Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-77063
multer vulnerable to file size limit bypass via async fileFilter race condition
GHSA-2x7j-588g-ccc2
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
CVE-2026-82333
multer vulnerable to Denial of Service via oversized array index in field names
CVE-2026-77037
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
GHSA-2q42-4q24-7rgv
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
CVE-2026-76845
adm-zip extraction follows destination symlinks, allowing arbitrary file overwrite
CVE-2026-84375
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
GHSA-26w7-cxv4-gfx2
Astro: Remote code execution through AVIF image optimization
GHSA-rgj7-g3m4-5g8c
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
CVE-2026-84369
SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements
CVE-2026-84364
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
CVE-2026-84370
SVGO: removeScripts allows executable links through namespace and control-character bypasses
CVE-2026-84376
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
GHSA-2xp9-vwfh-vxw4
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
GHSA-j95f-988m-3j2f
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
CVE-2026-84365
Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
CVE-2026-84363
Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
GHSA-8m3c-c648-2xjj
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
CVE-2026-83613
xmldom: Quadratic-time attribute deduplication
CVE-2026-83619
xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser
CVE-2026-83618
xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator
CVE-2026-83616
xmldom: Processing Instruction Target Injection Bypasses requireWellFormed
CVE-2026-83617
xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator
CVE-2026-83615
xmldom: Quadratic-memory consumption
CVE-2026-83614
xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
CVE-2026-84368
joi: Prototype pollution via a `__proto__` language key in custom messages
CVE-2026-83612
xmldom: HTML raw-text closing-tag case mismatch causes output amplification
CVE-2026-83611
xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content
CVE-2026-83609
xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path
CVE-2026-83608
xmldom: DocType `name` Injection Bypasses requireWellFormed
CVE-2026-45819
baseline-browser-mapping process termination on invalid input causes denial of service
CVE-2026-19693
extract-zip allows arbitrary file writes through symlink archive entries
CVE-2026-84373
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
CVE-2026-85062
Colord: Slow rejection of oversized malformed color strings
CVE-2026-75604
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
CVE-2026-85061
MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip
CVE-2026-84367
joi: object().rename() with a template target can set the validated object's prototype
CVE-2026-83607
xmldom: Element name injection via createElement() bypasses requireWellFormed
CVE-2026-83605
xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed
CVE-2026-83606
xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions
CVE-2026-72925
SWC HTML minifier may allow script element breakout when minifying embedded JSON
CVE-2026-69222
LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process
CVE-2026-85063
node-csv: Prototype replacement still reachable via columns path
CVE-2026-12208
jsonata: Function Binding Prototype Pollution via hasOwnProperty Override
CVE-2026-67321
Axios form serializer maxDepth bypass via {} metatoken
GHSA-3mcp-22mf-vrw3
Duplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken
CVE-2025-59057
React Router has XSS Vulnerability
CVE-2026-33244
React Router has stored XSS via unescaped Location header in prerendered redirect HTML
CVE-2026-21884
React Router SSR XSS in ScrollRestoration
CVE-2026-8769
@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
CVE-2026-53668
React Router: Open redirect leading to XSS
CVE-2026-56812
Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
GHSA-7q9c-hpx7-9cwm
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
CVE-2026-54527
jupyterlab-git extension: Stored XSS leading to RCE
CVE-2026-16629
danger allows local OS command injection through crafted file paths
CVE-2026-11779
Payload CMS default account-unlock access allows authenticated users to reset other accounts' lockouts
CVE-2026-75912
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
CVE-2026-75856
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
CVE-2026-75911
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
CVE-2026-75859
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
Ready to move
Start Securing
Free, no credit card | First findings in minutes