Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

33,931 vulnerabilities

LOW 3.7
npm

CVE-2026-77063

multer vulnerable to file size limit bypass via async fileFilter race condition

HIGH 7.5
npm

GHSA-2x7j-588g-ccc2

Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list

HIGH 7.5
npm

CVE-2026-82333

multer vulnerable to Denial of Service via oversized array index in field names

HIGH 7.5
npm

CVE-2026-77037

multer vulnerable to Denial of Service via file descriptor leak on aborted uploads

HIGH 7.1
npm

GHSA-2q42-4q24-7rgv

OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree

MEDIUM 6.5
npm

CVE-2026-76845

adm-zip extraction follows destination symlinks, allowing arbitrary file overwrite

HIGH 7.5
npm

CVE-2026-84375

js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources

CRITICAL 9.8
npm

GHSA-26w7-cxv4-gfx2

Astro: Remote code execution through AVIF image optimization

UNKNOWN
npm

GHSA-rgj7-g3m4-5g8c

sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545

MEDIUM 6.1
npm

CVE-2026-84369

SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements

MEDIUM 5.3
npm

CVE-2026-84364

Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion

HIGH 8.2
npm

CVE-2026-84370

SVGO: removeScripts allows executable links through namespace and control-character bypasses

UNKNOWN
npm

CVE-2026-84376

Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base

UNKNOWN
npm

GHSA-2xp9-vwfh-vxw4

Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

UNKNOWN
npm

GHSA-j95f-988m-3j2f

Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing

MEDIUM 6.5
npm

CVE-2026-84365

Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory

MEDIUM 5.9
npm

CVE-2026-84363

Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

MEDIUM 5.9
npm

GHSA-8m3c-c648-2xjj

Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature

UNKNOWN
npm

CVE-2026-83613

xmldom: Quadratic-time attribute deduplication

UNKNOWN
npm

CVE-2026-83619

xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser

UNKNOWN
npm

CVE-2026-83618

xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator

UNKNOWN
npm

CVE-2026-83616

xmldom: Processing Instruction Target Injection Bypasses requireWellFormed

UNKNOWN
npm

CVE-2026-83617

xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator

UNKNOWN
npm

CVE-2026-83615

xmldom: Quadratic-memory consumption

UNKNOWN
npm

CVE-2026-83614

xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge

LOW 3.7
npm

CVE-2026-84368

joi: Prototype pollution via a `__proto__` language key in custom messages

UNKNOWN
npm

CVE-2026-83612

xmldom: HTML raw-text closing-tag case mismatch causes output amplification

UNKNOWN
npm

CVE-2026-83611

xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content

UNKNOWN
npm

CVE-2026-83609

xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path

UNKNOWN
npm

CVE-2026-83608

xmldom: DocType `name` Injection Bypasses requireWellFormed

UNKNOWN
npm

CVE-2026-45819

baseline-browser-mapping process termination on invalid input causes denial of service

HIGH 8.1
npm

CVE-2026-19693

extract-zip allows arbitrary file writes through symlink archive entries

MEDIUM 5.9
npm

CVE-2026-84373

Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock

UNKNOWN
npm

CVE-2026-85062

Colord: Slow rejection of oversized malformed color strings

CRITICAL 9.0
npm

CVE-2026-75604

Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

CRITICAL 10.0
npm

CVE-2026-85061

MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip

LOW 3.7
npm

CVE-2026-84367

joi: object().rename() with a template target can set the validated object's prototype

UNKNOWN
npm

CVE-2026-83607

xmldom: Element name injection via createElement() bypasses requireWellFormed

UNKNOWN
npm

CVE-2026-83605

xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed

UNKNOWN
npm

CVE-2026-83606

xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions

MEDIUM 6.1
npm

CVE-2026-72925

SWC HTML minifier may allow script element breakout when minifying embedded JSON

HIGH 7.5
npm

CVE-2026-69222

LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process

UNKNOWN
npm

CVE-2026-85063

node-csv: Prototype replacement still reachable via columns path

MEDIUM 5.3
npm

CVE-2026-12208

jsonata: Function Binding Prototype Pollution via hasOwnProperty Override

UNKNOWN
npm

CVE-2026-67321

Axios form serializer maxDepth bypass via {} metatoken

HIGH 7.5
npm

GHSA-3mcp-22mf-vrw3

Duplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken

HIGH 7.6
npm

CVE-2025-59057

React Router has XSS Vulnerability

MEDIUM 5.4
npm

CVE-2026-33244

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

HIGH 8.2
npm

CVE-2026-21884

React Router SSR XSS in ScrollRestoration

MEDIUM 4.3
npm

CVE-2026-8769

@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue

MEDIUM 6.9
npm

CVE-2026-53668

React Router: Open redirect leading to XSS

UNKNOWN
Hex

CVE-2026-56812

Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff

HIGH 7.5
npm

GHSA-7q9c-hpx7-9cwm

TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop

CRITICAL 9.0
PyPI

CVE-2026-54527

jupyterlab-git extension: Stored XSS leading to RCE

MEDIUM 5.3
npm

CVE-2026-16629

danger allows local OS command injection through crafted file paths

UNKNOWN
npm

CVE-2026-11779

Payload CMS default account-unlock access allows authenticated users to reset other accounts' lockouts

HIGH 7.4
crates.io

CVE-2026-75912

CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval

HIGH 8.6
crates.io

CVE-2026-75856

CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning

HIGH 7.8
crates.io

CVE-2026-75911

CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository

HIGH 7.5
crates.io

CVE-2026-75859

CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository

Ready to move

Start Securing

Free, no credit card | First findings in minutes