An open index of dependabot pull requests across open source projects.

Security Advisories

Browse security advisories and track which Dependabot PRs address them.

35,046

Total Advisories

3,110

With Dependabot PRs

4,560

Critical Severity

12,276

High Severity

body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
GHSA-v422-hmwv-36x6 CVE-2026-12590 LOW 8 days ago
### Impact When body-parser is configured with an invalid `limit` option value, such as an unparseable string or `NaN`, `bytes.parse()` returns `n...
npm
21
Dependabot PRs
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
GHSA-r557-wffq-wvrc CVE-2026-59730 LOW 8 days ago
### Impact With `trailingSlash: 'always'` configured, the `@astrojs/node` standalone server's static file handler appends a trailing slash to requ...
npm
No PRs yet
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
GHSA-f48w-9m4c-m7f5 CVE-2026-59729 MODERATE 8 days ago
## Summary The fix for CVE-2026-54298 (GHSA-jrpj-wcv7-9fh9) added an `INVALID_ATTR_NAME_CHAR` guard to `addAttribute()` so that spread-prop attrib...
npm
No PRs yet
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
GHSA-8j5q-mfj2-5q9q CVE-2026-59728 MODERATE 8 days ago
## Summary In `@astrojs/rss`, the `source.title` and `enclosure.type` item fields are interpolated directly into XML template strings without XML-...
npm
No PRs yet
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
GHSA-7pw4-f3q4-r2p2 CVE-2026-59727 LOW 8 days ago
### Summary When a `transition:persist`, `transition:scope`, or `transition:persist-props` directive is applied to a client-hydrated (`client:*`) ...
npm
No PRs yet
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
GHSA-9hw9-ch79-4vh6 CVE-2026-59205 HIGH 8 days ago
### Summary Pillow's public `ImageCms.ImageCmsTransform.apply(im, imOut)` API can trigger controlled native heap corruption when the caller suppli...
pypi
No PRs yet
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
GHSA-vjc4-5qp5-m44j CVE-2026-59204 HIGH 8 days ago
### Summary `src/libImaging/Jpeg2KDecode.c:853` accumulates `total_component_width` across every tile in a JPEG2000 image instead of recomputing it...
pypi
No PRs yet
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
GHSA-pg7v-jwj7-p798 CVE-2026-59203 MODERATE 8 days ago
### Summary Pillow's EPS parser (PIL/EpsImagePlugin.py) accepts a negative byte count in the %%BeginBinary directive. A crafted EPS file can cause...
pypi
No PRs yet
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
GHSA-jjj6-mw9f-p565 CVE-2026-59200 HIGH 8 days ago
### Summary `PdfParser.PdfStream.decode()` in Pillow's `PdfParser.py` calls `zlib.decompress()` with the `bufsize` parameter set to the value of th...
pypi
No PRs yet
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
GHSA-6r8x-57c9-28j4 CVE-2026-59199 HIGH 8 days ago
### Summary Pillow's public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit inte...
pypi
No PRs yet
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
GHSA-fj7v-r99m-22gq CVE-2026-59198 MODERATE 8 days ago
### Summary Pillow's TGA RLE encoder reads past its row buffer when saving a mode `"1"` image. Adjacent process heap bytes can be copied into the ...
pypi
No PRs yet
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
GHSA-xj96-63gp-2gmr CVE-2026-59197 HIGH 8 days ago
### Summary Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size. Minimal public...
pypi
No PRs yet
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
GHSA-wp74-jgxh-gv4q CVE-2026-50651 HIGH 8 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET HTTP client (System.Net.Ht...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
GHSA-74jp-vm22-8q8x CVE-2026-50659 MODERATE 8 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SMTP client (System.Net.Ma...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
GHSA-8q5v-6pqq-x66h CVE-2026-50525 HIGH 8 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Sec...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
GHSA-qvw7-jm5c-6hqw CVE-2026-50528 HIGH 8 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Securi...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
GHSA-23rf-6693-g89p CVE-2026-50648 HIGH 8 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Sec...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
