Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-MHM7-754M-9P8WMediumcom.fasterxml.jackson.core:jackson-databind: jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`GHSA-P63J-VCC4-9VMVCritical@vitest/browser: @vitest/browser: Browser Mode provider commands bypass the file-access permission gateCVE-2026-59891Critical@sigstore/oci: Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registryCVE-2026-59888Mediumcom.fasterxml.jackson.core:jackson-databind: jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategyCVE-2026-57894Highcode.gitea.io/gitea: Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository ExfiltrationCVE-2026-59886Highpyasn1: pyasn1: Uncontrolled resource consumption when converting decoded REAL valuesCVE-2026-59885Highpyasn1: pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of serviceCVE-2026-59884Highpyssn1: pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDsCVE-2026-59890Mediumsetuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+CVE-2026-59892High@opentelemetry/propagator-jaeger: OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed headerCVE-2026-59887Highlinkify-it: linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker textCVE-2026-13760Highaws-cdk-lib: aws-cdk-lib: OS Command Injection in NodejsFunction Docker BundlingCVE-2026-13676Highfast-uri: fast-uri vulnerable to host confusion via failed IDN canonicalizationCVE-2026-59880Highimmutable: Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/SetCVE-2026-59879Highimmutable: Immutable.js `List` 32-bit trie overflow → unrecoverable DoSCVE-2026-59882Mediumguzzlehttp/psr7: guzzlehttp/psr7: Host Confusion via Weak URI Host ValidationCVE-2026-61666Highwebsocket-driver: websocket-driver-ruby: Denial of service via malformed Host headerCVE-2026-59896Mediumhono: hono/jsx does not isolate context per request, leading to cross-request data disclosureCVE-2026-59895Mediumhono: Hono: Server-Side XSS via JSX Escaping Bypass in cx() UtilityCVE-2026-59897Mediumhono: Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplicationGHSA-FRVP-7C67-39W9Medium@hono/node-server: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)CVE-2026-54291Highorg.postgresql:postgresql: PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithmsCVE-2026-56170HighMicrosoft.AspNetCore.App.Runtime.linux-arm: Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service VulnerabilityCVE-2026-50526HighMicrosoft.NET.Build.Containers: Microsoft Security Advisory CVE-2026-50526 – .NET Tampering VulnerabilityCVE-2026-47300HighMicrosoft.AspNetCore.Authentication.Negotiate: Microsoft Security Advisory CVE-2026-47300 – .NET Elevation of Privilege Vulnerability

Stop the waste.
Protect your environment with Kodem.