Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-wmmp-3585-3rmp
    Fix available
    Packages

    nodemailer

    Summary

    Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

    Published
    8 Sept 2026
    CGA-2v38-rqf7-wxpg
    Fix available
    Packages

    kubectl-argo-rollouts-fips

    Summary

    Published
    8 Sept 2026
    GHSA-2x7j-588g-ccc2
    Fix available
    Packages

    nodemailer

    Summary

    Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list

    Published
    8 Sept 2026
    GHSA-cc9r-2j5m-2m83
    Fix available
    Packages

    nodemailer

    Summary

    Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain

    Published
    8 Sept 2026
    GHSA-2q42-4q24-7rgv
    No fix available
    Packages

    @typespec/openapi3, @typespec/compiler

    Summary

    OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree

    Published
    8 Sept 2026
    GHSA-wc9g-mqfw-jrwm
    Fix available
    Packages

    multer

    Summary

    multer vulnerable to Denial of Service via crafted multipart field names

    Published
    8 Sept 2026
    GHSA-qfvm-cv95-jqjf
    Fix available
    Packages

    multer

    Summary

    multer vulnerable to Denial of Service via file descriptor leak on aborted uploads

    Published
    8 Sept 2026
    GHSA-qvfw-j98x-7q72
    Fix available
    Packages

    multer

    Summary

    multer vulnerable to file size limit bypass via async fileFilter race condition

    Published
    8 Sept 2026
    CVE-2026-86075
    Fix available
    Packages

    Summary

    n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint

    Published
    8 Sept 2026
    CGA-22r6-f77g-vxw6
    Fix available
    Packages

    argo-rollouts-fips

    Summary

    Published
    8 Sept 2026
    CVE-2026-86076
    Fix available
    Packages

    Summary

    n8n: Expression Sandbox Escape in Editor-UI Enables Stored Cross-User JavaScript Execution

    Published
    8 Sept 2026
    GHSA-535w-7cp7-47q4
    Fix available
    Packages

    multer

    Summary

    multer vulnerable to Denial of Service via oversized array index in field names

    Published
    8 Sept 2026
    GHSA-jxfw-x594-9x9m
    Fix available
    Packages

    morgan

    Summary

    morgan vulnerable to Log Forging via unescaped Unicode line separators

    Published
    8 Sept 2026
    CVE-2026-86077
    Fix available
    Packages

    Summary

    n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket

    Published
    8 Sept 2026
    GHSA-96p9-rh4f-92cf
    Fix available
    Packages

    winml-cli

    Summary

    Windows ML CLI: CORS misconfig enables localhost RCE

    Published
    8 Sept 2026
    GHSA-65fr-j4p9-vc33
    Fix available
    Packages

    mongodb/mongodb, mongodb/mongodb

    Summary

    mongodb: Reject "." and NUL bytes in database and collection names

    Published
    8 Sept 2026
    CVE-2026-86078
    Fix available
    Packages

    Summary

    n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service

    Published
    8 Sept 2026
    CGA-x7qm-88xj-wg3h
    Fix available
    Packages

    gitlab-elasticsearch-indexer-fips

    Summary

    Published
    8 Sept 2026
    CVE-2026-86079
    Fix available
    Packages

    Summary

    n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers

    Published
    8 Sept 2026
    GHSA-26w7-cxv4-gfx2
    Fix available
    Packages

    astro

    Summary

    Astro: Remote code execution through AVIF image optimization

    Published
    8 Sept 2026
    GHSA-376h-93r7-7g6f
    Fix available
    Packages

    astro

    Summary

    Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base

    Published
    8 Sept 2026
    CVE-2026-86080
    Fix available
    Packages

    Summary

    n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open

    Published
    8 Sept 2026
    GHSA-rvx4-ffvw-m9q3
    Fix available
    Packages

    composer/composer, composer/composer

    Summary

    Composer arbitrary command execution via a malicious package's Perforce source URL