GHSA-w7cw-xp7h-6j5j CVE-2026-50524 HIGH 8 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Securi...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
GHSA-g8r8-53c2-pm3f CVE-2026-47304 HIGH 8 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Sec...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
GHSA-cvvh-rhrc-wg4q CVE-2026-47302 HIGH 8 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML processing (System.Sec...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
GHSA-rp2p-6cmp-jxj9 CVE-2026-57108 HIGH 8 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in the .NET runtime cryptography l...
nuget
No PRs yet
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
GHSA-gcfj-64vw-6mp9 HIGH 8 days ago
## Summary Axios’ Node.js HTTP adapter can route requests through an attacker-controlled proxy when `Object.prototype.proxy` is polluted and reque...
npm
No PRs yet
Axios form serializer maxDepth bypass via {} metatoken
GHSA-hcpx-6fm6-wx23 MODERATE 8 days ago
## Summary Axios versions in the fixed lines for GHSA-62hf-57xw-28j9 still contain an incomplete depth-limit bypass in `lib/helpers/toFormData.js`...
npm
No PRs yet
Axios: Nested axios option objects can consume polluted prototype values
GHSA-7q8q-rj6j-mhjq MODERATE 8 days ago
## Summary Axios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted `Object.pr...
npm
No PRs yet
Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
GHSA-mwf2-3pr3-8698 MODERATE 8 days ago
## Summary Axios versions with Node.js HTTP/2 support allow streamed request bodies to bypass `maxBodyLength` enforcement when requests are sent w...
npm
No PRs yet
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
GHSA-jqh4-m9w3-8hp9 MODERATE 8 days ago
## Summary axios’ fetch adapter does not enforce `maxBodyLength` for live WHATWG `ReadableStream` request bodies whose size cannot be determined b...
npm
No PRs yet
Axios: Prototype pollution gadgets can alter axios request construction
GHSA-mmx7-hfxf-jppx MODERATE 8 days ago
## Summary axios is vulnerable to read-side prototype-pollution gadgets when `Object.prototype` has already been polluted by another vulnerability...
npm
No PRs yet
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
GHSA-f4gw-2p7v-4548 MODERATE 8 days ago
## Summary Axios versions containing `lib/helpers/shouldBypassProxy.js` do not treat `0.0.0.0` as a local address when evaluating `NO_PROXY` rules...
npm
No PRs yet
File Browser: Colliding username normalization gives two users the same home directory
GHSA-7rc3-g7h6-22m7 CVE-2026-62685 HIGH 8 days ago
## Summary FileBrowser confines each user to a *scope*: a home directory that acts as the boundary for everything they can read or write. When sel...
go
No PRs yet
File Browser: Share API exposes the password hash and bypass token
GHSA-833g-cqhp-h72j CVE-2026-62684 LOW 8 days ago
## Summary When a user creates a password-protected share or lists existing shares, the JSON response includes the full bcrypt `password_hash` and...
go
No PRs yet
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
GHSA-83xp-526h-j3ww CVE-2026-62843 MODERATE 8 days ago
## Summary The fix for `GHSA-gxjx-7m74-hcq8` / `CVE-2026-54093` (shipped in v2.63.6) added a `strings.ReplaceAll(nameInArchive, "\\", "/")` step t...
go
No PRs yet
protobufjs: Text Format string map parsing can mutate returned map object prototype
GHSA-jfj6-75fj-8934 CVE-2026-59876 MODERATE 8 days ago
## Summary The protobuf.js text format extension parsed string-keyed map entries using ordinary property assignment. A text-format map entry with ...
npm
No PRs yet
protobufjs: Denial of Service via infinite loop in .proto option parsing
GHSA-j3f2-48v5-ccww CVE-2026-59877 MODERATE 8 days ago
## Summary protobufjs parsed option names by advancing through schema tokens until it reached an `=` token, without checking for end of input. A c...
npm
No PRs yet
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
GHSA-m28w-2pqf-7qgj CVE-2026-14631 MODERATE 8 days ago
### Impact An unauthenticated peer that can reach the `webpack-dev-server` process can terminate it by sending either a normal HTTP request with a...
npm
No PRs yet
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
GHSA-f5vj-f2hx-8m93 CVE-2026-14620 MODERATE 8 days ago
