npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-84363Mediumhono: Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentialsGHSA-2XP9-VWFH-VXW4Criticalnext: Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are usedCVE-2026-84370Highsvgo: SVGO: removeScripts allows executable links through namespace and control-character bypassesCVE-2026-84369Mediumsvgo: SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elementsGHSA-8M3C-C648-2XJJMediumnodemailer: Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signatureCVE-2026-83616High@xmldom/xmldom: xmldom: Processing Instruction Target Injection Bypasses requireWellFormedCVE-2026-83617High@xmldom/xmldom: xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminatorCVE-2026-83608High@xmldom/xmldom: xmldom: DocType `name` Injection Bypasses requireWellFormedCVE-2026-83609High@xmldom/xmldom: xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default…CVE-2026-83618High@xmldom/xmldom: xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminatorCVE-2026-83611Medium@xmldom/xmldom: xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing contentCVE-2026-83613High@xmldom/xmldom: xmldom: Quadratic-time attribute deduplicationCVE-2026-83619High@xmldom/xmldom: xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parserCVE-2026-83615High@xmldom/xmldom: xmldom: Quadratic-memory consumptionCVE-2026-83614High@xmldom/xmldom: xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text mergeCVE-2026-83612High@xmldom/xmldom: xmldom: HTML raw-text closing-tag case mismatch causes output amplificationCVE-2026-84368Lowjoi: joi: Prototype pollution via a `__proto__` language key in custom messagesCVE-2026-85062Mediumcolord: Colord: Slow rejection of oversized malformed color stringsCVE-2026-75604Criticalnext: Next.js: Unauthenticated Remote Code Execution on windows-hosted serversCVE-2026-84367Lowjoi: joi: object().rename() with a template target can set the validated object's prototypeCVE-2026-85061Criticalmaplibre-gl: MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal SkipCVE-2026-84373Medium@vitest/mocker: Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect MockCVE-2026-83606High@xmldom/xmldom: xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructionsCVE-2026-83607High@xmldom/xmldom: xmldom: Element name injection via createElement() bypasses requireWellFormedCVE-2026-83605High@xmldom/xmldom: xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed

Stop the waste.
Protect your environment with Kodem.