Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2210071
AlmaLinux
5931
Alpaquita
16087
Alpine
4608
Android
3677
Azure Linux
17651
BellSoft Hardened Containers
754
Bitnami
9325
Chainguard
1030749
CleanStart
3846
CRAN
14
crates.io
2738
Debian
68472
Echo
7444
GHC
3
GIT
108258
GitHub Actions
55
Go
9245
Hackage
33
Hex
364
Julia
1713
Linux
29974
Mageia
6232
Maven
7044
MinimOS
144672
npm
228850
NuGet
1869
opam
29
openEuler
8800
openSUSE
14480
OSS-Fuzz
4013
Packagist
7098
Pub
11
PyPI
25181
Red Hat
23387
Rocky Linux
4305
Root
19583
RubyGems
5326
SUSE
23350
SwiftURL
60
TuxCare
9606
Ubuntu
65406
VSCode
21
Wolfi
289807
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-rcw4-f5rp-g42v
npm/adm-zip
adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
1 hour ago
Fix available
Severity - 7.5 (High)
GHSA-j5f4-cc29-5x44
npm/adm-zip
adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
1 hour ago
Fix available
Severity - 7.1 (High)
GHSA-8vvx-rff5-p5rq
npm/nodemailer
Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
1 hour ago
Fix available
Severity - 5.9 (Medium)
GHSA-pmjh-fq2x-6v4x
npm/undici
undici vulnerable to Denial of Service via orphaned RetryHandler response body
1 hour ago
Fix available
Severity - 5.9 (Medium)
GHSA-r53p-7pc4-xj5r
npm/undici
undici vulnerable to downstream response splitting via retry interceptor
1 hour ago
Fix available
Severity - 3.7 (Low)
GHSA-rfgv-xxqx-mfg5
npm/undici
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
1 hour ago
Fix available
Severity - 7.5 (High)
GHSA-3xpg-4rpp-hhhm
npm/undici
undici vulnerable to Denial of Service via unbounded decompression of compressed responses
1 hour ago
Fix available
Severity - 5.9 (Medium)
GHSA-2jfj-6hjv-fm6j
npm/undici
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
1 hour ago
Fix available
Severity - 6.5 (Medium)
GHSA-2gqq-gqf2-x968
npm/undici
undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
1 hour ago
Fix available
Severity - 3.7 (Low)
GHSA-w293-vg96-wgc3
npm/undici
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
2 hours ago
Fix available
Severity - 7.4 (High)
GHSA-8436-99hf-9mmv
npm/undici
undici vulnerable to caching and replay of unsafe HTTP method responses
2 hours ago
Fix available
Severity - 3.7 (Low)
GHSA-vp8m-p9jh-q5pm
npm/undici
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
2 hours ago
Fix available
Severity - 7.4 (High)
GHSA-rx4f-c7p8-82vq
npm/undici
undici vulnerable to Denial of Service via WebSocketStream unclean close
2 hours ago
Fix available
Severity - 5.9 (Medium)
GHSA-6h2x-m376-mqjq
npm/joi
joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
2 hours ago
Fix available
Severity - 7.5 (High)
GHSA-vv43-5jgx-7qv8
npm/electron
Electron: Local race condition in Squirrel.Mac update installation on macOS
2 hours ago
Fix available
Severity - 6.7 (Medium)
GHSA-hq2x-r82h-9wj4
npm/electron
Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
2 hours ago
Fix available
Severity - 8.2 (High)
Load more...
npm - OSV