npm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-59873Criticaltar: node-tar: Decompression/parse DoS via unlimited inputCVE-2026-59874Hightar: node-tar: Negative tar entry size causes infinite loop in archive replaceCVE-2026-59875Mediumtar: node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath recordsCVE-2026-59725Highengine.io: Socket.IO: Engine.IO Polling Transport Connection ExhaustionCVE-2026-13311Highshell-quote: shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)CVE-2026-61836Highdirectus: Directus: Authorization-dependent response served from unsegmented cache keyCVE-2026-61835Highdirectus: Directus: SSRF Protection Bypass via 0.0.0.0 in File ImportCVE-2026-59868Mediumjs-yaml: js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yamlCVE-2026-59869Highjs-yaml: js-yaml: YAML merge-key chains can force quadratic CPU consumptionCVE-2026-59870Mediumjs-yaml: js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMAGHSA-4G3V-8H47-V7G6Mediumastro: Astro: Reflected XSS via unescaped View Transition animation propertiesCVE-2026-53515High@better-auth/sso: @better-auth/sso: SSO provider may allow registration for any org member without a checking their roleCVE-2026-13149Highbrace-expansion: brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groupsGHSA-42H9-826W-CGV3Mediumaxios: Axios: Excessive recursion in formDataToJSON can cause denial of serviceGHSA-XJ6Q-8X83-JV6GMediumaxios: Axios: Prototype pollution auth subfields can inject Basic authGHSA-PMV8-RQ9R-6J72Mediumaxios: Axios: Deep formToJSON Key Recursion Can Cause Denial of ServiceCVE-2026-55177High@tak-ps/cloudtak: CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guardCVE-2026-53496Mediumexifreader: ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxesCVE-2026-53597High@prompty/core: Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loaderCVE-2026-53598Highprompty: Prompty: Arbitrary file read via file reference expansionCVE-2026-54561Mediummcp-memory-keeper: mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePathCVE-2026-54546Medium@tak-ps/cloudtak: TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guardCVE-2026-54504High@andrea9293/mcp-documentation-server: @andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by defaultCVE-2026-50289Highsysteminformation: systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on LinuxCVE-2026-50272Highdd-trace: dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS

Stop the waste.
Protect your environment with Kodem.