GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,343
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,550
Pub
12
RubyGems
1,013
Rust
1,203
Swift
51
Unreviewed advisories
All unreviewed
5,000+
532 advisories
Filter by severity
MikroORM has Prototype Pollution in Utils.merge
High
CVE-2026-34221
was published
for
@mikro-orm/core
(npm)
Mar 29, 2026
Handlebars.js has a Prototype Method Access Control Gap via Missing __lookupSetter__ Blocklist Entry
Moderate
GHSA-7rx3-28cr-v5wh
was published
for
handlebars
(npm)
Mar 29, 2026
Locutus Prototype Pollution due to incomplete fix for CVE-2026-25521
Moderate
CVE-2026-33994
was published
for
locutus
(npm)
Mar 27, 2026
Locutus has Prototype Pollution via __proto__ Key Injection in unserialize()
Moderate
CVE-2026-33993
was published
for
locutus
(npm)
Mar 27, 2026
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
Moderate
CVE-2026-33916
was published
for
handlebars
(npm)
Mar 26, 2026
Convict has Prototype Pollution via startsWith() function
Critical
CVE-2026-33864
was published
for
convict
(npm)
Mar 26, 2026
Convict has prototype pollution via load(), loadFile(), and schema initialization
Critical
CVE-2026-33863
was published
for
convict
(npm)
Mar 26, 2026
n8n: Prototype Pollution in XML and GSuiteAdmin node parameters lead to RCE
Critical
CVE-2026-33696
was published
for
n8n
(npm)
Mar 26, 2026
Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
Moderate
CVE-2026-33672
was published
for
picomatch
(npm)
Mar 25, 2026
Prototype Pollution via parse() in NodeJS flatted
High
CVE-2026-33228
was published
for
flatted
(npm)
Mar 19, 2026
Parse Server vulnerable to schema poisoning via prototype pollution in deep copy
Moderate
CVE-2026-32878
was published
for
parse-server
(npm)
Mar 17, 2026
Parse Server's Cloud function dispatch crashes server via prototype chain traversal
High
CVE-2026-32886
was published
for
parse-server
(npm)
Mar 17, 2026
Elysia Cookie Value Prototype Pollution
Moderate
CVE-2026-31865
was published
for
elysia
(npm)
Mar 17, 2026
Apollo Federation vulnerable to prototype pollution via incomplete key sanitization
Critical
CVE-2026-32621
was published
for
@apollo/federation-internals
(npm)
Mar 13, 2026
Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own properties
Low
GHSA-mwv9-gp5h-frr4
was published
for
devalue
(npm)
Mar 12, 2026
devalue has prototype pollution in devalue.parse and devalue.unflatten
Moderate
CVE-2026-30226
was published
for
devalue
(npm)
Mar 12, 2026
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
Moderate
GHSA-v8w9-8mx6-g223
was published
for
hono
(npm)
Mar 11, 2026
Parse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain Resolution
High
CVE-2026-30939
was published
for
parse-server
(npm)
Mar 10, 2026
Immutable is vulnerable to Prototype Pollution
High
CVE-2026-29063
was published
for
immutable
(npm)
Mar 4, 2026
OpenClaw's runtime /debug override path accepted prototype-reserved keys
Low
CVE-2026-27524
was published
for
openclaw
(npm)
Mar 3, 2026
`@orpc/client` has Prototype Pollution via `StandardRPCJsonSerializer` Deserialization
Critical
CVE-2026-28794
was published
for
@orpc/client
(npm)
Mar 2, 2026
dottie is vulnerable to Prototype Pollution bypass via non-first path segments in set() and transform()
Moderate
CVE-2026-27837
was published
for
dottie
(npm)
Feb 26, 2026
devalue `uneval`ed code can create objects with polluted prototypes when `eval`ed
Low
GHSA-8qm3-746x-r74r
was published
for
devalue
(npm)
Feb 19, 2026
A State Pollution vulnerability was discovered in the TON Virtual Machine (TVM) before v2025.04....
High
Unreviewed
CVE-2025-70956
was published
Feb 14, 2026
ProTip!
Advisories are also available from the
GraphQL API