Security Advisories
Browse security advisories and track which Dependabot PRs address them.
35,046
Total Advisories
3,110
With Dependabot PRs
4,560
Critical Severity
12,276
High Severity
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
GHSA-v422-hmwv-36x6 CVE-2026-12590 LOW 8 days ago
### Impact
When body-parser is configured with an invalid `limit` option value, such as an unparseable string or `NaN`, `bytes.parse()` returns `n...
npm
21
Dependabot PRs
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
GHSA-r557-wffq-wvrc CVE-2026-59730 LOW 8 days ago
### Impact
With `trailingSlash: 'always'` configured, the `@astrojs/node` standalone server's static file handler appends a trailing slash to requ...
npm
No PRs yet
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
GHSA-f48w-9m4c-m7f5 CVE-2026-59729 MODERATE 8 days ago
## Summary
The fix for CVE-2026-54298 (GHSA-jrpj-wcv7-9fh9) added an `INVALID_ATTR_NAME_CHAR` guard to `addAttribute()` so that spread-prop attrib...
npm
No PRs yet
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
GHSA-8j5q-mfj2-5q9q CVE-2026-59728 MODERATE 8 days ago
## Summary
In `@astrojs/rss`, the `source.title` and `enclosure.type` item fields are interpolated directly into XML template strings without XML-...
npm
No PRs yet
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
GHSA-7pw4-f3q4-r2p2 CVE-2026-59727 LOW 8 days ago
### Summary
When a `transition:persist`, `transition:scope`, or `transition:persist-props` directive is applied to a client-hydrated (`client:*`) ...
npm
No PRs yet
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
GHSA-9hw9-ch79-4vh6 CVE-2026-59205 HIGH 8 days ago
### Summary
Pillow's public `ImageCms.ImageCmsTransform.apply(im, imOut)` API can trigger
controlled native heap corruption when the caller suppli...
pypi
No PRs yet
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
GHSA-vjc4-5qp5-m44j CVE-2026-59204 HIGH 8 days ago
### Summary
`src/libImaging/Jpeg2KDecode.c:853` accumulates `total_component_width` across every tile in a JPEG2000 image instead of recomputing it...
pypi
No PRs yet
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
GHSA-pg7v-jwj7-p798 CVE-2026-59203 MODERATE 8 days ago
### Summary
Pillow's EPS parser (PIL/EpsImagePlugin.py) accepts a negative byte count in the %%BeginBinary directive. A crafted EPS file can cause...
pypi
No PRs yet
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
GHSA-jjj6-mw9f-p565 CVE-2026-59200 HIGH 8 days ago
### Summary
`PdfParser.PdfStream.decode()` in Pillow's `PdfParser.py` calls `zlib.decompress()` with the `bufsize` parameter set to the value of th...
pypi
No PRs yet
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
GHSA-6r8x-57c9-28j4 CVE-2026-59199 HIGH 8 days ago
### Summary
Pillow's public image coordinate APIs can trigger a native heap out-of-bounds
write when given coordinates near the signed 32-bit inte...
pypi
No PRs yet
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
GHSA-fj7v-r99m-22gq CVE-2026-59198 MODERATE 8 days ago
### Summary
Pillow's TGA RLE encoder reads past its row buffer when saving a mode `"1"`
image. Adjacent process heap bytes can be copied into the ...
pypi
No PRs yet
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
GHSA-xj96-63gp-2gmr CVE-2026-59197 HIGH 8 days ago
### Summary
Pillow's public rank-filter API can trigger a native heap out-of-bounds write
when given a very large odd filter size.
Minimal public...
pypi
No PRs yet
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
GHSA-wp74-jgxh-gv4q CVE-2026-50651 HIGH 8 days ago
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET HTTP client (System.Net.Ht...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
GHSA-74jp-vm22-8q8x CVE-2026-50659 MODERATE 8 days ago
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SMTP client (System.Net.Ma...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
GHSA-8q5v-6pqq-x66h CVE-2026-50525 HIGH 8 days ago
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Sec...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
GHSA-qvw7-jm5c-6hqw CVE-2026-50528 HIGH 8 days ago
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Securi...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
GHSA-23rf-6693-g89p CVE-2026-50648 HIGH 8 days ago
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Sec...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
GHSA-w7cw-xp7h-6j5j CVE-2026-50524 HIGH 8 days ago
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Securi...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
GHSA-g8r8-53c2-pm3f CVE-2026-47304 HIGH 8 days ago
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Sec...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
GHSA-cvvh-rhrc-wg4q CVE-2026-47302 HIGH 8 days ago
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML processing (System.Sec...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
GHSA-rp2p-6cmp-jxj9 CVE-2026-57108 HIGH 8 days ago
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in the .NET runtime cryptography l...
