GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,654
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,861
Pub
13
RubyGems
1,050
Rust
1,304
Swift
53
Unreviewed advisories
All unreviewed
5,000+
29,689 advisories
Filter by severity
VM2 Has a WASM Sandbox Escape (Node 25 only)
Critical
CVE-2026-26956
was published
for
vm2
(npm)
May 5, 2026
VM2 Has a Sandbox Escape Issue via SuppressedError
Critical
CVE-2026-26332
was published
for
vm2
(npm)
May 5, 2026
VM2 Has Sandbox Breakout Through Inspect Function
Critical
CVE-2026-24781
was published
for
vm2
(npm)
May 5, 2026
Jupyter Server has an open redirection vulnerability in `next` query parameter
Moderate
CVE-2025-61669
was published
for
jupyter-server
(pip)
May 5, 2026
VM2 Has Sandbox Breakout Through Promise Species
Critical
CVE-2026-24120
was published
for
vm2
(npm)
May 5, 2026
Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
Moderate
CVE-2026-42037
was published
for
axios
(npm)
May 5, 2026
Axios: no_proxy bypass via IP alias allows SSRF
Moderate
CVE-2026-42038
was published
for
axios
(npm)
May 5, 2026
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
Moderate
CVE-2026-42039
was published
for
axios
(npm)
May 5, 2026
Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
Moderate
CVE-2026-42034
was published
for
axios
(npm)
May 5, 2026
Axios: HTTP adapter streamed responses bypass maxContentLength
Moderate
CVE-2026-42036
was published
for
axios
(npm)
May 5, 2026
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
High
CVE-2026-42033
was published
for
axios
(npm)
May 5, 2026
Axios: Header Injection via Prototype Pollution
High
CVE-2026-42035
was published
for
axios
(npm)
May 5, 2026
Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
Moderate
CVE-2026-42042
was published
for
axios
(npm)
May 5, 2026
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Moderate
CVE-2026-42041
was published
for
axios
(npm)
May 5, 2026
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
High
CVE-2026-42043
was published
for
axios
(npm)
May 5, 2026
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
Moderate
CVE-2026-42044
was published
for
axios
(npm)
May 5, 2026
Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
High
CVE-2026-42264
was published
for
axios
(npm)
May 5, 2026
Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
Low
CVE-2026-42040
was published
for
axios
(npm)
May 5, 2026
ogham-mcp had credentials embedded in published PyPI sdists -- Neon postgres URLs and Voyage API key
Moderate
GHSA-8pqq-224h-x875
was published
for
ogham-mcp
(pip)
May 5, 2026
sequoia-git has broken hard revocation handling
Low
GHSA-g27r-r6ph-vf5r
was published
for
sequoia-git
(Rust)
May 4, 2026
webonyx/graphql-php has quadratic validation cost in OverlappingFieldsCanBeMerged via inline fragments
High
GHSA-fc86-6rv6-2jpm
was published
for
webonyx/graphql-php
(Composer)
May 4, 2026
livewire-markdown-editor has arbitrary file upload that allows stored XSS via attachment handler
High
GHSA-gxxh-8vcj-w2mh
was published
for
mckenziearts/livewire-markdown-editor
(Composer)
May 4, 2026
pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy via unrestricted `proxy.*` config (incomplete fix for CVE-2026-33509 / -35463 / -35464 / -35586)
High
CVE-2026-42313
was published
for
pyload-ng
(pip)
May 4, 2026
pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification via unrestricted `ssl_verify` config (incomplete fix for CVE-2026-33509 / -35463 / -35464 / -35586)
Moderate
CVE-2026-42312
was published
for
pyload-ng
(pip)
May 4, 2026
net-imap vulnerable to command Injection via "raw" arguments to multiple commands
Moderate
CVE-2026-42257
was published
for
net-imap
(RubyGems)
May 4, 2026
ProTip!
Advisories are also available from the
GraphQL API