npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-59879Highimmutable: Immutable.js `List` 32-bit trie overflow → unrecoverable DoSCVE-2026-59896Mediumhono: hono/jsx does not isolate context per request, leading to cross-request data disclosureCVE-2026-59895Mediumhono: Hono: Server-Side XSS via JSX Escaping Bypass in cx() UtilityCVE-2026-59897Mediumhono: Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplicationGHSA-FRVP-7C67-39W9Medium@hono/node-server: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)GHSA-8MV7-9C27-98VCMediumastro: Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misorderedGHSA-HP3V-MFQW-H74CLow@astrojs/netlify: @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escapedCVE-2026-12590Lowbody-parser: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcementCVE-2026-59730Low@astrojs/node: @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirectCVE-2026-59729Mediumastro: Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)CVE-2026-59728Medium@astrojs/rss: @astrojs/rss: XML Injection via Unescaped RSS Feed FieldsCVE-2026-59727Lowastro: Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islandsGHSA-GCFJ-64VW-6MP9Highaxios: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloningGHSA-HCPX-6FM6-WX23Mediumaxios: Axios form serializer maxDepth bypass via {} metatokenGHSA-7Q8Q-RJ6J-MHJQMediumaxios: Axios: Nested axios option objects can consume polluted prototype valuesGHSA-MWF2-3PR3-8698Mediumaxios: Axios: HTTP/2 streamed uploads bypass `maxBodyLength`GHSA-JQH4-M9W3-8HP9Mediumaxios: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`GHSA-MMX7-HFXF-JPPXMediumaxios: Axios: Prototype pollution gadgets can alter axios request constructionGHSA-F4GW-2P7V-4548Mediumaxios: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axiosCVE-2026-59876Mediumprotobufjs: protobufjs: Text Format string map parsing can mutate returned map object prototypeCVE-2026-59877Mediumprotobufjs: protobufjs: Denial of Service via infinite loop in .proto option parsingCVE-2026-14631Mediumwebpack-dev-server: webpack-dev-server vulnerable to denial of service via a malformed Host or Origin headerCVE-2026-14620Mediumwebpack-dev-server: webpack-dev-server vulnerable to cross-site request forgery via internal developer endpointsCVE-2026-59731Highastro: Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization MismatchCVE-2026-59871Mediumtar: node-tar: Process crash via PAX numeric path type confusion

Stop the waste.
Protect your environment with Kodem.