026-85152
was published
for
undici
(npm)
Sep 29, 2026
undici vulnerable to Denial of Service via WebSocketStream unclean close
Moderate
CVE-2026-85014
was published
for
undici
(npm)
Sep 29, 2026
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
High
CVE-2026-76844
was published
for
webpack-dev-middleware
(npm)
Sep 29, 2026
undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
Moderate
CVE-2026-85024
was published
for
undici
(npm)
Sep 28, 2026
multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
Moderate
CVE-2026-88932
was published
for
multer
(npm)
Sep 28, 2026
morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
Moderate
CVE-2026-87859
was published
for
morgan
(npm)
Sep 28, 2026
fast-uri vulnerable to authority injection via an unvalidated port in serialize
High
CVE-2026-84292
was published
for
fast-uri
(npm)
Sep 28, 2026
fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
High
CVE-2026-84394
was published
for
fast-uri
(npm)
Sep 28, 2026
multer vulnerable to Denial of Service via crafted multipart field names
High
CVE-2026-77078
was published
for
multer
(npm)
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API