Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55435Mediumgithub.com/coder/coder/v2: Suspended Coder users retain access to AI Bridge LLM proxy endpointsCVE-2026-55434Mediumgithub.com/coder/coder/v2: Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpointsCVE-2026-55433Mediumgithub.com/coder/coder/v2: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containersCVE-2026-55432Mediumgithub.com/coder/coder/v2: Coder's sub-agent app registration bypasses template port-sharing policy enforcementCVE-2026-55431Highgithub.com/coder/coder/v2: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace appsCVE-2026-55078Mediumgithub.com/coder/coder/v2: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of serviceCVE-2026-55430Mediumgithub.com/coder/coder/v2: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data accessCVE-2026-55428Highgithub.com/coder/coder/v2: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinatorCVE-2026-55429Highgithub.com/coder/coder/v2: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app IDCVE-2026-55079Mediumgithub.com/coder/coder/v2: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of serviceCVE-2026-55427Highgithub.com/coder/coder/v2: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`CVE-2026-55077Highgithub.com/coder/coder/v2: Coder: User-admin role can reset owner account passwordCVE-2026-55075Highgithub.com/coder/coder/v2: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypassCVE-2026-55076Highgithub.com/coder/coder/v2: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linkingCVE-2026-54640Highio.openremote:openremote-agent: OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected…CVE-2026-54641Highio.openremote:openremote-manager: OpenRemote has Cross-Realm User Information Disclosure in UserResourceImplCVE-2026-53935Mediumgithub.com/cilium/cilium: CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translationCVE-2026-53624Mediumgithub.com/gofiber/fiber: GoFiber never set HSTS header in helmet middleware due to incorrect protocol checkCVE-2026-54771Highlangroid: Langroid: handle_message() executes user-supplied tool JSON without sender verification CVE-2026-54769Criticallangroid: Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgentCVE-2026-54760Criticallangroid: Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file callsCVE-2026-54637Mediumd7y.io/dragonfly/v2: Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFileCVE-2026-53759Lowlinuxfabrik-lib: Linuxfabrik Monitoring Plugins allow insecure creation of SQLite databasesGHSA-X76W-8C62-48MGMediumcraftcms/cms: Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permissionCVE-2026-53486Critical@xhmikosr/decompress: Decompress: Archive extraction can create files and links outside of the target directory

Stop the waste.
Protect your environment with Kodem.