    Published
    8 Sept 2026
    GHSA-rgj7-g3m4-5g8c
    Fix available
    Packages

    sharp

    Summary

    sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545

    Published
    8 Sept 2026
    GHSA-2883-xcg3-v3hh
    Fix available
    Packages

    js-yaml, js-yaml

    Summary

    js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources

    Published
    8 Sept 2026
    GHSA-q97c-8qh3-fpc6
    Fix available
    Packages

    phpseclib, phpseclib

    Summary

    phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery

    Published
    8 Sept 2026
    CVE-2026-86081
    Fix available
    Packages

    Summary

    n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path

    Published
    8 Sept 2026
    GHSA-j95f-988m-3j2f
    Fix available
    Packages

    @tiptap/core

    Summary

    Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing

    Published
    8 Sept 2026
    GHSA-gqvv-2mrq-wpjv
    Fix available
    Packages

    hono

    Summary

    Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory

    Published
    8 Sept 2026
    CVE-2026-86082
    Fix available
    Packages

    Summary

    n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node

    Published
    8 Sept 2026
    GHSA-g6gw-c38x-mqfc
    Fix available
    Packages

    hono

    Summary

    Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion

    Published
    8 Sept 2026
    GHSA-crvj-82cr-hjcx
    Fix available
    Packages

    hono

    Summary

    Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

    Published
    8 Sept 2026
    CVE-2026-86083
    Fix available
    Packages

    Summary

    n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution

    Published
    8 Sept 2026
    CVE-2026-86084
    Fix available
    Packages

    Summary

    n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions

    Published
    8 Sept 2026
    GHSA-2v4p-qf9q-27wj
    Fix available
    Packages

    google.golang.org/grpc, google.golang.org/grpc, google.golang.org/grpc

    Summary

    gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers

    Published
    8 Sept 2026
    GHSA-2xp9-vwfh-vxw4
    Fix available
    Packages

    next, next

    Summary

    Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used

    Published
    8 Sept 2026
    CVE-2026-86085
    Fix available
    Packages

    Summary

    n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints

    Published
    8 Sept 2026
    GHSA-w27v-7q3p-w38r
    Fix available
    Packages

    svgo, svgo, svgo

    Summary

    SVGO: removeScripts allows executable links through namespace and control-character bypasses

    Published
    8 Sept 2026
    GHSA-4vpr-x523-8j87
    Fix available
    Packages

    svgo, svgo, svgo

    Summary

    SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements

    Published
    8 Sept 2026
    CVE-2026-86993
    Fix available
    Packages

    Summary

    n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check

    Published
    8 Sept 2026
    CVE-2026-86994
    Fix available
    Packages

    Summary

    n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter

    Published
    8 Sept 2026
    CVE-2026-86995
    Fix available
    Packages

    Summary

    n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read

    Published
    8 Sept 2026
    Packages

    ffmpeg, ffmpeg, ffmpeg

    Summary

    Published
    8 Sept 2026
    GHSA-8m3c-c648-2xjj
    Fix available
    Packages

    nodemailer

    Summary

    Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature

    Published
    8 Sept 2026
    CVE-2026-86996
    Fix available
    Packages

    Summary

    n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy

    Published
    8 Sept 2026
    CGA-x8qx-8wjq-h6h2
    Fix available
    Packages

    argo-rollouts-fips

    Summary

    Published
    8 Sept 2026
    GHSA-c7q8-3ch8-vqpv
    Fix available
    Packages

    @xmldom/xmldom, @xmldom/xmldom, xmldom

    Summary

    xmldom: Processing Instruction Target Injection Bypasses requireWellFormed

    Published
    8 Sept 2026
    GHSA-jxjr-3g7g-3944
    Fix available
    Packages

    @xmldom/xmldom

    Summary

    xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator

    Published
    8 Sept 2026
    GHSA-27p8-2357-5qqv
    Fix available
    Packages

    @xmldom/xmldom, @xmldom/xmldom, xmldom

    Summary

    xmldom: DocType `name` Injection Bypasses requireWellFormed

    Published
    8 Sept 2026
    GHSA-3px3-54cx-rmw9
    Fix available
    Packages

    @xmldom/xmldom

    Summary

    xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path

    Published
    8 Sept 2026