Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-464C-974J-9XM6Lowaws-cdk-lib: AWS CDK CodeBuild S3 Log Encryption Boolean InversionCVE-2026-7120Medium@fastify/static: @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL PathsCVE-2026-15074High@fastify/static: @fastify/static vulnerable to route guard bypass via path traversalGHSA-R9MR-M37C-5FR3HighGitPython: GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command executionGHSA-6P8H-3WGX-97GFHighGitPython: GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooksGHSA-FJR4-X663-MWXCHighGitPython: GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)GHSA-R292-9MHP-454MMediumtar: node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selectionGHSA-R28C-9Q8G-F849Highpostcss: PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File DisclosureGHSA-W28W-GP39-M4P6Critical@prompty/core: Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks RendererGHSA-664H-WQGQ-64GWMediummongoose: Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)GHSA-3RP5-JJMW-4WV2Highgitpython: GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)GHSA-7GFH-X38P-PRH3Criticalvelocityjs: Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)GHSA-38HQ-7X33-PHP4Medium@backstage/plugin-auth-backend: @backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypassCVE-2026-62946MediumMagick.NET-Q16-AnyCPU: ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit buildsCVE-2026-62363MediumMagick.NET-Q16-AnyCPU: ImageMagick: Heap Buffer Over-Write in fx operationCVE-2026-62343MediumMagick.NET-Q16-AnyCPU: ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is providedCVE-2026-61632Mediumpymdown-extensions: PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_pathGHSA-53G2-MVCC-Q9X3Mediumtrix: Trix: Stored XSS via HTMLParser attribute injection on pasteGHSA-P5RM-JG5C-8C77MediumMicrosoft.OpenApi.Kiota: Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)CVE-2026-59952Mediumvalibot: Valibot: record() issue paths can make flatten() throw for inherited Object property namesCVE-2026-59940Criticalseroval: seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserializationCVE-2026-59949Mediumat.yawk.lz4:lz4-java: LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array rangesCVE-2026-59866HighMicrosoft.OpenApi.Kiota: Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceNameCVE-2026-59865CriticalMicrosoft.OpenApi.Kiota: Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`CVE-2026-59863HighMicrosoft.OpenApi.Kiota: Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF

Stop the waste.
Protect your environment with Kodem.