Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

LOW 3.3
npm

CVE-2026-57583

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

LOW 3.7
npm

GHSA-9wx3-p993-35vp

Duplicate Advisory: Axios: Nested axios option objects can consume polluted prototype values

LOW 3.7
npm

CVE-2026-71849

Hono: Proxy Helper does not remove response headers listed in the `Connection` header

LOW 3.7
npm

CVE-2026-11525

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

LOW 3.1
npm

CVE-2026-53663

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

LOW 3.5
npm

CVE-2026-48051

Papra HTTP redirect bypass can lead to SSRF via webhook delivery system

LOW 3.7
npm

CVE-2026-6733

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

LOW 3.8
npm

CVE-2026-44459

Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()

LOW 3.7
npm

CVE-2026-44572

Next.js's Middleware / Proxy redirects can be cache-poisoned

LOW 3.7
npm

CVE-2026-34166

LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter

LOW 3.3
npm

CVE-2026-3449

@tootallnate/once vulnerable to Incorrect Control Flow Scoping

LOW 3.7
npm

CVE-2025-48985

Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files

LOW 3.1
npm

CVE-2025-46653

Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content

LOW 3.7
npm

CVE-2026-82562

qs array-limit bypass via bracket-key comma parsing

LOW 3.3
npm

GO-2026-6093

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion

LOW 3.7
npm

CVE-2026-12590

body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement

LOW 3.8
npm

CVE-2026-67334

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

LOW 2.5
npm

GHSA-g7r4-m6w7-qqqr

esbuild allows arbitrary file read when running the development server on Windows

LOW 3.2
npm

CVE-2026-49356

@babel/core: Arbitrary File Read via sourceMappingURL Comment

LOW 3.7
npm

CVE-2026-42040

Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams

LOW 3.7
npm

CVE-2026-44582

Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting

LOW 3.7
npm

CVE-2026-44489

Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix

LOW 3.7
npm

GHSA-442j-39wm-28r2

Handlebars.js has a Property Access Validation Bypass in container.lookup

LOW 3.7
npm

CVE-2026-2391

qs's arrayLimit bypass in comma parsing allows denial of service

LOW 3.7
npm

CVE-2026-56764

Hono added timing comparison hardening in basicAuth and bearerAuth

LOW 3.7
npm

CVE-2025-68458

webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior

LOW 3.7
npm

CVE-2025-68157

webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence

LOW 3.7
npm

CVE-2025-15284

qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion

LOW 2.5
npm

CVE-2025-54798

tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter

LOW 3.7
npm

CVE-2025-49005

Next.js has a Cache poisoning vulnerability due to omission of the Vary header

LOW 2.9
npm

CVE-2025-43712

Withdrawn Advisory: JHipster allows privilege escalation via a modified authorities parameter

LOW 3.4
npm

CVE-2025-7339

on-headers is vulnerable to http response header manipulation

LOW 3.1
npm

CVE-2025-5889

brace-expansion Regular Expression Denial of Service vulnerability

LOW 3.1
npm

CVE-2025-47279

undici Denial of Service attack via bad certificate data

LOW 3.5
npm

CVE-2025-30351

Suspended Directus user can continue to use session token to access API

LOW 3.5
npm

CVE-2024-21539

Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit

LOW 3.7
npm

CVE-2024-9506

ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function

LOW 2.0
npm

CVE-2024-38372

Undici vulnerable to data leak when using response.arrayBuffer()

LOW 3.7
npm

CVE-2024-39919

@jmondi/url-to-png enables capture screenshot of localhost web services (unauthenticated pages)

LOW 2.3
npm

CVE-2024-29181

@strapi/plugin-content-manager leaks data via relations via the Admin Panel

LOW 3.9
npm

CVE-2024-24758

Undici proxy-authorization header not cleared on cross-origin redirect in fetch

LOW 3.7
npm

CVE-2023-48711

google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability

LOW 3.1
npm

CVE-2023-35931

Shescape potential environment variable exposure on Windows with CMD

LOW 3.7
npm

CVE-2023-30857

Possible prototype pollution in metadata record, when using meta decorator

LOW 2.3
npm

CVE-2024-28238

Session Token in URL in directus

LOW 3.7
npm

GHSA-6475-r3vj-m8vf

AWS SDK for JavaScript v3 adopted defense in depth enhancement for region parameter value

LOW 3.5
npm

CVE-2016-1000021

Duplicate Advisory: Node CLI Allows Arbitrary File Overwrite

LOW 3.7
npm

CVE-2017-16137

Regular Expression Denial of Service in debug

LOW 3.7
npm

CVE-2026-77063

multer vulnerable to file size limit bypass via async fileFilter race condition

LOW 3.7
npm

CVE-2026-84368

joi: Prototype pollution via a `__proto__` language key in custom messages

LOW 3.7
npm

CVE-2026-84367

joi: object().rename() with a template target can set the validated object's prototype

LOW 3.7
npm

CVE-2026-73844

CKAN MCP Server: Information disclosure via verbose error reflection

LOW 3.7
npm

GHSA-chqm-wxm2-w73w

Duplicate Advisory: OpenClaw: Mattermost handlers could fall open when channel type was missing

LOW 3.7
npm

CVE-2026-53837

OpenClaw: Mattermost handlers could fall open when channel type was missing

LOW 3.1
npm

CVE-2026-2366

Keycloak vulnerable to authorization bypass via the Admin API

LOW 3.4
npm

CVE-2024-6533

Directus has a DOM-Based cross-site scripting (XSS) via layout_options

LOW 3.7
npm

CVE-2026-73425

@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped

LOW 3.1
npm

CVE-2026-70600

Electron: Cross-origin iframe can position native autofill popup

LOW 3.9
npm

CVE-2026-70598

Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size

LOW 3.7
npm

CVE-2026-53607

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header

Ready to move

Start Securing

Free, no credit card | First findings in minutes