An open index of dependabot pull requests across open source projects.

Security Advisories

Browse security advisories and track which Dependabot PRs address them.

38,210

Total Advisories

3,606

With Dependabot PRs

4,952

Critical Severity

13,574

High Severity

fast-jwt: Verifier cache accepts expired JWTs without iat.
GHSA-x937-hj6v-793p CVE-2026-107719 MODERATE about 7 hours ago
### Summary `cacheSet` only derives its `exp` cache deadline inside `hasIat` (`src/verifier.js:127-140`). JWT `iat` is optional. For a valid token ...
npm
No PRs yet
AdonisJS: Unencoded route parameters can produce open redirects
GHSA-2m6q-8v3h-jqww CVE-2026-107718 MODERATE about 7 hours ago
Route parameters are inserted into generated URLs without URI encoding. When an application passes untrusted input to a route whose first path seg...
npm
No PRs yet
fast-jwt: createVerifier accepts unsigned JWTs when key is '' or null and algorithms is explicitly set
GHSA-8wpc-h4q6-8fxv CVE-2026-107720 HIGH about 7 hours ago
### Summary `createVerifier` in fast-jwt ≤ 6.3.0 skips signature verification entirely when the `key` option is a falsy synchronous value (`''` or...
npm
No PRs yet
fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion
GHSA-ww5h-9m49-7xx4 CVE-2026-107722 CRITICAL about 7 hours ago
### Summary The fix for CVE-2026-34950 (CVSS 9.1, released in v6.2.0) is **incomplete**. It adds `key.trim()` to the PEM-detection path in `src/cr...
npm
No PRs yet
fast-jwt clockTolerance: Infinity silently bypasses both exp and nbf validation (and persists in the verifier cache)
GHSA-687g-22h4-j4w4 CVE-2026-107721 MODERATE about 7 hours ago
## Summary `createVerifier({ clockTolerance: Infinity })` silently bypasses both `exp` (expiry) AND `nbf` (not-before) validation. Any expired or ...
npm
No PRs yet
fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
GHSA-5hjw-83fp-phq9 CVE-2026-107723 HIGH about 7 hours ago
### Summary `fast-jwt`'s `createVerifier` silently skips **all** configured claim validators (`exp`, `nbf`, `iss`, `aud`, `sub`, `jti`, `nonce`) w...
npm
No PRs yet
fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery
GHSA-g3jj-5cmm-3hxx CVE-2026-107724 HIGH about 7 hours ago
### Summary `fast-jwt` 6.2.4 silently classifies raw serialized public JWK JSON as an HMAC secret. If an application supplies public JWK JSON tex...
npm
No PRs yet
PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure
GHSA-6wjp-v33h-5cvq CVE-2026-61426 HIGH about 7 hours ago
## Summary The AgentOS server in the `praisonai` TypeScript/npm package ships an insecure default: it binds `0.0.0.0`, sets no API key, and uses C...
npm
No PRs yet
music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — unreleased regression on master
GHSA-f94x-6692-553q CVE-2026-107391 MODERATE about 9 hours ago
### Summary `StsdAtom.get()` in `lib/mp4/AtomToken.ts` parses an MP4 `stsd` (sample description) box's entry table by advancing a cursor with `off...
npm
No PRs yet
music-metadata: Uncontrolled memory allocation in APEv2 parser
GHSA-53v6-4h7p-p4gj CVE-2026-107387 MODERATE about 9 hours ago
## Summary `music-metadata` 11.15.0 is vulnerable to uncontrolled memory allocation in the APEv2 parser. The parser reads the size of an APEv2 ta...
npm
No PRs yet
music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS
GHSA-jjpr-9cvf-cq55 CVE-2026-107388 MODERATE about 9 hours ago
### Summary The ID3v2 parser in music-metadata trusts the tag size field without validation and allocates the full requested buffer before reading...
npm
No PRs yet
music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process abort
GHSA-5gfj-9q3v-qfp3 CVE-2026-107389 MODERATE about 9 hours ago
## Summary The Matroska/WebM EBML parser decodes attacker-controlled variable-length integer (VINT) element lengths without first validating that ...
npm
No PRs yet
MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH_ESCAPES
GHSA-r3rv-jm3r-62q2 CVE-2026-107385 HIGH about 9 hours ago
### Description When escaping string and binary parameters for the text protocol, the connector always escaped the quote character with a backslash...
npm
No PRs yet
MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMultiParamEntries)
GHSA-v6pj-gxxw-phfw CVE-2026-107384 HIGH about 9 hours ago
### Description With the non-default permitSetMultiParamEntries option enabled, an object passed as a query parameter is expanded into a SET clause...
npm
No PRs yet
MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON parameters
GHSA-48qf-xh34-q73r CVE-2026-107383 HIGH about 9 hours ago
### Description When encoding a GeoJSON Polygon or MultiPolygon parameter for the binary protocol, the connector sized its output buffer from the l...
npm
No PRs yet
MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS
GHSA-cx2f-j9fh-8g68 CVE-2026-107382 MODERATE about 9 hours ago
