Security Advisories
Browse security advisories and track which Dependabot PRs address them.
35,046
Total Advisories
3,109
With Dependabot PRs
4,560
Critical Severity
12,276
High Severity
n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
GHSA-6qc9-mqvw-jg7x HIGH 6 days ago
## Impact
An authenticated member with edit access to a shared workflow could reference another user's credential in an HTTP Request node while sp...
npm
No PRs yet
n8n: Expression sandbox escape via arrow-function bodies enabling command execution
GHSA-gv7g-jm28-cr3m HIGH 6 days ago
## Impact
An authenticated user with permission to create or modify workflows could abuse crafted expressions using arrow functions to bypass the ...
npm
No PRs yet
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
GHSA-2x35-3fw4-9jr4 HIGH 6 days ago
## Impact
The n8n Send Email node did not enforce that its message fields were strings, so a crafted untrusted non-string value from a workflow ex...
npm
No PRs yet
n8n: Authenticated code execution in the n8n Git node
GHSA-rcv6-pvrj-4xcg HIGH 6 days ago
## Impact
Authenticated n8n users with rights to create and execute workflows could achieve code execution on the n8n host. Using the Git node, un...
npm
No PRs yet
n8n: SSRF Protection Bypass via MCP Client Node
GHSA-vhf8-cg2h-cg3p MODERATE 6 days ago
## Impact
On an n8n instance with SSRF protection enabled, the MCP Client node sent requests to a user-supplied endpoint without routing them thro...
npm
No PRs yet
n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
GHSA-gf29-4f56-r2jf HIGH 6 days ago
## Impact
Authenticated n8n users with workflow create/execute rights could use the Git node's fetch, pull, or push-tags operations to bypass the ...
npm
No PRs yet
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
GHSA-64xh-79j6-r5v8 HIGH 6 days ago
## Impact
The credential "Allowed HTTP Request Domains" allowlist was intended to restrict which hosts a credential's secret could be sent to, pro...
npm
No PRs yet
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
GHSA-8342-988q-86cr HIGH 6 days ago
## Impact
In an n8n instance, when a validly-signed incoming token was matched to a local account by its email claim, the service did not check th...
npm
No PRs yet
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
GHSA-35q8-9mj6-wjmf CVE-2026-65016 HIGH 6 days ago
## Impact
n8n's Enterprise SSO instance-role provisioning maps a role claim asserted by the configured Identity Provider (IdP) to an n8n global rol...
npm
No PRs yet
n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
GHSA-pm35-fqvh-cq5g CVE-2026-65591 HIGH 6 days ago
## Impact
The legacy expression evaluator's computed-member sanitizer can be bypassed by an authenticated user with workflow create or modify permi...
npm
No PRs yet
n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
GHSA-9w78-79q7-r4fp CVE-2026-65593 MODERATE 6 days ago
## Impact
Endpoints in `/rest/dynamic-node-parameters/` lacked authorization scopes, making it reachable by any authenticated user with no workflo...
npm
No PRs yet
n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
GHSA-777w-rpr6-c52h CVE-2026-65595 HIGH 6 days ago
## Impact
JWTs issued through the Token Exchange module were assigned all Public API key scopes, regardless of the acting user's actual role. A lo...
npm
No PRs yet
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
GHSA-mq3m-f8x3-579w CVE-2026-59208 HIGH 6 days ago
## Impact
When an n8n instance is configured with more than one trusted token-exchange issuer, external identities are resolved to local accounts u...
npm
No PRs yet
n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
GHSA-h44j-f5r5-ph73 CVE-2026-59207 HIGH 6 days ago
## Impact
The AI Agents feature did not enforce the "Allowed HTTP Request Domains" restriction configured on credentials. As a result, a member-lev...
npm
No PRs yet
n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
GHSA-75qm-gp28-rcq9 CVE-2026-59206 HIGH 6 days ago
## Impact
An authenticated user with the default `workflow:create` permission could pollute `Object.prototype` through a crafted workflow saved, up...
