GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,830
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,155
Rust
1,577
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,512
Rust
20
647 advisories
Filter by severity
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject()...
High
Unreviewed
CVE-2026-93753
was published
Sep 18, 2026
Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution...
Moderate
Unreviewed
CVE-2026-92781
was published
Sep 16, 2026
Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution...
High
Unreviewed
CVE-2026-92779
was published
Sep 16, 2026
joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the...
Moderate
Unreviewed
CVE-2026-90771
was published
Sep 13, 2026
yayson: Prototype pollution in Store/LegacyStore deserialization
Critical
CVE-2026-61534
was published
for
yayson
(npm)
Sep 11, 2026
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
Moderate
CVE-2026-86078
was published
for
n8n
(npm)
Sep 10, 2026
Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype...
High
Unreviewed
CVE-2026-81994
was published
Sep 8, 2026
joi: Prototype pollution via a `__proto__` language key in custom messages
Low
CVE-2026-84368
was published
for
@hapi/joi
(npm)
Sep 8, 2026
joi: object().rename() with a template target can set the validated object's prototype
Low
CVE-2026-84367
was published
for
joi
(npm)
Sep 8, 2026
node-csv: Prototype replacement still reachable via columns path
Moderate
CVE-2026-85063
was published
for
csv-parse
(npm)
Sep 8, 2026
sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain...
Critical
Unreviewed
CVE-2026-85625
was published
Sep 4, 2026
toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization
High
CVE-2026-63376
was published
for
toml
(npm)
Sep 3, 2026
TOON: Prototype pollution when decoding untrusted TOON input
High
CVE-2026-82404
was published
for
@toon-format/toon
(npm)
Sep 3, 2026
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
High
CVE-2026-71553
was published
for
apostrophe
(npm)
Sep 2, 2026
Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes
Moderate
GHSA-cp6q-959q-f8rh
was published
for
@tiptap/core
(npm)
Sep 2, 2026
Livewire DOM-based cross-site scripting during client-side state handling
Moderate
CVE-2026-81887
was published
for
livewire/livewire
(Composer)
Sep 2, 2026
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
High
CVE-2026-73088
was published
for
browserslist
(npm)
Sep 1, 2026
SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form...
Moderate
Unreviewed
CVE-2026-82257
was published
Aug 28, 2026
exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge...
Critical
Unreviewed
CVE-2026-78207
was published
Aug 24, 2026
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch...
High
Unreviewed
CVE-2026-18420
was published
Aug 20, 2026
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
Moderate
CVE-2026-55451
was published
for
gettext-converter
(npm)
Aug 20, 2026
n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the...
Moderate
Unreviewed
CVE-2026-77083
was published
Aug 20, 2026
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in...
High
Unreviewed
CVE-2026-23929
was published
Aug 18, 2026
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
High
CVE-2026-73654
was published
for
@trigger.dev/core
(npm)
Aug 13, 2026
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit...
High
Unreviewed
CVE-2026-72749
was published
Aug 11, 2026
ProTip!
Advisories are also available from the
GraphQL API