### Description On the zero-configuration TLS path, the connector accepts a self-signed server certificate at the TLS level and then validates the ...
npm
No PRs yet
music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of GHSA-v6c2-xwv6-8xf7)
GHSA-8j4c-6x6g-rq3j CVE-2026-107392 MODERATE about 9 hours ago
## Summary `DsfParser.parseChunks` skips an unrecognised chunk's payload with an **un-awaited** call: ```js this.tokenizer.ignore(Number(chunkHeade...
npm
No PRs yet
Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates
GHSA-xw65-4hp5-5hc7 CVE-2026-106444 MODERATE about 11 hours ago
## Summary `Handlebars.precompile()` generates JavaScript source that is commonly embedded in browser `<script>` elements. Before the fix, static ...
npm
1
Dependabot PRs
Handlebars: JavaScript Injection via AST Type Confusion in compile (bypass of CVE-2026-33937)
GHSA-8r5x-fm3f-whwj CVE-2026-106446 CRITICAL about 11 hours ago
## Summary `Handlebars.compile()` and `Handlebars.precompile()` accept a pre-parsed AST as well as a template string. Handlebars 4.7.9 added valid...
npm
1
Dependabot PRs
Handlebars: JavaScript Injection via Own Property Check Bypass
GHSA-p8wg-vrv2-v86f CVE-2026-106445 CRITICAL about 11 hours ago
## Summary Handlebars can expose the `Function` constructor despite its prototype-access deny list. When a template reaches `Function.prototype`, ...
npm
1
Dependabot PRs
LangChain: MongoDBChatMessageHistory query injection can allow cross-session access
GHSA-m6rx-h84q-8r95 CVE-2026-106119 MODERATE about 11 hours ago
## Impact `MongoDBChatMessageHistory` did not enforce the documented string type for session identifiers at runtime. In affected applications, a s...
npm
No PRs yet
JHipster: SQL Injection in the Parameter of JHipster-Generated Reactive (WebFlux + R2DBC) Applicationssort
GHSA-r223-96jv-q533 CVE-2026-107375 HIGH about 11 hours ago
# SQL Injection in the `sort` Parameter of JHipster-Generated Reactive (WebFlux + R2DBC) Applications - **Product**: jhipster/generator-jhipster (...
npm
No PRs yet
JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
GHSA-9ffp-22j7-56r2 CVE-2026-107303 HIGH about 11 hours ago
## Summary Applications generated by generator-jhipster v9.2.0 can persist user-controlled Blob ContentType values and later use those values as th...
npm
No PRs yet
msgpack5: Truncated map32 headers throw an unexpected error
GHSA-8f34-f56x-9xph CVE-2026-107302 HIGH about 11 hours ago
### Impact A truncated `map32` header causes an out-of-bounds buffer read and throws `RangeError` instead of `IncompleteBufferError`. Applications...
npm
No PRs yet
msgpack5: Many buffered values can exhaust the streaming decoder stack
GHSA-5x5g-h9x8-2fh9 CVE-2026-107300 HIGH about 11 hours ago
### Impact The streaming decoder recursively invokes itself for every complete value remaining in a chunk. A single chunk containing many small va...
npm
No PRs yet
msgpack5: Reserved byte can cause unbounded stream buffering
GHSA-26wq-p25c-j6fv CVE-2026-107299 MODERATE about 12 hours ago
### Impact The reserved MessagePack byte `0xc1` is incorrectly treated as incomplete input. When it appears at the start of a decoder stream, all ...
npm
No PRs yet
msgpack5: Partial options disable prototype protection
GHSA-8hq7-ggx2-cc6m CVE-2026-107301 MODERATE about 12 hours ago
### Impact Passing an empty or partial options object disables the default `protoAction: 'error'` protection. A map containing a `__proto__` key c...
npm
No PRs yet
msgpack5: Deeply nested input can exhaust the decoder stack
GHSA-24ch-f2g6-9hhh CVE-2026-107298 MODERATE about 12 hours ago
### Impact The decoder has no nesting-depth limit for arrays and maps. An attacker who can provide MessagePack input can use deeply nested contain...
npm
No PRs yet
msgpack5: Quadratic parsing in the streaming decoder
GHSA-gcx5-hxj7-gpqq CVE-2026-107297 MODERATE about 12 hours ago
### Impact The streaming decoder reparses an incomplete container from the beginning whenever another chunk arrives. A remote peer can split one v...
npm
No PRs yet
msgpack5: Decoding negative int64 values mutates the input buffer
GHSA-qw35-55vc-rhgj CVE-2026-107296 LOW about 12 hours ago
### Impact Decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer. Applications that retai...
npm
No PRs yet
Ghost: Remote Code Execution via Bookmark Card Images
GHSA-788w-68h3-cvxp CVE-2026-105642 HIGH 1 day ago
### Impact An image processing library bundled with Ghost contained a vulnerability in its SVG handling. Any staff user, including Contributors, c...
npm
No PRs yet
Ghost: Stored XSS via Embed Card Previews
GHSA-69qc-f5m6-889c CVE-2026-105643 HIGH 1 day ago
### Impact Embed cards in the Ghost editor could be used to bypass the fix for GHSA-8vhf-xxpj-4qrg. Any staff user, including Contributors, could ...
npm
No PRs yet
Ghost : Stored XSS via SVG Files in Content Imports
