Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-69215Mediumorg.http4s:http4s-client_2.12: Http4s: CookieJar middleware matches by substring, leaking cookies cross-originCVE-2026-69214Mediumorg.http4s:http4s-client_2.12: Http4s: CookieJar middleware accepts arbitrary Set-Cookie domainCVE-2026-69213Highorg.http4s:http4s-ember-core_2.12: Http4s Ember HTTP/2 has an unbounded outbound frame queueCVE-2026-69208Highorg.http4s:http4s-ember-server_2.12: Http4s: DigestAuth nonce map grows unboundedCVE-2026-69206Mediumorg.http4s:http4s-ember-core_2.12: Http4s: DigestAuth allows replay of captured requestsCVE-2026-69205Highorg.http4s:http4s-ember-core_3: Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)CVE-2026-69204Criticalorg.http4s:http4s-ember-core_2.12: Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)CVE-2026-69203Highorg.http4s:http4s-ember-core_2.12: Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMSCVE-2026-69202Highorg.http4s:http4s-ember-core_2.12: Http4s Ember HTTP/2: unbounded inbound body bufferingGHSA-RF68-8GJR-36Q7Lowgithub.com/nezhahq/nezha: Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is emptyCVE-2026-32599Mediumgithub.com/gravitl/netmaker: Netmaker has a boolean‑based SQL InjectionCVE-2026-76081Mediumgithub.com/zitadel/zitadel: ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role DeletionsCVE-2026-56668Highgithub.com/zitadel/zitadel: ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token ExchangeCVE-2026-59178Criticalesphome-device-builder: ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgradeGHSA-2XMM-M4WV-3FJHLowoctober/october: October CMS: Incomplete Scheme Validation in Image ResizerCVE-2026-49400Lowoctober/system: October CMS: PHP Object Injection via Backend Widget Session StorageCVE-2026-46696Lowoctober/system: October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder CallsCVE-2026-56666Mediumgithub.com/zitadel/zitadel: ZITADEL: Auto-linking by email: IdP-side email verification is not checkedCVE-2026-61534Criticalyayson: yayson: Prototype pollution in Store/LegacyStore deserializationCVE-2026-59148High@mockoon/commons-server: @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theftCVE-2026-59149Medium@mockoon/commons-server: @Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)CVE-2026-59973Highmcp-from-openapi: FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fixCVE-2026-59151Criticalprowler-cloud: Prowler: SAML Domain Claiming Enables Cross-Tenant Account TakeoverCVE-2026-56665Mediumgithub.com/zitadel/zitadel: ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP ProviderCVE-2026-56825Highshopper/framework: Shopper: Missing authorization on product removal actions in CollectionProducts component

Stop the waste.
Protect your environment with Kodem.