nuget
No PRs yet
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
GHSA-gcfj-64vw-6mp9 HIGH 8 days ago
## Summary
Axios’ Node.js HTTP adapter can route requests through an attacker-controlled proxy when `Object.prototype.proxy` is polluted and reque...
npm
No PRs yet
Axios form serializer maxDepth bypass via {} metatoken
GHSA-hcpx-6fm6-wx23 MODERATE 8 days ago
## Summary
Axios versions in the fixed lines for GHSA-62hf-57xw-28j9 still contain an incomplete depth-limit bypass in `lib/helpers/toFormData.js`...
npm
No PRs yet
Axios: Nested axios option objects can consume polluted prototype values
GHSA-7q8q-rj6j-mhjq MODERATE 8 days ago
## Summary
Axios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted `Object.pr...
npm
No PRs yet
Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
GHSA-mwf2-3pr3-8698 MODERATE 8 days ago
## Summary
Axios versions with Node.js HTTP/2 support allow streamed request bodies to bypass `maxBodyLength` enforcement when requests are sent w...
npm
No PRs yet
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
GHSA-jqh4-m9w3-8hp9 MODERATE 8 days ago
## Summary
axios’ fetch adapter does not enforce `maxBodyLength` for live WHATWG `ReadableStream` request bodies whose size cannot be determined b...
npm
No PRs yet
Axios: Prototype pollution gadgets can alter axios request construction
GHSA-mmx7-hfxf-jppx MODERATE 8 days ago
## Summary
axios is vulnerable to read-side prototype-pollution gadgets when `Object.prototype` has already been polluted by another vulnerability...
npm
No PRs yet
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
GHSA-f4gw-2p7v-4548 MODERATE 8 days ago
## Summary
Axios versions containing `lib/helpers/shouldBypassProxy.js` do not treat `0.0.0.0` as a local address when evaluating `NO_PROXY` rules...
npm
No PRs yet
File Browser: Colliding username normalization gives two users the same home directory
GHSA-7rc3-g7h6-22m7 CVE-2026-62685 HIGH 8 days ago
## Summary
FileBrowser confines each user to a *scope*: a home directory that acts as the boundary for everything they can read or write. When sel...
go
No PRs yet
File Browser: Share API exposes the password hash and bypass token
GHSA-833g-cqhp-h72j CVE-2026-62684 LOW 8 days ago
## Summary
When a user creates a password-protected share or lists existing shares, the JSON response includes the full bcrypt `password_hash` and...
go
No PRs yet
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
GHSA-83xp-526h-j3ww CVE-2026-62843 MODERATE 8 days ago
## Summary
The fix for `GHSA-gxjx-7m74-hcq8` / `CVE-2026-54093` (shipped in v2.63.6) added a `strings.ReplaceAll(nameInArchive, "\\", "/")` step t...
go
No PRs yet
protobufjs: Text Format string map parsing can mutate returned map object prototype
GHSA-jfj6-75fj-8934 CVE-2026-59876 MODERATE 8 days ago
## Summary
The protobuf.js text format extension parsed string-keyed map entries using ordinary property assignment. A text-format map entry with ...
npm
No PRs yet
protobufjs: Denial of Service via infinite loop in .proto option parsing
GHSA-j3f2-48v5-ccww CVE-2026-59877 MODERATE 8 days ago
## Summary
protobufjs parsed option names by advancing through schema tokens until it reached an `=` token, without checking for end of input. A c...
npm
No PRs yet
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
GHSA-m28w-2pqf-7qgj CVE-2026-14631 MODERATE 8 days ago
### Impact
An unauthenticated peer that can reach the `webpack-dev-server` process can terminate it by sending either a normal HTTP request with a...
npm
No PRs yet
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
GHSA-f5vj-f2hx-8m93 CVE-2026-14620 MODERATE 8 days ago
### Impact
The internal `/webpack-dev-server/open-editor` and `/webpack-dev-server/invalidate` endpoints perform state-changing actions on any `GE...
