Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 5.7
npm

CVE-2026-33060

SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks

MEDIUM 5.7
npm

CVE-2026-53509

@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)

MEDIUM 5.7
npm

CVE-2026-61612

@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509

MEDIUM 4.3
npm

CVE-2026-77425

Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log

MEDIUM 5.3
npm

CVE-2026-56682

9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header

MEDIUM 6.5
npm

CVE-2026-58270

Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`

MEDIUM 5.3
npm

CVE-2026-58272

Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)

MEDIUM 6.8
npm

CVE-2026-58271

@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`

MEDIUM 6.1
npm

CVE-2026-56326

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

MEDIUM 6.1
npm

CVE-2026-84992

md-editor-v3: XSS via fenced-code language rendering bypass

MEDIUM 5.3
npm

CVE-2026-92963

vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`

MEDIUM 6.1
npm

CVE-2026-88976

@platejs/core HTML deserialization can trigger browser behavior during parsing

MEDIUM 5.3
npm

CVE-2026-81176

Svelte devalue: DoS via malformed input

MEDIUM 5.0
npm

CVE-2026-54546

TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard

MEDIUM 4.4
npm

CVE-2026-63225

Redocly CLI: Path traversal when using `split` command

MEDIUM 5.3
npm

CVE-2026-63461

Vendure: Shop API list queries can return non-public entities when filterOperator is OR

MEDIUM 6.5
npm

CVE-2026-92597

Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain

MEDIUM 5.9
npm

CVE-2026-92595

Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature

MEDIUM 6.5
npm

CVE-2026-92598

Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

MEDIUM 4.7
npm

CVE-2026-68921

DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)

MEDIUM 5.4
npm

CVE-2026-81888

@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking

MEDIUM 6.5
npm

CVE-2026-59149

@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)

MEDIUM 4.0
npm

CVE-2026-88059

Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`

MEDIUM 6.2
npm

CVE-2026-71429

stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)

MEDIUM 5.3
npm

CVE-2026-82417

qs: Denial of Service via Attacker Controlled isBuffer

MEDIUM 5.9
npm

GHSA-rgwj-5xj2-c3m3

MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS

MEDIUM 4.8
npm

CVE-2026-16729

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

MEDIUM 4.2
npm

CVE-2026-15157

undici vulnerable to CRLF Injection via blob-like body 'type' property

MEDIUM 5.9
npm

CVE-2026-14643

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

MEDIUM 4.8
npm

CVE-2026-71850

Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure

MEDIUM 5.3
npm

CVE-2026-69207

Hono: ReDoS in CORS middleware via Access-Control-Request-Headers

MEDIUM 4.8
npm

CVE-2026-16728

undici vulnerable to downstream response desynchronization via retry interceptor

MEDIUM 6.5
npm

CVE-2026-48816

sigstore-js has Insufficient Verification of Data Authenticity

MEDIUM 6.1
npm

CVE-2026-59895

Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility

MEDIUM 5.3
npm

CVE-2026-59871

node-tar: Process crash via PAX numeric path type confusion

MEDIUM 6.1
npm

CVE-2026-59711

showdown metadata title handling allows cross-site scripting

MEDIUM 4.3
npm

CVE-2026-49856

@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization

MEDIUM 5.3
npm

CVE-2026-5078

morgan vulnerable to Log Forging via unneutralized control characters in :remote-user

MEDIUM 5.3
npm

CVE-2026-13149

brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups

MEDIUM 5.7
npm

CVE-2026-73651

TypeORM: migration:generate template-literal code injection

MEDIUM 6.1
npm

CVE-2026-59710

showdown allows stored cross-site scripting through table header ID injection

MEDIUM 4.2
npm

CVE-2026-50179

@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

MEDIUM 5.3
npm

CVE-2026-47674

Hono: IP Restriction bypasses static deny rules for non-canonical IPv6

MEDIUM 6.1
npm

CVE-2026-49459

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

MEDIUM 5.9
npm

CVE-2026-9678

undici vulnerable to cross-user information disclosure via shared cache whitespace bypass

MEDIUM 5.9
npm

CVE-2026-9679

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

MEDIUM 6.1
npm

CVE-2026-50171

@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)

MEDIUM 5.3
npm

CVE-2026-9595

webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies

MEDIUM 5.4
npm

CVE-2026-48758

@sigstore/core has DSSE payloadType type-binding failure

MEDIUM 5.3
npm

CVE-2026-48988

markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

MEDIUM 6.1
npm

CVE-2026-54265

@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)

MEDIUM 5.3
npm

CVE-2026-47676

Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths

MEDIUM 5.4
npm

CVE-2026-42042

Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion

MEDIUM 5.4
npm

CVE-2026-82661

Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection

MEDIUM 4.3
npm

CVE-2026-8766

@kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

MEDIUM 5.3
npm

CVE-2026-44457

Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage

MEDIUM 6.5
npm

CVE-2026-45149

brace-expansion: Large numeric range defeats documented `max` DoS protection

MEDIUM 5.3
npm

CVE-2026-45740

protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion

MEDIUM 6.8
npm

CVE-2026-42038

Axios: no_proxy bypass via IP alias allows SSRF

MEDIUM 6.1
npm

CVE-2026-46341

Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching

Ready to move

Start Securing

Free, no credit card | First findings in minutes