Know every threat before it ships
200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.
CVE-2026-33060
SSRF in @aborruso/ckan-mcp-server via base_url allows access to internal networks
CVE-2026-53509
@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)
CVE-2026-61612
@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509
CVE-2026-77425
Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log
CVE-2026-56682
9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header
CVE-2026-58270
Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`
CVE-2026-58272
Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)
CVE-2026-58271
@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`
CVE-2026-56326
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
CVE-2026-84992
md-editor-v3: XSS via fenced-code language rendering bypass
CVE-2026-92963
vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`
CVE-2026-88976
@platejs/core HTML deserialization can trigger browser behavior during parsing
CVE-2026-81176
Svelte devalue: DoS via malformed input
CVE-2026-54546
TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard
CVE-2026-63225
Redocly CLI: Path traversal when using `split` command
CVE-2026-63461
Vendure: Shop API list queries can return non-public entities when filterOperator is OR
CVE-2026-92597
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
CVE-2026-92595
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
CVE-2026-92598
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
CVE-2026-68921
DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
CVE-2026-81888
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
CVE-2026-59149
@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
CVE-2026-88059
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
CVE-2026-71429
stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)
CVE-2026-82417
qs: Denial of Service via Attacker Controlled isBuffer
GHSA-rgwj-5xj2-c3m3
MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS
CVE-2026-16729
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
CVE-2026-15157
undici vulnerable to CRLF Injection via blob-like body 'type' property
CVE-2026-14643
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
CVE-2026-71850
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
CVE-2026-69207
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
CVE-2026-16728
undici vulnerable to downstream response desynchronization via retry interceptor
CVE-2026-48816
sigstore-js has Insufficient Verification of Data Authenticity
CVE-2026-59895
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
CVE-2026-59871
node-tar: Process crash via PAX numeric path type confusion
CVE-2026-59711
showdown metadata title handling allows cross-site scripting
CVE-2026-49856
@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization
CVE-2026-5078
morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
CVE-2026-13149
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
CVE-2026-73651
TypeORM: migration:generate template-literal code injection
CVE-2026-59710
showdown allows stored cross-site scripting through table header ID injection
CVE-2026-50179
@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields
CVE-2026-47674
Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
CVE-2026-49459
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
CVE-2026-9678
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
CVE-2026-9679
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
CVE-2026-50171
@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
CVE-2026-9595
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
CVE-2026-48758
@sigstore/core has DSSE payloadType type-binding failure
CVE-2026-48988
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
CVE-2026-54265
@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)
CVE-2026-47676
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
CVE-2026-42042
Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
CVE-2026-82661
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection
CVE-2026-8766
@kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-44457
Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage
CVE-2026-45149
brace-expansion: Large numeric range defeats documented `max` DoS protection
CVE-2026-45740
protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
CVE-2026-42038
Axios: no_proxy bypass via IP alias allows SSRF
CVE-2026-46341
Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
Ready to move
Start Securing
Free, no credit card | First findings in minutes