Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

127 advisories

Loading
Axios: HTTP/2 streamed uploads bypass `maxBodyLength` Moderate
GHSA-mwf2-3pr3-8698 was published for axios (npm) Jul 20, 2026
asadeddin Credited to asadeddin
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml Moderate
CVE-2026-59868 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
Axios: Excessive recursion in formDataToJSON can cause denial of service Moderate
GHSA-42h9-826w-cgv3 was published for axios (npm) Jul 20, 2026
alcls01111 Credited to alcls01111
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service Moderate
GHSA-pmv8-rq9r-6j72 was published for axios (npm) Jul 20, 2026
sam-caldwell Credited to sam-caldwell
LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body Moderate
CVE-2026-44645 was published for liquidjs (npm) May 27, 2026
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
Claw Orchestrator has inefficient regular expression complexity via validateRegex() Moderate
CVE-2026-10291 was published for @enderfga/claw-orchestrator (npm) Jun 2, 2026
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations Moderate
CVE-2026-48988 was published for markdown-it (npm) Jun 15, 2026
tndud042713 Credited to tndud042713
UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()` Moderate
CVE-2026-48125 was published for ua-parser-js (npm) Jun 15, 2026
sondt99 Credited to sondt99
joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas Moderate
CVE-2026-48038 was published for joi (npm) Jun 11, 2026
kexwin Credited to kexwin
OpenClaude MCP OAuth Callback: State Check Bypass via error Param Leads to DoS Moderate
CVE-2026-42073 was published for @gitlawb/openclaude (npm) May 12, 2026
xancyber Credited to xancyber
brace-expansion: Large numeric range defeats documented `max` DoS protection Moderate
CVE-2026-45149 was published for brace-expansion (npm) May 18, 2026
subhashdasyam Credited to subhashdasyam and katzj katzj katzj
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects Moderate
CVE-2026-34043 was published for serialize-javascript (npm) Mar 27, 2026
TomerAberbach Credited to TomerAberbach and sealonohana sealonohana sealonohana
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests Moderate
CVE-2026-44456 was published for hono (npm) May 6, 2026
lalalala5678 Credited to lalalala5678 and Jvr2022 Jvr2022 Jvr2022
Kazamayc Credited to Kazamayc
@evomap/evolver has an unbounded request body in proxy /asset/submit that causes persistent disk-exhaustion DoS Moderate
GHSA-7xp7-m392-h92c was published for @evomap/evolver (npm) May 5, 2026
offset Credited to offset
OpenClaw: Gateway WebSocket Denial of Service via unbounded pre-auth upgrades Moderate
CVE-2026-41399 was published for openclaw (npm) Mar 31, 2026
topsec-bunney Credited to topsec-bunney
Axios HTTP/2 Session Cleanup State Corruption Vulnerability Moderate
CVE-2026-39865 was published for axios (npm) Apr 8, 2026
vmulas Credited to vmulas and sealonohana sealonohana sealonohana
Zod jsVideoUrlParser vulnerable to ReDoS in util.js Moderate
CVE-2026-5986 was published for js-video-url-parser (npm) Apr 10, 2026
OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation Moderate
CVE-2026-35640 was published for openclaw (npm) Mar 29, 2026
tdjackey Credited to tdjackey
OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling Moderate
CVE-2026-35626 was published for openclaw (npm) Mar 26, 2026
SEORY0 Credited to SEORY0
Next.js has Unbounded Memory Consumption via PPR Resume Endpoint Moderate
CVE-2025-59472 was published for next (npm) Jan 28, 2026
cylewaitforit Credited to cylewaitforit and jesvinjames jesvinjames jesvinjames
skilleton has improper input handling in repository/path processing Moderate
GHSA-5g3j-89fr-r2vp was published for skilleton (npm) Apr 8, 2026
Directus: GraphQL Alias Amplification Denial of Service Due to Missing Query Cost/Complexity Limits Moderate
CVE-2026-35441 was published for directus (npm) Apr 4, 2026
liyander Credited to liyander
ProTip! Advisories are also available from the GraphQL API