Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,078 advisories

Loading
Nest: Remote process termination via a deeply nested microservice message pattern High
CVE-2026-102281 was published for @nestjs/microservices (npm) Sep 29, 2026
zerovulnlabs Credited to zerovulnlabs
fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets Moderate
CVE-2026-86472 was published for fast-uri (npm) Sep 29, 2026
fg0x0 Credited to fg0x0, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization Moderate
CVE-2026-86818 was published for fast-uri (npm) Sep 29, 2026
manus-use Credited to manus-use, mcollina, UlisesGascon, and manus-pi mcollina mcollina
UlisesGascon UlisesGascon manus-pi manus-pi
@xhmikosr/decompress: Path traversal via symlink chain Critical
CVE-2026-101894 was published for @xhmikosr/decompress (npm) Sep 29, 2026
umar0x Credited to umar0x and XhmikosR XhmikosR XhmikosR
moment vulnerable to Path Traversal via crafted non-string locale name Moderate
CVE-2026-17495 was published for moment (npm) Sep 29, 2026
zolbooo Credited to zolbooo, UlisesGascon, gilmoreorless, and mattjohnsonpint UlisesGascon UlisesGascon
gilmoreorless gilmoreorless mattjohnsonpint mattjohnsonpint
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service Moderate
CVE-2026-102277 was published for brace-expansion (npm) Sep 29, 2026
G-Rath Credited to G-Rath and katzj katzj katzj
brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion High
CVE-2026-102278 was published for brace-expansion (npm) Sep 29, 2026
G-Rath Credited to G-Rath and katzj katzj katzj
brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion High
CVE-2026-102276 was published for brace-expansion (npm) Sep 29, 2026
baeseungwon1010 Credited to baeseungwon1010, katzj, and G-Rath katzj katzj
G-Rath G-Rath
Socket.IO: Engine.IO Protocol Revision Mismatch DoS High
CVE-2026-102599 was published for engine.io (npm) Sep 29, 2026
sondt99 Credited to sondt99
Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing Moderate
GHSA-g57g-f23g-4646 was published for nodemailer (npm) Sep 29, 2026
ZeroXJacks Credited to ZeroXJacks
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service High
GHSA-v53p-9fqp-m79j was published for nodemailer (npm) Sep 29, 2026
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation High
CVE-2026-102266 was published for PyJWT (pip) Sep 29, 2026
hsnyus-09 Credited to hsnyus-09
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header Moderate
CVE-2026-102265 was published for pyJWT (pip) Sep 29, 2026
Nivid42 Credited to Nivid42
PyJWT: Non-canonical signature segments enable raw-token revocation bypass Moderate
CVE-2026-102269 was published for PyJWT (pip) Sep 29, 2026
ze3tar Credited to ze3tar
e1024x Credited to e1024x
PyJWT accepts public JWK containers as HMAC secrets High
CVE-2026-102273 was published for PyJWT (pip) Sep 29, 2026
the-vibe-dev Credited to the-vibe-dev
PyJWT: PyJWKClient follows redirects when fetching JWKS High
CVE-2026-102267 was published for PyJWT (pip) Sep 29, 2026
NovaHunter06 Credited to NovaHunter06
0xSmiley Credited to 0xSmiley
PyJWT BOM Bypass High
CVE-2026-102272 was published for PyJWT (pip) Sep 29, 2026
wnsgurd90-keke Credited to wnsgurd90-keke
babakizo420 Credited to babakizo420
adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content Moderate
GHSA-p634-w6r4-rjp2 was published for adm-zip (npm) Sep 29, 2026
zikk090 Credited to zikk090
adm-zip: getDataAsync() bypasses the maxOutputLength size guard enforced by the synchronous getData() path Moderate
GHSA-c6fg-446q-cg94 was published for adm-zip (npm) Sep 29, 2026
zikk090 Credited to zikk090
adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS) High
GHSA-8238-w5pm-2374 was published for adm-zip (npm) Sep 29, 2026
chan154 Credited to chan154
ProTip! Advisories are also available from the GraphQL API