Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,615 advisories

Loading
probe-image-size: Quadratic-time Denial of Service in the SVG Parser High
CVE-2026-104861 was published for probe-image-size (npm) Oct 2, 2026
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary High
CVE-2026-19484 was published for @fastify/busboy (npm) Oct 2, 2026
LorenzoRD2003 Credited to LorenzoRD2003, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header High
CVE-2026-19481 was published for @fastify/busboy (npm) Oct 2, 2026
kq5y Credited to kq5y, mcollina, UlisesGascon, and AdmirBajric mcollina mcollina
UlisesGascon UlisesGascon AdmirBajric AdmirBajric
@a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions Critical
CVE-2026-10032 was published for @a2ui/web_core (npm) Oct 2, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
Duplicate Advisory: @a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions Moderate
GHSA-w72q-x6w3-7rj3 was published for @a2ui/web_core (npm) Aug 4, 2026 • withdrawn
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values Moderate
GHSA-fj2x-mqqp-3v2w was published for trigger.dev (npm) Oct 2, 2026
Rikuxx0 Credited to Rikuxx0
Duplicate Advisory: DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. Moderate
GHSA-jxrp-r7gx-q4j8 was published for dompurify (npm) Jul 24, 2026 • withdrawn
Trigger.dev: Cross-environment deployment cancel Moderate
GHSA-4672-hwv6-gq62 was published for trigger.dev (npm) Oct 2, 2026
CyberKareem Credited to CyberKareem
sajdakabir Credited to sajdakabir
Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise High
GHSA-pqxw-g93w-hj9x was published for trigger.dev (npm) Oct 2, 2026
sfwani Credited to sfwani
Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId Moderate
GHSA-59h8-w5q6-mfmp was published for trigger.dev (npm) Oct 2, 2026
sfwani Credited to sfwani, dodge1218, geo-chen, and MatiasTilleriasLey dodge1218 dodge1218
geo-chen geo-chen MatiasTilleriasLey MatiasTilleriasLey
ismayilamiraslanov555 Credited to ismayilamiraslanov555
Trigger.dev: V1 coordinator default-secret unauth Socket.IO Critical
GHSA-gg6r-gp4c-89hp was published for trigger.dev (npm) Oct 2, 2026
lissy93 Credited to lissy93
http-cache-semantics max-stale handling can disclose cross-user cached responses High
CVE-2026-93748 was published for http-cache-semantics (npm) Sep 18, 2026
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns High
CVE-2026-93687 was published for braces (npm) Sep 18, 2026
0xkakash1 Credited to 0xkakash1
Duplicate Advisory: Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true }) Moderate
GHSA-3wcj-gjvf-fvch was published for hono (npm) Jul 11, 2026 • withdrawn
Trigger.dev: Blind SSRF via alert-channel webhook Moderate
GHSA-q567-cr4x-96w4 was published for trigger.dev (npm) Oct 2, 2026
CyberKareem Credited to CyberKareem and dizconnectz dizconnectz dizconnectz
Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR) High
GHSA-pp95-gc86-jq6q was published for trigger.dev (npm) Oct 2, 2026
sajdakabir Credited to sajdakabir and zerotrail-ai zerotrail-ai zerotrail-ai
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL High
GHSA-xxv7-2vv3-h682 was published for trigger.dev (npm) Oct 2, 2026
geo-chen Credited to geo-chen
Trigger.dev: Run replay injects a task run into an attacker-chosen environment (cross-tenant write) High
GHSA-qxpp-qjg8-x4jv was published for trigger.dev (npm) Oct 2, 2026
geo-chen Credited to geo-chen
Hono vulnerable to Vary Header Injection leading to potential CORS Bypass Moderate
CVE-2025-71381 was published for hono (npm) Oct 24, 2025
gigatechcode Credited to gigatechcode
Duplicate Advisory: Hono vulnerable to Vary Header Injection leading to potential CORS Bypass Moderate
GHSA-cw3j-28qq-x3xh was published for hono (npm) Jul 1, 2026 • withdrawn
node-forge RSA PKCS#1 v1.5 signature verification accepts extra nested DigestAlgorithm elements High
CVE-2026-85393 was published for node-forge (npm) Sep 3, 2026
ProTip! Advisories are also available from the GraphQL API