Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

371 advisories

Loading
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding High
CVE-2026-54609 was published for com.quietterminal:qti-neon (Maven) Jul 28, 2026
Shescape: Quadratic-time denial of service in the flag-protection High
GHSA-gm3r-q2wp-hw87 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash High
CVE-2026-14257 was published for brace-expansion (npm) Jul 24, 2026
bnbdr Credited to bnbdr
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion High
GHSA-g5vv-q72c-7j78 was published for @anephenix/hub (npm) Jul 24, 2026
react-server-dom: Denial of Service in Server Functions High
CVE-2026-44907 was published for react-server-dom-parcel (npm) Jul 24, 2026
React Router: Unauthenticated Denial of Service via Inefficient Route Matching High
CVE-2026-55685 was published for react-router (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set High
CVE-2026-59880 was published for immutable (npm) Jul 21, 2026
nvth Credited to nvth
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS High
CVE-2026-59879 was published for immutable (npm) Jul 21, 2026
mateuszismyname Credited to mateuszismyname
Axios: HTTP/2 streamed uploads bypass `maxBodyLength` Moderate
GHSA-mwf2-3pr3-8698 was published for axios (npm) Jul 20, 2026
asadeddin Credited to asadeddin
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml Moderate
CVE-2026-59868 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
js-yaml: YAML merge-key chains can force quadratic CPU consumption High
CVE-2026-59869 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups High
CVE-2026-13149 was published for brace-expansion (npm) Jul 20, 2026
bnbdr Credited to bnbdr, ljharb, and juliangruber ljharb ljharb
juliangruber juliangruber
Axios: Excessive recursion in formDataToJSON can cause denial of service Moderate
GHSA-42h9-826w-cgv3 was published for axios (npm) Jul 20, 2026
alcls01111 Credited to alcls01111
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service Moderate
GHSA-pmv8-rq9r-6j72 was published for axios (npm) Jul 20, 2026
sam-caldwell Credited to sam-caldwell
adm-zip: Crafted ZIP file triggers 4GB memory allocation High
CVE-2026-39244 was published for adm-zip (npm) Jul 10, 2026
julianladisch Credited to julianladisch
Denial of Service in ws High
GHSA-5v72-xg48-5rpm was published for ws (npm) Jun 4, 2019
RainSignal Credited to RainSignal
dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS High
CVE-2026-50272 was published for dd-trace (npm) Jul 15, 2026
@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo) High
CVE-2026-50171 was published for @angular/common (npm) Jun 15, 2026
alan-agius4 Credited to alan-agius4, JeanMeche, AndrewKushnir, and josephperrott JeanMeche JeanMeche
AndrewKushnir AndrewKushnir josephperrott josephperrott
@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate) High
CVE-2026-54268 was published for @angular/common (npm) Jun 15, 2026
JeanMeche Credited to JeanMeche, alan-agius4, SkyZeroZx, and josephperrott alan-agius4 alan-agius4
SkyZeroZx SkyZeroZx josephperrott josephperrott
Keystone: GraphQL API Endpoint Lacks Query Depth Limits Low
CVE-2026-10802 was published for @keystone-6/core (npm) Jun 4, 2026
ws: Memory exhaustion DoS from tiny fragments and data chunks High
CVE-2026-48779 was published for ws (npm) Jun 15, 2026
Nadav0077 Credited to Nadav0077
DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption Low
CVE-2026-10691 was published for @wonderwhy-er/desktop-commander (npm) Jun 3, 2026
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays High
CVE-2026-49866 was published for @libp2p/gossipsub (npm) Jul 10, 2026
tahaafarooq Credited to tahaafarooq
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
ProTip! Advisories are also available from the GraphQL API