Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-61568Critical@zereight/mcp-gitlab: @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transportGHSA-5648-RGJ9-V224High@zereight/mcp-gitlab: @zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports,…CVE-2026-61554Highgithub.com/jm33-m0/emp3r0r/core: emp3r0r has an unauthenticated HTTP Polling DoSCVE-2026-88975Highorg.http4s:http4s-ember-core_2.13: Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZECVE-2026-61544Highlibp2p-quic: libp2p-quic: Remote panic via certificate expiry race during QUIC handshakeCVE-2026-69201Mediumorg.http4s:http4s-server_2.12: Http4s: ResourceService and Webjar Service path escape via percent-encoded separatorsCVE-2026-69218Highorg.http4s:http4s-ember-core_2.12: Http4s Ember HTTP/2: unbounded continuation frame accumulationCVE-2026-69216Mediumorg.http4s:http4s-ember-core_2.12: Http4s: Ember chunk parser lenience (TE.TE request smuggling)CVE-2026-69215Mediumorg.http4s:http4s-client_2.12: Http4s: CookieJar middleware matches by substring, leaking cookies cross-originCVE-2026-69214Mediumorg.http4s:http4s-client_2.12: Http4s: CookieJar middleware accepts arbitrary Set-Cookie domainCVE-2026-69213Highorg.http4s:http4s-ember-core_2.12: Http4s Ember HTTP/2 has an unbounded outbound frame queueCVE-2026-69208Highorg.http4s:http4s-ember-server_2.12: Http4s: DigestAuth nonce map grows unboundedCVE-2026-69206Mediumorg.http4s:http4s-ember-core_2.12: Http4s: DigestAuth allows replay of captured requestsCVE-2026-69205Highorg.http4s:http4s-ember-core_3: Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)CVE-2026-69204Criticalorg.http4s:http4s-ember-core_2.12: Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)CVE-2026-69203Highorg.http4s:http4s-ember-core_2.12: Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMSCVE-2026-69202Highorg.http4s:http4s-ember-core_2.12: Http4s Ember HTTP/2: unbounded inbound body bufferingGHSA-RF68-8GJR-36Q7Lowgithub.com/nezhahq/nezha: Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is emptyCVE-2026-32599Mediumgithub.com/gravitl/netmaker: Netmaker has a boolean‑based SQL InjectionCVE-2026-76081Mediumgithub.com/zitadel/zitadel: ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role DeletionsCVE-2026-56668Highgithub.com/zitadel/zitadel: ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token ExchangeCVE-2026-59178Criticalesphome-device-builder: ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgradeGHSA-2XMM-M4WV-3FJHLowoctober/october: October CMS: Incomplete Scheme Validation in Image ResizerCVE-2026-49400Lowoctober/system: October CMS: PHP Object Injection via Backend Widget Session StorageCVE-2026-46696Lowoctober/system: October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls

Stop the waste.
Protect your environment with Kodem.