npm
No PRs yet
n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
GHSA-q3j5-8vrg-4p9q CVE-2026-59209 HIGH 6 days ago
## Impact
An authenticated member with use-only editor access to a shared workflow could read credential-populated headers exposed via the `$reques...
npm
No PRs yet
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
GHSA-gcjf-9mgh-3p7g CVE-2026-59921 MODERATE 6 days ago
# Security Vulnerability Report: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
## 1. Vulnerability Summary
| Field | Valu...
maven
No PRs yet
Netty: STOMP CONNECT Frame Header Injection in Netty
GHSA-3g8r-4pfx-jmfh CVE-2026-59920 MODERATE 6 days ago
# Security Vulnerability Report: STOMP CONNECT Frame Header Injection in Netty
## 1. Vulnerability Summary
| Field | Value |
|-------|-------|
| ...
maven
No PRs yet
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
GHSA-wh89-7897-x99h CVE-2026-59919 MODERATE 6 days ago
# Security Vulnerability Report: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address in Netty
## 1. Vulnerability Summary
| Field | Value |
|-...
maven
No PRs yet
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
GHSA-558v-64gr-wgg4 CVE-2026-59901 HIGH 6 days ago
The `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that ...
maven
No PRs yet
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
GHSA-c69g-56f8-xwqj CVE-2026-59900 MODERATE 6 days ago
Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate...
maven
No PRs yet
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
GHSA-q4f6-jm68-57ww CVE-2026-59899 MODERATE 6 days ago
### Impact
`HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence...
maven
No PRs yet
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
GHSA-4mp9-239f-g9hg CVE-2026-59898 MODERATE 6 days ago
## Summary
An attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connecti...
maven
No PRs yet
Netty: TOCTOU in OcspServerCertificateValidator
GHSA-wc96-39fc-566f CVE-2026-56822 HIGH 6 days ago
### Summary
Netty's OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This...
maven
No PRs yet
Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
GHSA-g7hg-vrcf-mvmr CVE-2026-56821 HIGH 6 days ago
### Summary
`OcspServerCertificateValidator` flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is sti...
maven
No PRs yet
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
GHSA-272m-gcwp-mpwg CVE-2026-56820 HIGH 6 days ago
### Summary
Netty's OcspClient does not validate that the CertificateID in an OCSP response matches the requested CertificateID. A bad actor can re...
maven
No PRs yet
Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling
GHSA-4qhr-g3c6-fcfx CVE-2026-56817 HIGH 6 days ago
Any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a DOCTYPE declaration to a parser instantia...
maven
No PRs yet
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
GHSA-hpcc-26xq-25fv CVE-2026-56816 HIGH 6 days ago
### Summary
Netty's Http3FrameCodec buffers incoming data for HTTP/3 reserved frame types up to the specified payload length without any limits. Th...
maven
No PRs yet
Netty: Security Control Bypass via CORS Short-Circuit Failure
GHSA-6cqp-g7gg-8hr5 CVE-2026-56746 MODERATE 6 days ago
### Summary
Netty's CorsHandler provides a `shortCircuit()` configuration designed to reject unauthorized cross-origin requests immediately, acting...
maven
No PRs yet
Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
GHSA-jppx-w49h-x2qq CVE-2026-56745 HIGH 6 days ago
The `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with...
maven
No PRs yet
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
GHSA-cx96-42px-69fm CVE-2026-56722 MODERATE 6 days ago
**Description:** An attacker, who controls the HTML input supplied to dompdf, can read arbitrary images from the server’s file system, bypassing th...
packagist
No PRs yet
Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
GHSA-q6cq-mhr2-jmr5 CVE-2026-55851 HIGH 6 days ago
The `HAProxyMessageDecoder` in netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte of the inbound stream as...
maven
No PRs yet
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
GHSA-mvh2-crg5-v77c CVE-2026-55833 HIGH 6 days ago
### Summary
Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has already exceeded maxHeader...
maven
No PRs yet
Netty SPDY SETTINGS frame count materializes unbounded settings map
GHSA-6jqx-86gh-f27w CVE-2026-55831 HIGH 6 days ago
### Summary
Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every u...
