Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-57583
OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
GHSA-9wx3-p993-35vp
Duplicate Advisory: Axios: Nested axios option objects can consume polluted prototype values
CVE-2026-71849
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
CVE-2026-11525
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
CVE-2026-53663
React Router: Potential CSRF via PUT/PATCH/DELETE document requests
CVE-2026-48051
Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
CVE-2026-6733
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
CVE-2026-44459
Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
CVE-2026-44572
Next.js's Middleware / Proxy redirects can be cache-poisoned
CVE-2026-34166
LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter
CVE-2026-3449
@tootallnate/once vulnerable to Incorrect Control Flow Scoping
CVE-2025-48985
Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
CVE-2025-46653
Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content
CVE-2026-82562
qs array-limit bypass via bracket-key comma parsing
GO-2026-6093
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
CVE-2026-12590
body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement
CVE-2026-67334
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
GHSA-g7r4-m6w7-qqqr
esbuild allows arbitrary file read when running the development server on Windows
CVE-2026-49356
@babel/core: Arbitrary File Read via sourceMappingURL Comment
CVE-2026-42040
Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
CVE-2026-44582
Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting
CVE-2026-44489
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
GHSA-442j-39wm-28r2
Handlebars.js has a Property Access Validation Bypass in container.lookup
CVE-2026-2391
qs's arrayLimit bypass in comma parsing allows denial of service
CVE-2026-56764
Hono added timing comparison hardening in basicAuth and bearerAuth
CVE-2025-68458
webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior
CVE-2025-68157
webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence
CVE-2025-15284
qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion
CVE-2025-54798
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
CVE-2025-49005
Next.js has a Cache poisoning vulnerability due to omission of the Vary header
CVE-2025-43712
Withdrawn Advisory: JHipster allows privilege escalation via a modified authorities parameter
CVE-2025-7339
on-headers is vulnerable to http response header manipulation
CVE-2025-5889
brace-expansion Regular Expression Denial of Service vulnerability
CVE-2025-47279
undici Denial of Service attack via bad certificate data
CVE-2025-30351
Suspended Directus user can continue to use session token to access API
CVE-2024-21539
Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit
CVE-2024-9506
ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function
CVE-2024-38372
Undici vulnerable to data leak when using response.arrayBuffer()
CVE-2024-39919
@jmondi/url-to-png enables capture screenshot of localhost web services (unauthenticated pages)
CVE-2024-29181
@strapi/plugin-content-manager leaks data via relations via the Admin Panel
CVE-2024-24758
Undici proxy-authorization header not cleared on cross-origin redirect in fetch
CVE-2023-48711
google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability
CVE-2023-35931
Shescape potential environment variable exposure on Windows with CMD
CVE-2023-30857
Possible prototype pollution in metadata record, when using meta decorator
CVE-2024-28238
Session Token in URL in directus
GHSA-6475-r3vj-m8vf
AWS SDK for JavaScript v3 adopted defense in depth enhancement for region parameter value
CVE-2016-1000021
Duplicate Advisory: Node CLI Allows Arbitrary File Overwrite
CVE-2017-16137
Regular Expression Denial of Service in debug
CVE-2026-77063
multer vulnerable to file size limit bypass via async fileFilter race condition
CVE-2026-84368
joi: Prototype pollution via a `__proto__` language key in custom messages
CVE-2026-84367
joi: object().rename() with a template target can set the validated object's prototype
CVE-2026-73844
CKAN MCP Server: Information disclosure via verbose error reflection
GHSA-chqm-wxm2-w73w
Duplicate Advisory: OpenClaw: Mattermost handlers could fall open when channel type was missing
CVE-2026-53837
OpenClaw: Mattermost handlers could fall open when channel type was missing
CVE-2026-2366
Keycloak vulnerable to authorization bypass via the Admin API
CVE-2024-6533
Directus has a DOM-Based cross-site scripting (XSS) via layout_options
CVE-2026-73425
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
CVE-2026-70600
Electron: Cross-origin iframe can position native autofill popup
CVE-2026-70598
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
CVE-2026-53607
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
Ready to move
Start Securing
Free, no credit card | First findings in minutes