Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-64647Mediumnext: Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequencesCVE-2026-64646Mediumnext: Next.js: Unbounded Server Action payload in Edge runtimeCVE-2026-64645Highnext: Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostnameCVE-2026-64644Mediumnext: Next.js: Denial of Service in the Image Optimization API using SVGsCVE-2026-64643Mediumnext: Next.js: Unauthenticated disclosure of internal Server Function endpointsCVE-2026-64642Highnext: Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single localeCVE-2026-64641Highnext: Next.js: Denial of Service in App Router using Server ActionsCVE-2024-7708Highorg.eclipse.jetty:jetty-server: Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requestsCVE-2026-8384Mediumorg.eclipse.jetty:jetty-util: Eclipse Jetty: Path parameter traversalCVE-2026-6790Mediumorg.eclipse.jetty:jetty-server: Eclipse Jetty: HTTP Authority/Host mismatchCVE-2026-10051Mediumorg.eclipse.jetty:jetty-server: Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connectionsCVE-2026-10050Highorg.eclipse.jetty:jetty-security: Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitutionCVE-2026-65589Mediumn8n: n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution DataCVE-2026-59943Mediumdompdf/dompdf: Dompdf: Embedded SVG images can leak existence of files and directories within the filesystemCVE-2026-59942Mediumdompdf/dompdf: Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image BitmapsCVE-2026-59941Mediumdompdf/dompdf: Dompdf: Uncontrolled resource consumption based on declared BMP dimensionsCVE-2026-59821Lowlitellm: LiteLLM: Custom Code Guardrails production endpoints bypass code safety checksCVE-2026-59822Highlitellm: LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough FallbackCVE-2026-59819Lowlitellm: LiteLLM: Local file read via request-supplied OIDC file referencesCVE-2026-59820Mediumlitellm: LiteLLM: Arbitrary file write via path traversal in Skills archive extractionCVE-2026-65014Mediumn8n: n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test WebhookCVE-2026-65596Mediumn8n: n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" RestrictionCVE-2026-65594Mediumn8n: n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization CheckCVE-2026-65590Mediumn8n: n8n: computer-use Shell Sandbox Not Enforced on Linux and WindowsCVE-2026-58661Mediumn8n: n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads

Stop the waste.
Protect your environment with Kodem.