### Impact The internal `/webpack-dev-server/open-editor` and `/webpack-dev-server/invalidate` endpoints perform state-changing actions on any `GE...
npm
No PRs yet
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
GHSA-g446-98w2-8p5w CVE-2026-59883 MODERATE 8 days ago
### Impact `CookieJar` does not restrict a cookie scoped to an IP address to the exact host that set it. When a stored cookie's `Domain` attribute...
packagist
No PRs yet
Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
GHSA-vj59-8hwv-xxmv CVE-2026-59731 HIGH 8 days ago
# Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch ## Summary Astro 6.4.7 appears to reintr...
npm
No PRs yet
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
GHSA-gjfg-22fp-rrxx CVE-2026-59946 MODERATE 8 days ago
## Summary A Composer package declares its executables in the `bin` field of its `composer.json`. When Composer installs a package, it processes e...
packagist
No PRs yet
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)
GHSA-g6xq-892h-64w3 CVE-2026-59947 MODERATE 8 days ago
## Summary When Composer is run with -vvv (debug verbosity), it could print a credential that was embedded directly in a repository or package URL...
packagist
No PRs yet
node-tar: Process crash via PAX numeric path type confusion
GHSA-w8wr-v893-vjvp CVE-2026-59871 MODERATE 8 days ago
### Summary A crafted 2.5KB tar archive crashes any Node.js process that extracts it. The PAX header parser coerces all-digit path values to JavaS...
npm
No PRs yet
node-tar: Decompression/parse DoS via unlimited input
GHSA-23hp-3jrh-7fpw CVE-2026-59873 CRITICAL 8 days ago
### Summary A **Decompression/parse DoS via unlimited input** vulnerability in `node-tar` allows an attacker to exhaust server resources (disk spac...
npm
No PRs yet
node-tar: Negative tar entry size causes infinite loop in archive replace
GHSA-8x88-c5mf-7j5w CVE-2026-59874 HIGH 8 days ago
### Summary A checksum-valid tar archive with a negative base-256 encoded entry size can make `tar.replace()` loop forever while scanning the exis...
npm
No PRs yet
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
GHSA-gvwx-54wh-qm9j CVE-2026-59875 MODERATE 8 days ago
## Summary `node-tar` strips trailing `NUL` bytes from long-name (`L`) and long-linkpath (`K`) GNU extended headers but does **not** apply the sam...
npm
No PRs yet
Socket.IO: Engine.IO Polling Transport Connection Exhaustion
GHSA-r635-g3xr-vw7x CVE-2026-59725 HIGH 8 days ago
### Impact An unauthenticated remote attacker can cause a denial of service in affected versions of **engine.io** by opening Engine.IO polling ses...
npm
No PRs yet
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
GHSA-395f-4hp3-45gv CVE-2026-13311 HIGH 8 days ago
### Summary `shell-quote`'s `parse()` finalizes its token list with a `reduce` that uses `Array.prototype.concat` as the accumulator. Each `prev.co...
npm
27
Dependabot PRs
Directus: Authorization-dependent response served from unsegmented cache key
GHSA-c6w9-5g5j-jh2p CVE-2026-61836 HIGH 8 days ago
## Summary When response caching is enabled (`CACHE_ENABLED=true`), the cache-key derivation in `api/src/utils/get-cache-key.ts` includes only `ve...
npm
No PRs yet
Directus: SSRF Protection Bypass via 0.0.0.0 in File Import
GHSA-j5h6-vqc3-phqh CVE-2026-61835 HIGH 8 days ago
### Summary The SSRF protection on Directus's file-import-from-URL feature can be bypassed using the address `0.0.0.0`. While `127.0.0.1` and othe...
npm
No PRs yet
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
GHSA-f4vv-55c2-5789 CVE-2026-61740 CRITICAL 8 days ago
## Summary When LightRAG is deployed with `LIGHTRAG_API_KEY` set but `AUTH_ACCOUNTS` unset (an officially documented "API-Key authentication" mode...
pypi
No PRs yet
Guzzle: Proxy-Authorization headers can be sent to origin servers
GHSA-94pj-82f3-465w MODERATE 8 days ago
### Impact In affected versions, the built-in cURL handlers (`CurlHandler` and `CurlMultiHandler`) put every first-class request header in cURL's ...
packagist
No PRs yet
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
GHSA-6x6h-qqr7-855w CVE-2026-61736 CRITICAL 8 days ago
### Summary The server defaults to CORS_ORIGINS=* combined with allow_credentials=True. Starlette's CORSMiddleware echoes the requesting origin in ...
pypi
No PRs yet