GHSA-hqq2-xqr2-fmx2 CVE-2026-105644 MODERATE 1 day ago
### Impact SVG images included in content imports were stored without sanitization. An attacker who convinced an Administrator to import a crafted...
npm
No PRs yet
Ghost: Regular Expression Denial of Service in External Media Inliner
GHSA-9m4w-fmjw-fvjq CVE-2026-105645 MODERATE 1 day ago
### Impact A crafted request to the external media inliner could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this ...
npm
No PRs yet
Ghost: Regular Expression Denial of Service in Content Import
GHSA-fwh9-qg68-vxp4 CVE-2026-105646 MODERATE 1 day ago
### Impact A crafted content import file could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administr...
npm
No PRs yet
Ghost: Server-Side Request Forgery in Bookmark Fetching
GHSA-322m-ff4g-9vx9 CVE-2026-105647 MODERATE 1 day ago
### Impact A validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP reques...
npm
No PRs yet
Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses
GHSA-r7f2-6fj8-6fg2 CVE-2026-105648 MODERATE 1 day ago
### Impact A validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP reques...
npm
No PRs yet
Ghost: Stored XSS via SVG Uploads Bypassing Sanitization
GHSA-8575-cr6v-7jh4 CVE-2026-105649 HIGH 1 day ago
### Impact SVG media thumbnails, and SVG images uploaded with a non-SVG file extension, were stored without sanitization. This allowed any staff u...
npm
No PRs yet
Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages
GHSA-3w37-wq28-93x7 CVE-2026-94544 MODERATE 1 day ago
Pending `use cache` fills are shared across requests for the same key without distinguishing Draft Mode requests from regular requests. When two su...
npm
41
Dependabot PRs
Next.js has cache poisoning of SSG and ISR pages in self-hosted applications
GHSA-4jqv-mc3x-m676 CVE-2026-94543 MODERATE 1 day ago
Self-hosted Next.js applications that use the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages can have a page...
npm
44
Dependabot PRs
Next.js has information disclosure in development server's Model Context Protocol endpoint
GHSA-39w2-rjm5-chcv CVE-2026-94486 LOW 1 day ago
The Next.js development server (`next dev`) exposes a Model Context Protocol endpoint that does not verify which website a request originates from,...
npm
41
Dependabot PRs
Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass
GHSA-f87g-xv8r-7p7x CVE-2026-94485 MODERATE 1 day ago
In Next.js App Router applications built with webpack, metadata image routes such as opengraph-image and twitter-image ignore the `dynamicParams` r...
npm
44
Dependabot PRs
Next.js has cache poisoning in SSG/ISR rendering that leads to cross-user content substitution and persistent denial of service
GHSA-mcj8-r9mp-w47p CVE-2026-94484 MODERATE 1 day ago
Next.js applications that use a root-level catch-all page together with statically generated or Incremental Static Regeneration routes can have the...
npm
44
Dependabot PRs
Next.js has Server-Side Request Forgery in Image Optimization
GHSA-cjq9-62q9-8jv4 CVE-2026-94483 HIGH 1 day ago
## Impact An attacker-controlled, allow-listed remote URL can lead to server-side request forgery (e.g. to private IPs) during Image Optimization....
npm
41
Dependabot PRs
Payload: SQL injection in SQLite/Postgres
GHSA-pj7x-6wpf-pgvp CVE-2026-105856 HIGH 1 day ago
### Impact An attacker who has read plus create or update access to a collection can submit a request that includes a SQL injection targeting a sp...
npm
No PRs yet
Payload: Remote Code Execution through first-register
GHSA-97rh-rhh2-7vjv CVE-2026-105858 HIGH 1 day ago
### Impact A crafted request to the public first-register operation can be used to perform a RCE exploit. **You are affected if:** - You use loca...
npm
No PRs yet
Payload has a tenant authorization bypass in Multi-Tenant Plugin
GHSA-p96c-xwx8-3cqj CVE-2026-105860 HIGH 1 day ago
## Impact When using the default tenant array field access, an authenticated user could assign themselves to other tenants. **You are affected if...
npm
No PRs yet
Payload external upload trust validation issue
GHSA-pj5h-5q6c-3pfx CVE-2026-105861 HIGH 1 day ago
## Impact Under certain external upload configurations, Payload could send authentication data to a destination that was not verified as trusted. ...
npm
No PRs yet
Payload: Bypassed sanitization of user uploaded SVGs
GHSA-2pwp-2369-8fg3 CVE-2026-105862 HIGH 1 day ago
## Impact A malicious SVG file upload could bypass sanitization, be stored, and execute attacker-controlled JavaScript (XSS) after a user download...
npm
No PRs yet
@payloadcms/plugin-multi-tenant has a cross-tenant create issue
GHSA-xhm9-gwgw-3q2q CVE-2026-105864 MODERATE 1 day ago
### Impact An authenticated user limited to one tenant could create a record in another tenant. This requires the multi-tenant plugin with at least...
npm
No PRs yet