Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-59921Mediumio.netty:netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoderCVE-2026-59920Mediumio.netty:netty-codec-stomp: Netty: STOMP CONNECT Frame Header Injection in NettyCVE-2026-59919Mediumio.netty:netty-codec-haproxy: Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX AddressCVE-2026-59901Highio.netty:netty-codec-compression: Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread HangCVE-2026-59900Mediumio.netty:netty-codec-http2: Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing BypassCVE-2026-59899Mediumio.netty:netty-codec-http: Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of ServiceCVE-2026-59898Mediumio.netty:netty-codec-http: Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validationCVE-2026-56822Highio.netty:netty-handler-ssl-ocsp: Netty: TOCTOU in OcspServerCertificateValidatorCVE-2026-56821Highio.netty:netty-handler-ssl-ocsp: Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidatorCVE-2026-56820Highio.netty:netty-handler-ssl-ocsp: Netty: Missing CertificateID Validation in OCSP Response Allows Replay AttacksCVE-2026-56817Highio.netty:netty-codec-xml: Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handlingCVE-2026-56816Highio.netty:netty-codec-http3: Netty: Memory Exhaustion via HTTP/3 Reserved Frame TypesCVE-2026-56746Mediumio.netty:netty-codec-http: Netty: Security Control Bypass via CORS Short-Circuit FailureCVE-2026-56745Highio.netty:netty-codec-http: Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory ExhaustionCVE-2026-56722Mediumdompdf/dompdf: Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URICVE-2026-55851Highio.netty:netty-codec-haproxy: Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory ExhaustionCVE-2026-55833Highio.netty:netty-codec-http: Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncationCVE-2026-55831Highio.netty:netty-codec-http: Netty SPDY SETTINGS frame count materializes unbounded settings mapCVE-2026-55555Lowdompdf/dompdf: Dompdf: File existence oracle via font-face stylesheet declarationCVE-2026-55554Lowdompdf/dompdf: Dompdf: Chroot Validation BypassCVE-2026-65599Mediumn8n: n8n: Google Service Account Private Key Exposed in JWT HeaderCVE-2026-65592Highn8n: n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`CVE-2026-65597Highn8n: n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML PreviewCVE-2026-65598Highn8n: n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code ExecutionCVE-2026-65015Highn8n: n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool

Stop the waste.
Protect your environment with Kodem.