GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,653
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,860
Pub
13
RubyGems
1,050
Rust
1,304
Swift
53
Unreviewed advisories
All unreviewed
5,000+
29,681 advisories
Filter by severity
Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
Moderate
CVE-2026-42037
was published
for
axios
(npm)
May 5, 2026
Axios: no_proxy bypass via IP alias allows SSRF
Moderate
CVE-2026-42038
was published
for
axios
(npm)
May 5, 2026
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
Moderate
CVE-2026-42039
was published
for
axios
(npm)
May 5, 2026
Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
Moderate
CVE-2026-42034
was published
for
axios
(npm)
May 5, 2026
Axios: HTTP adapter streamed responses bypass maxContentLength
Moderate
CVE-2026-42036
was published
for
axios
(npm)
May 5, 2026
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
High
CVE-2026-42033
was published
for
axios
(npm)
May 5, 2026
Axios: Header Injection via Prototype Pollution
High
CVE-2026-42035
was published
for
axios
(npm)
May 5, 2026
Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
Moderate
CVE-2026-42042
was published
for
axios
(npm)
May 5, 2026
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Moderate
CVE-2026-42041
was published
for
axios
(npm)
May 5, 2026
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
High
CVE-2026-42043
was published
for
axios
(npm)
May 5, 2026
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
Moderate
CVE-2026-42044
was published
for
axios
(npm)
May 5, 2026
Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
High
CVE-2026-42264
was published
for
axios
(npm)
May 5, 2026
Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
Low
CVE-2026-42040
was published
for
axios
(npm)
May 5, 2026
ogham-mcp had credentials embedded in published PyPI sdists -- Neon postgres URLs and Voyage API key
Moderate
GHSA-8pqq-224h-x875
was published
for
ogham-mcp
(pip)
May 5, 2026
sequoia-git has broken hard revocation handling
Low
GHSA-g27r-r6ph-vf5r
was published
for
sequoia-git
(Rust)
May 4, 2026
webonyx/graphql-php has quadratic validation cost in OverlappingFieldsCanBeMerged via inline fragments
High
GHSA-fc86-6rv6-2jpm
was published
for
webonyx/graphql-php
(Composer)
May 4, 2026
livewire-markdown-editor has arbitrary file upload that allows stored XSS via attachment handler
High
GHSA-gxxh-8vcj-w2mh
was published
for
mckenziearts/livewire-markdown-editor
(Composer)
May 4, 2026
pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy via unrestricted `proxy.*` config (incomplete fix for CVE-2026-33509 / -35463 / -35464 / -35586)
High
CVE-2026-42313
was published
for
pyload-ng
(pip)
May 4, 2026
pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification via unrestricted `ssl_verify` config (incomplete fix for CVE-2026-33509 / -35463 / -35464 / -35586)
Moderate
CVE-2026-42312
was published
for
pyload-ng
(pip)
May 4, 2026
net-imap vulnerable to command Injection via "raw" arguments to multiple commands
Moderate
CVE-2026-42257
was published
for
net-imap
(RubyGems)
May 4, 2026
net-imap vulnerable to command Injection via unvalidated Symbol inputs
Moderate
CVE-2026-42258
was published
for
net-imap
(RubyGems)
May 4, 2026
net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication
Moderate
CVE-2026-42256
was published
for
net-imap
(RubyGems)
May 4, 2026
net-imap has quadratic complexity when reading response literals
Low
CVE-2026-42245
was published
for
net-imap
(RubyGems)
May 4, 2026
net-imap vulnerable to STARTTLS stripping via invalid response timing
High
CVE-2026-42246
was published
for
net-imap
(RubyGems)
May 4, 2026
`mysten-metrics` was removed from crates.io for malicious code
Critical
GHSA-g38r-8gmr-ghrf
was published
for
mysten-metrics
(Rust)
May 4, 2026
ProTip!
Advisories are also available from the
GraphQL API