GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
7,615 advisories
Filter by severity
probe-image-size: Quadratic-time Denial of Service in the SVG Parser
High
CVE-2026-104861
was published
for
probe-image-size
(npm)
Oct 2, 2026
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
High
CVE-2026-19484
was published
for
@fastify/busboy
(npm)
Oct 2, 2026
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
High
CVE-2026-19481
was published
for
@fastify/busboy
(npm)
Oct 2, 2026
@a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions
Critical
CVE-2026-10032
was published
for
@a2ui/web_core
(npm)
Oct 2, 2026
Duplicate Advisory: @a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions
Moderate
GHSA-w72q-x6w3-7rj3
was published
for
@a2ui/web_core
(npm)
Aug 4, 2026
•
withdrawn
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values
Moderate
GHSA-fj2x-mqqp-3v2w
was published
for
trigger.dev
(npm)
Oct 2, 2026
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
Low
CVE-2026-66010
was published
for
dompurify
(npm)
Jul 21, 2026
Duplicate Advisory: DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
Moderate
GHSA-jxrp-r7gx-q4j8
was published
for
dompurify
(npm)
Jul 24, 2026
•
withdrawn
Trigger.dev: Cross-environment deployment cancel
Moderate
GHSA-4672-hwv6-gq62
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name
High
GHSA-9q4r-4842-93vw
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise
High
GHSA-pqxw-g93w-hj9x
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
Moderate
GHSA-59h8-w5q6-mfmp
was published
for
trigger.dev
(npm)
Oct 2, 2026
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
High
CVE-2026-96780
was published
for
figlet
(npm)
Oct 2, 2026
Trigger.dev: V1 coordinator default-secret unauth Socket.IO
Critical
GHSA-gg6r-gp4c-89hp
was published
for
trigger.dev
(npm)
Oct 2, 2026
http-cache-semantics max-stale handling can disclose cross-user cached responses
High
CVE-2026-93748
was published
for
http-cache-semantics
(npm)
Sep 18, 2026
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
High
CVE-2026-93687
was published
for
braces
(npm)
Sep 18, 2026
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
Moderate
CVE-2026-56763
was published
for
hono
(npm)
Mar 11, 2026
Duplicate Advisory: Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
Moderate
GHSA-3wcj-gjvf-fvch
was published
for
hono
(npm)
Jul 11, 2026
•
withdrawn
Trigger.dev: Blind SSRF via alert-channel webhook
Moderate
GHSA-q567-cr4x-96w4
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR)
High
GHSA-pp95-gc86-jq6q
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL
High
GHSA-xxv7-2vv3-h682
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Run replay injects a task run into an attacker-chosen environment (cross-tenant write)
High
GHSA-qxpp-qjg8-x4jv
was published
for
trigger.dev
(npm)
Oct 2, 2026
Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
Moderate
CVE-2025-71381
was published
for
hono
(npm)
Oct 24, 2025
Duplicate Advisory: Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
Moderate
GHSA-cw3j-28qq-x3xh
was published
for
hono
(npm)
Jul 1, 2026
•
withdrawn
node-forge RSA PKCS#1 v1.5 signature verification accepts extra nested DigestAlgorithm elements
High
CVE-2026-85393
was published
for
node-forge
(npm)
Sep 3, 2026
ProTip!
Advisories are also available from the
GraphQL API