GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36,288 advisories
Filter by severity
vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
High
CVE-2026-92958
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
Critical
CVE-2026-92957
was published
for
vm2
(npm)
Oct 1, 2026
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
Moderate
CVE-2026-92949
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
Critical
CVE-2026-92935
was published
for
vm2
(npm)
Oct 1, 2026
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
Critical
CVE-2026-92937
was published
for
vm2
(npm)
Oct 1, 2026
vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
Critical
CVE-2026-92938
was published
for
vm2
(npm)
Oct 1, 2026
vm2 crypto builtin loads attacker native code through setEngine
Critical
CVE-2026-92939
was published
for
vm2
(npm)
Oct 1, 2026
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
Critical
CVE-2026-92944
was published
for
vm2
(npm)
Oct 1, 2026
vm2 NodeVM can replace the host process TLS trust store
Critical
CVE-2026-92941
was published
for
vm2
(npm)
Oct 1, 2026
vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
Moderate
CVE-2026-92945
was published
for
vm2
(npm)
Oct 1, 2026
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
Moderate
CVE-2026-102830
was published
for
jupyterlab
(pip)
Oct 1, 2026
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
Moderate
CVE-2026-102904
was published
for
jupyterlab
(pip)
Oct 1, 2026
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
High
CVE-2026-102831
was published
for
jupyterlab
(pip)
Oct 1, 2026
jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)
High
CVE-2026-89425
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Oct 1, 2026
jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()
High
CVE-2026-89407
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Oct 1, 2026
devalue: `stringify`/`uneval` serialize shared memory
High
CVE-2026-92708
was published
for
devalue
(npm)
Oct 1, 2026
devalue: Residual sparse-array CPU amplification in uneval
Moderate
GHSA-hx4r-w6wj-j8fg
was published
for
devalue
(npm)
Oct 1, 2026
devalue: Repeated primitive strings cause quadratic expansion in uneval
High
GHSA-mcm9-63f2-9j32
was published
for
devalue
(npm)
Oct 1, 2026
devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
Low
GHSA-wf3x-273g-mvxv
was published
for
devalue
(npm)
Oct 1, 2026
devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
High
GHSA-x5rw-q4pp-hg5g
was published
for
devalue
(npm)
Oct 1, 2026
devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
Moderate
GHSA-4q55-j62x-fr9h
was published
for
devalue
(npm)
Oct 1, 2026
virtualenv bash and fish activation scripts execute commands embedded in paths
High
CVE-2026-102925
was published
for
virtualenv
(pip)
Oct 1, 2026
virtualenv: Command injection via --prompt in activate.bat (batch activator)
High
CVE-2026-102937
was published
for
virtualenv
(pip)
Oct 1, 2026
pypdf: Possible long runtimes with large amount of embedded files
High
CVE-2026-102999
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible long runtimes when generating appearance streams
High
CVE-2026-102998
was published
for
pypdf
(pip)
Oct 1, 2026
ProTip!
Advisories are also available from the
GraphQL API