npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55575Highliquidjs: LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforceCVE-2026-54673Highbuilder-util-runtime: electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`CVE-2026-54672Highapp-builder-lib: electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`CVE-2026-53669Mediumreact-router: React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)CVE-2026-53668Mediumreact-router-dom: React Router: Open redirect leading to XSSCVE-2026-53667Mediumreact-router: React Router: RSCErrorHandler Missing Protocol Validation (XSS)CVE-2026-53666Mediumreact-router: React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR HydrationCVE-2026-47219Highfind-my-way: find-my-way: DDoS with HTTP2CVE-2026-45623Highpostcss: PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentsGHSA-8FPG-XM3F-6CX3Criticalnext-auth: Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)GHSA-XMF8-CVQR-RFGJHigh@auth/core: Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headersGHSA-7RQJ-J65F-68WHCritical@auth/core: Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypassGHSA-X445-F3H2-J279Medium@auth/core: Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created themGHSA-652Q-GVQ3-74QVMediumn8n: n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression InterpolationGHSA-JQWR-VX3P-R266Mediumn8n: n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL InstancesGHSA-9CMH-XCQM-5HQRMediumn8n: n8n: Cross-Tenant Module-Cache Poisoning in the JS Task RunnerCVE-2026-64649Highnext: Next.js: Server-Side Request Forgery in Server Actions on custom serversCVE-2026-64648Mediumnext: Next.js: Cache confusion of response bodies for requests with bodiesCVE-2026-64647Mediumnext: Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequencesCVE-2026-64646Mediumnext: Next.js: Unbounded Server Action payload in Edge runtimeCVE-2026-64645Highnext: Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostnameCVE-2026-64644Mediumnext: Next.js: Denial of Service in the Image Optimization API using SVGsCVE-2026-64643Mediumnext: Next.js: Unauthenticated disclosure of internal Server Function endpointsCVE-2026-64642Highnext: Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single localeCVE-2026-64641Highnext: Next.js: Denial of Service in App Router using Server Actions

Stop the waste.
Protect your environment with Kodem.