Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,052 advisories

Loading
dilipk5 Credited to dilipk5
adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation High
CVE-2026-102282 was published for adm-zip (npm) Sep 29, 2026
Ahmed-Elmahgob Credited to Ahmed-Elmahgob
Laravel: XSS in Debug Page Information Low
CVE-2026-102279 was published for laravel/framework (Composer) Sep 29, 2026
Rikuxx0 Credited to Rikuxx0
Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS Moderate
GHSA-8vvx-rff5-p5rq was published for nodemailer (npm) Sep 29, 2026
ry2811 Credited to ry2811
PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set Moderate
CVE-2026-102274 was published for PyJWT (pip) Sep 29, 2026
pi3ch Credited to pi3ch
undici vulnerable to Denial of Service via orphaned RetryHandler response body Moderate
CVE-2026-18149 was published for undici (npm) Sep 29, 2026
mcollina Credited to mcollina, UlisesGascon, and samuel871211 UlisesGascon UlisesGascon
samuel871211 samuel871211
undici vulnerable to downstream response splitting via retry interceptor Low
CVE-2026-18540 was published for undici (npm) Sep 29, 2026
samuel871211 Credited to samuel871211, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol High
CVE-2026-19534 was published for undici (npm) Sep 29, 2026
manus-use Credited to manus-use, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
undici vulnerable to Denial of Service via unbounded decompression of compressed responses Moderate
CVE-2026-84890 was published for undici (npm) Sep 29, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches Moderate
CVE-2026-84933 was published for undici (npm) Sep 29, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
MegaManSec Credited to MegaManSec, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
undici vulnerable to caching and replay of unsafe HTTP method responses Low
CVE-2026-85008 was published for undici (npm) Sep 29, 2026
MegaManSec Credited to MegaManSec, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors High
CVE-2026-85152 was published for undici (npm) Sep 29, 2026
nikolakojic-rasit Credited to nikolakojic-rasit, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
undici vulnerable to Denial of Service via WebSocketStream unclean close Moderate
CVE-2026-85014 was published for undici (npm) Sep 29, 2026
Yanhaoxi Credited to Yanhaoxi, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()` High
GHSA-6h2x-m376-mqjq was published for joi (npm) Sep 29, 2026
qrn12580 Credited to qrn12580 and yfwmaniish yfwmaniish yfwmaniish
Electron: Local race condition in Squirrel.Mac update installation on macOS Moderate
CVE-2026-102672 was published for electron (npm) Sep 29, 2026
sgretas Credited to sgretas
Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab High
CVE-2026-102673 was published for electron (npm) Sep 29, 2026
varisys Credited to varisys
Mickey777777 Credited to Mickey777777
Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled High
CVE-2026-102675 was published for electron (npm) Sep 29, 2026
manus-use Credited to manus-use
Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions High
CVE-2026-102676 was published for electron (npm) Sep 29, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and liangjs keenanwgn keenanwgn
liangjs liangjs
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer High
CVE-2026-102677 was published for electron (npm) Sep 29, 2026
varisys Credited to varisys
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full Moderate
CVE-2026-81872 was published for go.opentelemetry.io/otel/sdk/log (Go) Sep 29, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation Moderate
CVE-2026-81869 was published for go.opentelemetry.io/otel/sdk (Go) Sep 29, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
ProTip! Advisories are also available from the GraphQL API