maven
No PRs yet
Dompdf: File existence oracle via font-face stylesheet declaration
GHSA-7x2p-4jvh-6384 CVE-2026-55555 LOW 6 days ago
## Description
Dompdf is vulnerable to a **File Existence Oracle** attack through the manipulation of the CSS `@font-face` directive. By providing...
packagist
No PRs yet
Dompdf: Chroot Validation Bypass
GHSA-wvh6-f5jh-8gw4 CVE-2026-55554 LOW 6 days ago
### Summary
The chroot check for local files uses a prefix string check to enforce chroot boundaries. The simple string comparison it performs allo...
packagist
No PRs yet
n8n: Google Service Account Private Key Exposed in JWT Header
GHSA-9r8p-h6cc-6qhm CVE-2026-65599 MODERATE 6 days ago
## Impact
When n8n was configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header's `kid` field...
npm
No PRs yet
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
GHSA-9wcp-9r3j-383q CVE-2026-65592 HIGH 6 days ago
## Impact
The Resource Locator passes the workflow-persisted `cachedResultUrl` to `window.open()` without scheme validation. When a victim opens th...
npm
No PRs yet
n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
GHSA-p3rg-hrf9-w9gj CVE-2026-65597 HIGH 6 days ago
## Impact
The HTML preview renders execution output into an `iframe srcdoc` without `sandbox`, so a sanitizer bypass lets injected script run same...
npm
No PRs yet
n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
GHSA-g3r5-9h93-4j2c CVE-2026-65598 HIGH 6 days ago
## Impact
A TOCTOU race condition in the Git node's `clone` operation lets an authenticated user bypass its path restrictions by swapping a directo...
npm
No PRs yet
n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
GHSA-x5vx-c2c8-m3w9 CVE-2026-65015 HIGH 6 days ago
## Impact
In n8n's AI Agents feature, a user with the read-only Project Viewer role could escalate their privileges by chatting with an agent that ...
npm
No PRs yet
fast-uri vulnerable to host confusion via literal backslash authority delimiter
GHSA-v2hh-gcrm-f6hx CVE-2026-16221 HIGH 7 days ago
### Impact
`fast-uri` v4.1.0 and earlier do not treat a literal backslash (U+005C) as an authority delimiter. Node's native WHATWG `URL` (used by ...
npm
28
Dependabot PRs
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
GHSA-f88m-g3jw-g9cj HIGH 7 days ago
### Impact
A number of vulnerabilities, two rated as "High" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependen...
npm
1
Dependabot PRs
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
GHSA-8r6m-32jq-jx6q HIGH 7 days ago
### Impact
`fast-xml-parser` processes multiple "DOCTYPE" declarations within a single XML document. Each declaration passes its entities to `@noda...
npm
No PRs yet
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GHSA-rwj8-pgh3-r573 HIGH 7 days ago
### Summary
`Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path...
pypi
6
Dependabot PRs
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
GHSA-cj75-f6xr-r4g7 MODERATE 7 days ago
## Summary
There is a possible cross-site scripting vulnerability in rails-html-sanitizer when the sanitizer is configured to allow an SVG referen...
rubygems
No PRs yet
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
GHSA-9mqv-5hh9-4cgg MODERATE 7 days ago
## Summary
A WebSocket upgrade request to an `upgradeWebSocket` route with a missing or malformed `Sec-WebSocket-Key` header leaks memory permanen...
npm
2
Dependabot PRs
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
GHSA-hrxh-6v49-42gf HIGH 7 days ago
Multiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and...
go
No PRs yet
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
GHSA-5qhf-9phg-95m2 LOW 7 days ago
## Summary
`Loofah::HTML5::Scrub.allowed_uri?` does not correctly reject `javascript:` or `vbscript:` URIs when the scheme is split by a numeric c...
rubygems
No PRs yet
Loofah: SVG `href` attribute bypasses local-reference restriction
GHSA-9wjq-cp2p-hrgf MODERATE 7 days ago
## Summary
Loofah's HTML5 sanitizer restricted only the `xlink:href` attribute on certain SVG elements to local, same-document references. Browser...
rubygems
No PRs yet