npm
No PRs yet
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
GHSA-g446-98w2-8p5w CVE-2026-59883 MODERATE 8 days ago
### Impact
`CookieJar` does not restrict a cookie scoped to an IP address to the exact host that set it. When a stored cookie's `Domain` attribute...
packagist
No PRs yet
Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
GHSA-vj59-8hwv-xxmv CVE-2026-59731 HIGH 8 days ago
# Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
## Summary
Astro 6.4.7 appears to reintr...
npm
No PRs yet
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
GHSA-gjfg-22fp-rrxx CVE-2026-59946 MODERATE 8 days ago
## Summary
A Composer package declares its executables in the `bin` field of its `composer.json`. When Composer installs a package, it processes e...
packagist
No PRs yet
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
GHSA-g6xq-892h-64w3 CVE-2026-59947 MODERATE 8 days ago
## Summary
When Composer is run with -vvv (debug verbosity), it could print a credential that was embedded directly in a repository or package URL...
packagist
No PRs yet
node-tar: Process crash via PAX numeric path type confusion
GHSA-w8wr-v893-vjvp CVE-2026-59871 MODERATE 8 days ago
### Summary
A crafted 2.5KB tar archive crashes any Node.js process that extracts it. The PAX header parser coerces all-digit path values to JavaS...
npm
No PRs yet
node-tar: Decompression/parse DoS via unlimited input
GHSA-23hp-3jrh-7fpw CVE-2026-59873 CRITICAL 8 days ago
### Summary
A **Decompression/parse DoS via unlimited input** vulnerability in `node-tar` allows an attacker to exhaust server resources (disk spac...
npm
No PRs yet
node-tar: Negative tar entry size causes infinite loop in archive replace
GHSA-8x88-c5mf-7j5w CVE-2026-59874 HIGH 8 days ago
### Summary
A checksum-valid tar archive with a negative base-256 encoded entry size can make `tar.replace()` loop forever while scanning the exis...
npm
No PRs yet
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
GHSA-gvwx-54wh-qm9j CVE-2026-59875 MODERATE 8 days ago
## Summary
`node-tar` strips trailing `NUL` bytes from long-name (`L`) and long-linkpath (`K`) GNU extended headers but does **not** apply the sam...
npm
No PRs yet
Socket.IO: Engine.IO Polling Transport Connection Exhaustion
GHSA-r635-g3xr-vw7x CVE-2026-59725 HIGH 8 days ago
### Impact
An unauthenticated remote attacker can cause a denial of service in affected versions of **engine.io** by opening Engine.IO polling ses...
npm
No PRs yet
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
GHSA-395f-4hp3-45gv CVE-2026-13311 HIGH 8 days ago
### Summary
`shell-quote`'s `parse()` finalizes its token list with a `reduce` that uses
`Array.prototype.concat` as the accumulator. Each `prev.co...
npm
27
Dependabot PRs
Directus: Authorization-dependent response served from unsegmented cache key
GHSA-c6w9-5g5j-jh2p CVE-2026-61836 HIGH 8 days ago
## Summary
When response caching is enabled (`CACHE_ENABLED=true`), the cache-key derivation in `api/src/utils/get-cache-key.ts` includes only `ve...
npm
No PRs yet
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
GHSA-j5h6-vqc3-phqh CVE-2026-61835 HIGH 8 days ago
### Summary
The SSRF protection on Directus's file-import-from-URL feature can be bypassed using the address `0.0.0.0`. While `127.0.0.1` and othe...
npm
No PRs yet
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
GHSA-f4vv-55c2-5789 CVE-2026-61740 CRITICAL 8 days ago
## Summary
When LightRAG is deployed with `LIGHTRAG_API_KEY` set but `AUTH_ACCOUNTS` unset (an officially documented "API-Key authentication" mode...
pypi
No PRs yet
Guzzle: Proxy-Authorization headers can be sent to origin servers
GHSA-94pj-82f3-465w MODERATE 8 days ago
### Impact
In affected versions, the built-in cURL handlers (`CurlHandler` and `CurlMultiHandler`) put every first-class request header in cURL's ...
packagist
No PRs yet
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
GHSA-6x6h-qqr7-855w CVE-2026-61736 CRITICAL 8 days ago
### Summary
The server defaults to CORS_ORIGINS=* combined with allow_credentials=True. Starlette's CORSMiddleware echoes the requesting origin in ...
pypi
No PRs yet