Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-86039High@libp2p/peer-store: libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addressesCVE-2026-75523MediumSteeltoe.Management.Endpoint: Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secretsCVE-2026-75831Mediumgetgrav/grav: Grav: Stored XSS via Markdown audio/video media <source> URLCVE-2026-86038High@libp2p/gossipsub: libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer IDCVE-2026-72832Mediumgetgrav/grav: Grav: Stored XSS via quoted-attribute bypass in detectXssCVE-2026-85717Mediumorg.asynchttpclient:async-http-client: AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect targetCVE-2026-85720Mediumorg.asynchttpclient:async-http-client: AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT requestCVE-2026-85721Highorg.asynchttpclient:async-http-client: AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of serviceCVE-2026-85716Loworg.asynchttpclient:async-http-client: AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responsesCVE-2026-85756HighSSH.NET: SSH.NET: ScpClient allows server-side RCE via default SCP path handlingCVE-2026-73245Mediumio.kestra:kestra: Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-authCVE-2026-69147Mediumvllm: vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservationCVE-2026-69089Highgetgrav/grav: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached imagesCVE-2026-69088Highgetgrav/grav: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosureCVE-2026-85732Mediumoras.land/oras-go/v2: oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probingCVE-2026-85731Highoras.land/oras-go/v2: oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)CVE-2026-73247Highio.kestra:core: Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadataCVE-2026-65608Highgetgrav/grav: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validationCVE-2026-86043Highgithub.com/zalando/skipper: Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)CVE-2026-77412Highgithub.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP ClientCVE-2026-77411Criticalgithub.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstrCVE-2026-77410Highgithub.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer AllocationCVE-2026-77408Criticalgithub.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer OverflowCVE-2026-77407Highgithub.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct FieldsCVE-2026-77406Highgithub.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration

Stop the waste.
Protect your environment with Kodem.