Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-84303Mediumgoogle.golang.org/grpc: gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasionCVE-2026-84382Highhttpx2: HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)CVE-2026-84373Medium@vitest/mocker: Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect MockCVE-2026-84380Mediumhttpx2: HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generatedCVE-2026-84379Mediumhttpx2: HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headersCVE-2026-84378Mediumhttpx2: HTTPX2: Quadratic SSE line buffering can cause CPU denial of serviceCVE-2026-84381Highhttpcore2: HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxiesCVE-2026-73560Mediumvllm: vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protectionsCVE-2026-84374Highmaatwebsite/excel: Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled pathCVE-2026-83606High@xmldom/xmldom: xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructionsCVE-2026-83607High@xmldom/xmldom: xmldom: Element name injection via createElement() bypasses requireWellFormedCVE-2026-83605High@xmldom/xmldom: xmldom: Attribute name injection via setAttribute() bypasses requireWellFormedCVE-2026-50646HighMicrosoft.WindowsDesktop.App.Runtime.win-x64: Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution VulnerabilityCVE-2026-81725Mediumnltk: NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocksCVE-2026-80206Highnltk: NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressionsCVE-2026-80205Highnltk: NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressionsCVE-2026-62815CriticalMicrosoft.Native.Quic.MsQuic.OpenSSL: Microsoft QUIC: Remote Code Execution VulnerabilityCVE-2026-62900MediumMicrosoft.Build.Tasks.Git: Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure VulnerabilityCVE-2026-73558Mediumvllm: vLLM: Cross-User Data Leak VulnerabilityCVE-2026-78679MediumGitPython: GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of…CVE-2026-78677HighGitPython: GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside…CVE-2026-78678MediumGitPython: GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()CVE-2026-78676CriticalGitPython: GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated…CVE-2026-78675HighGitPython: GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables…CVE-2026-75595Criticalio.netty:netty-handler: Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext

Stop the waste.
Protect your environment with Kodem.